What Routekeeper knows and where it doesn’t go
Routekeeper doesn’t collect data about you or your traffic and doesn’t send it anywhere. Everything it knows about your connections stays on your Mac.
In effect from the first public version of Routekeeper. Revised October 3, 2026.
What Routekeeper sees
To decide where a connection goes, the Routekeeper system extension sees, for every outgoing connection:
- which process opened it: path, code signature, parent processes;
- where to: address, port, protocol and host name, if the app provided one;
- how much data went through, how long it took and how it ended.
Routekeeper doesn’t read what’s inside connections. Traffic sent through a proxy is passed on as is, without decrypting it.
Where it’s kept
| What | Where | For how long |
|---|---|---|
| Connection log for the monitor | In the system extension’s memory, the last few thousand entries | Until the extension restarts. Never written to disk. |
| Rules, proxy list, settings, proxy passwords | The system extension’s configuration file, readable only by root | Until you delete them. Kept when the app is removed, so your rules come back if you reinstall. |
| Service logs | The macOS system log (unified logging) | As long as macOS keeps them, usually a few days. |
The Routekeeper window receives settings without proxy passwords.
Service logs contain technical events: startup, errors, decisions about connections. They may include addresses that apps connected to. Logs don’t leave your Mac unless you attach them to a bug report yourself. “Collect diagnostics” in Settings puts an archive on your desktop and sends it nowhere.
The traffic map looks up countries and networks in a database built into the app (DB-IP Lite), without any requests to the internet.
What Routekeeper connects to on its own
- Your proxies — to carry the traffic of apps you routed through a proxy.
- ipinfo.io, through your proxy — to show the latency, address and country that websites see. This happens when you click “Check”, save a proxy or open the proxy list. For the primary proxy, also when you open the menu bar or the Routekeeper window, at most once a minute, a few seconds after the network changes if the proxy was checked before, and once a minute while the check keeps failing. The request goes through the proxy, so ipinfo.io sees the proxy’s address, not yours.
- Updates — once a day and when you click “Check for Updates…”. Routekeeper downloads the version list (
appcast.xml) from getroutekeeper.app and, if you agree to update, the build itself from the GitHub releases page. The request carries only the Routekeeper and macOS versions. The site and the builds are hosted on GitHub, so GitHub sees your Mac’s address, as with any page of the site. You can turn automatic checks off in Settings: “Check for updates automatically”.
Nothing else. No analytics, telemetry, crash reports or advertising identifiers.
Your proxies
Traffic you send through a proxy is visible to whoever runs the proxy server. Routekeeper can’t vouch for it: use proxies you trust.
If you contact us
Bug reports in GitHub Issues are public. Before attaching a log or a diagnostics archive, look through it and remove anything you don’t want to share.
Changes
If this policy changes, the new revision will appear on this page, and the history of changes in the repository history.