Last updated: July 27, 2026
Shieldxy is designed to analyze and control network connections locally on your Mac. It does not require an account and does not include analytics, advertising, or telemetry.
After you enable its Network Extension, Shieldxy can observe metadata for newly created socket flows, including:
- the connecting application's bundle identifier, signing team, path, and presentation metadata;
- the destination hostname or IP address;
- connection timing, allow or block decisions, and byte counts; and
- locally derived company, risk, and optional geographic labels.
Shieldxy does not decrypt TLS, inspect request or response bodies, capture credentials, or record network payloads. Connections that were already open before filtering began may not be visible.
Connection analysis, rule evaluation, history, risk scoring, and optional GeoIP lookups run on your Mac. Rules and connection history are stored under the current user's Application Support directory. Preferences are stored with macOS UserDefaults.
Shieldxy does not upload this information to Shieldxy, Rockxy, or a third-party analytics service. Removing Shieldxy's Application Support and preference data after quitting the app removes the information retained by Shieldxy.
When software updates are enabled in an official release, Sparkle contacts the public Shieldxy update feed hosted on GitHub. GitHub receives the normal connection metadata associated with that request, such as the requester's IP address and user agent, under GitHub's own privacy terms. Update archives and the update feed are cryptographically verified before installation.
When you open the Network Map, Shieldxy renders it with Apple's standard MapKit. MapKit may contact Apple to fetch map content, and Apple receives the normal connection metadata for those tile requests (such as your IP address and the map region you are viewing) under Apple's own privacy terms. Shieldxy does not send the observed connection's host or IP address to Apple to draw the map: a connection is placed on the map using the offline GeoIP table and the bundled company-region fallback, both of which are evaluated locally.
Shieldxy has no cloud reputation service and makes no per-connection online GeoIP requests. Opening a website, privacy-policy link, or the optional “Open in Rockxy” action is an explicit user action handled by macOS or the receiving application.
The optional offline GeoIP database is generated from DB-IP data licensed under CC BY 4.0. It is processed locally and does not contact DB-IP while Shieldxy is running.
Material changes to this policy will be documented in the repository history and release notes. To report a privacy or security issue, follow the private reporting instructions in SECURITY.md.