Privacy policy
Last updated: October 1, 2026
Drop Down (“we”, “our”) is made and operated by Ah Yasin, an independent software developer based in Türkiye. This policy covers the Drop Down app for the Mac, its update server (updates.getdropdown.app) and this website (getdropdown.app).
The short version
- The app has no analytics, no telemetry, no ads and no account.
- The only server the app contacts is our update server. It counts update checks and downloads without storing your IP address.
- Pictures of your menu bar, your settings and the diagnostics report stay on your Mac.
- This website runs no analytics, sets no cookies and has no forms.
The app
Accessibility
Drop Down needs Accessibility permission to work. Through it, Drop Down reads the menu bar items of the apps on your Mac: where each one sits, how big it is, what kind of element it is and the label its app gives it (a title or a description), so the panel can show each item and name it for VoiceOver. To open a hidden item, it presses that item for you. For the few apps that only answer a real click, it shows the icon for a moment, clicks it and puts the pointer back; you can switch that off in Settings › General.
To tell whether a menu opened, Drop Down looks at the position, size and layer of the windows the opened app shows, never at their contents or titles. While the panel is open, it notices a mouse click outside it, so it can close. It does not read your documents or the text in your windows, and it does not record your keystrokes.
Screen Recording (optional)
With Screen Recording allowed, Drop Down takes pictures of the menu bar, and only of the menu bar, while an icon is visible: just before it hides an app’s icon, after you open one, when you press Refresh Icons, and from time to time while icons are visible. From each picture it cuts out the menu bar icons and saves them as small images on your Mac, in~/Library/Application Support/com.ahyasinsab.drop-down/ItemImages/, so the panel can show the icons as they look in your menu bar. At most 256 are kept; older ones are replaced. The pictures never leave your Mac. When Screen Recording is turned off, Drop Down deletes them, at once or at its next start. Without the permission, the panel shows app icons and no picture is taken.
What stays on your Mac
Drop Down keeps the following on your Mac and sends none of it anywhere:
- Your settings, in the app’s preferences: which apps you hide, the panel’s layout, order and shortcut, the chevron’s look and the safety options.
- What it has learned, in the same preferences: the apps that have shown a menu bar icon (their names, bundle identifiers, where they are installed, when they were first and last seen, and how many icons they showed), the order their icons last had in the menu bar, which way of opening worked for each app, and whether the last session ended normally, so that repeated crashes start it in safe mode.
- The menu bar pictures described above.
The diagnostics report
Settings › About › Save Diagnostics Report… writes a plain-text file to a place you choose. It describes your Mac (macOS version, languages, displays), this copy of Drop Down with its settings and permissions, the apps that have shown a menu bar icon (their names, bundle identifiers and the kind of place they run from), and what Drop Down logged since it started, such as which hidden icons you opened and when. It leaves out menu bar item titles, the name of your home folder, the names of other volumes and the folders of programs that are not app bundles. Drop Down never sends the report. You decide whether to share it, and with whom; please do not post it on the public feedback board.
Update checks and downloads
Drop Down updates itself with Sparkle, an open-source updater. Once a day, and whenever you choose Check for Updates…, it asks updates.getdropdown.app whether a new version exists; if you accept an update, it downloads it from the same server. Sparkle’s system profile is switched off, so the check sends no profile of your Mac: its User-Agent names only the versions of Drop Down and Sparkle, and like any request from a Mac it carries standard headers such as your preferred language, which the server does not keep. You can turn automatic checks off in Settings › General.
Like any request on the internet, these show your IP address to the server. The server is a small program we run on Cloudflare. It counts update checks and downloads, including downloads of the disk image from this website, so we know roughly how many copies are in use and which versions. For each counted request it stores:
- the time, and whether it was a check, a download or an update patch;
- the file asked for;
- the kind of client: Drop Down’s updater, a browser, a known crawler or something else;
- the version numbers of Drop Down and Sparkle, when the updater asked;
- the country Cloudflare derives from the address, as a two-letter code;
- a daily visitor token: a shortened SHA-256 hash of your IP address and the client’s User-Agent, together with the date and a secret value that exists only in Cloudflare. It changes every day, so tokens from different days cannot be matched, and it cannot be turned back into an address. It lets us estimate how many copies check in on a given day.
The server does not store your IP address or the full User-Agent, sets no cookies, and keeps no referrer, language, Mac model or macOS version. Requests it does not count (errors, release notes, other files) leave nothing behind. The counts are kept in Workers Analytics Engine in our Cloudflare account, which only we can read, and Cloudflare deletes them after three months. One honest limit: each row keeps its time to the second, so someone reading the data could in principle notice a Mac that checks at the same moment every day. We do not try to; we only look at totals, and nothing stored names you or your Mac.
Feedback
Send Feedback, in Settings › About and in the chevron’s menu, opens Drop Down’s feedback board in your browser. The board is run by UserJot (operated by LogSnag LLC), a third party, under UserJot’s privacy policy. Everything you post there, and the name you post under, is public. The app sends nothing to the board by itself.
This website
getdropdown.app is a static website served by Cloudflare. It runs no analytics, sets no cookies, has no forms and loads nothing from other sites: no fonts, scripts or trackers. To deliver the pages and keep the site secure, Cloudflare processes technical data such as your IP address and browser type, as any host does. The download button points to a file on updates.getdropdown.app, and a download is counted as described above. Links to the feedback board, X and Reddit take you to those sites, which have their own policies.
Who processes data
Cloudflare, Inc. (USA) hosts this website and the update server, under Cloudflare’s privacy policy. UserJot runs the feedback board, for what you choose to post there. These providers may process data in the United States and rely on recognised safeguards such as standard contractual clauses. We sell no data and share none with advertisers.
Legal basis
We deliver updates, count update checks and downloads, and keep the update server and this website running securely because we have a legitimate interest in doing so: offering updates to the copies in use and knowing roughly how many there are (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)). The counts are built so that they do not name you. When you write to us, we use what you send to answer you, on the same basis.
Retention
- Update counts: Cloudflare deletes them three months after they are written.
- Messages you send us: kept as long as we need them to answer you and follow up, and deleted when you ask.
- Posts on the feedback board: they stay on the board until they are removed; ask us and we remove yours.
- What Cloudflare processes to deliver this website and the update server: kept under Cloudflare’s own policy.
Your rights
Depending on where you live, including under the GDPR and Türkiye’s KVKK, you may have the right to access, correct, delete or export your personal data, or to object to how it is used. Because the update server keeps no IP address and its daily token cannot be linked back to you, we usually hold nothing we could find for you; a message you send us, or a post on the board, we can. To exercise any of these rights, reach us as described below. You may also complain to a data protection authority: in Türkiye, the Personal Data Protection Board (KVK Kurulu); in the EU, the authority where you live or work.
Children
Drop Down and this website are not directed at children under 16, and we do not knowingly collect their data.
Changes
We update this policy when the app or the website changes what they do with data. The date at the top always shows the latest version.
Contact
Write to hello@getdropdown.app.