Privacy & security
What leaves your machine
The complete data flow, short enough to fit on one page — and every request on it is one you can see.
The scan stays here#
Scan results are never uploaded. Your projects, ports, branches, folder paths and metrics are read on your machine, rendered on your machine, and discarded on your machine. There is no account to sync them to and no server that would accept them.
The traffic, itemised#
Pip is private, not silent — the Network tool could hardly measure your connection without touching it. Every kind of request it makes is on this list, and each one is either visible on screen or something you asked for:
- Licence checks
- Activation, and a quiet background revalidation. They carry your key, a salted one-way device hash, and your machine's name — the label you see beside the seat.
- Connection probes
- Pings to your router and an internet anchor, every 2 seconds, so the Network tool always has a current reading. Measurements — nothing about you rides along.
- Speed tests and checks you run
- A speed test moves data to the nearest of Pip's own nodes; diagnostics query public DNS resolvers; a host check contacts the host you typed. All on demand, never on their own.
What is not on the list: telemetry, analytics, crash beacons, accounts, or anything read from a scan. The licence itself is stored encrypted with Windows DPAPI, readable only by your Windows user account on that machine.
The window is only a window#
Pip is two halves: a Rust core that does the work, and a webview that draws it. Everything on the list above is the core. The window itself cannot open a file, start a connection or run a shell — it can only send typed commands inward, and none of those commands carries a filesystem path.
That is why a speed test can move hundreds of megabytes while this still holds: the request comes from the core, because the interface has no way to make one. Even adding a folder for Storage to scan opens the operating system's own picker rather than accepting a path, so the window can only ever name things the core already knows about.
Fonts ship inside the binary. There are no CDNs, no remote assets and no analytics beacons, which also means nothing breaks when you are offline.
In legal terms#
Note
This page is the plain-language version. The binding one is the Privacy Policy, which also covers billing, support correspondence and crash diagnostics — the things that involve us because you sent them to us.
Did this page not answer it? Tell us what you were looking for — that is how Pip's documentation gets written.