Privacy Policy

This policy covers Starkive Manifest for macOS and Starkive Scanner for iPhone, together “the apps”. They are one product and share one register.

Last updated 5 August 2026 · Depalo Consulting LLC

The short version

Starkive Manifest has two workspace modes, and which one you choose decides everything on this page.

LOCAL  Your register is a file on your own Mac. The apps talk to each other over your own network and to nothing else. We receive no data of any kind. There is no account, no telemetry, and nothing for us to hand over, lose, or be compelled to produce.

CLOUD  Your register syncs through infrastructure we operate so your devices agree with each other. We do store your inventory. Some of it we can read; the most sensitive parts are encrypted on your device with a key we never receive, and those we cannot read even if asked. The rest of this page is precise about which is which.

We would rather lose a sale than be vague here. If a sentence below is not what you assumed, that is the sentence doing its job.

1. Who we are

Depalo Consulting LLC (“we”, “us”) is the developer of the apps and, for cloud workspaces, the controller of the data described in section 3. Reach us at [email protected].

2. Local workspaces

A local workspace stores its register in a database file on your Mac, inside the app’s own container. A paired iPhone holds its own copy and syncs directly with that Mac over your local network, using TLS with a certificate the phone pins at pairing time.

In this mode we collect nothing. No account is required, no analytics are sent, and no part of your inventory is transmitted to us. If you never turn on a cloud workspace, we never hold anything belonging to you.

Two things in this mode may send data somewhere that is not us, and both are yours to switch on:

  • Backups you choose to make. If you enable iCloud Drive backup, snapshots are written to your iCloud account under Apple’s terms. We have no access to them.
  • Integrations you configure. Directory sync (Okta, Microsoft Entra) and warranty or lease lookups (Dell, Lenovo, HP, CSI Leasing) run from your Mac using credentials you supply, directly to those vendors. Serial numbers and similar identifiers go to the vendor you asked. Nothing routes through us.

3. Cloud workspaces

A cloud workspace syncs through a Supabase project we operate, hosted in the United States, so that a Mac and a phone can hold the same register without being on the same network. This is the mode in which we hold your data.

What we can read

Stored so it can be indexed, searched and synced:

  • Asset records: tags, serial numbers, makes, models, types, statuses, purchase and warranty dates, locations, sites and stockrooms.
  • Your people directory as you enter or import it — names, departments, and the assignment linking a person to a device. These are your colleagues’ details, in your inventory, and you are responsible for having a basis to hold them.
  • Vendors, contracts, lease schedules, consumables and repair records.
  • The account email address you sign in with, and the identifiers of the devices you have admitted to the workspace.

What we cannot read

Encrypted on your device before it is sent, with an organisation key generated on your Mac or iPhone. That key is wrapped to each device you admit and to a twelve-word recovery phrase shown once, which you write down. We never receive the key or the phrase. If every one of your devices is lost and the phrase is gone, this data is unrecoverable — by you and by us. That is the trade, and it is deliberate:

  • Which assets fall in a card-data environment, or hold health records, controlled unclassified information, or personal data.
  • Disposal evidence: destruction witness names and sanitization certificate references.
  • Lease payment terms.
  • Whether a disk’s recovery key is escrowed.
  • Photographs and file attachments captured against an asset.

Access

Rows are separated per organisation and enforced at the database, not in the app. We do not read customer records as a matter of course; staff access happens only where you ask for support and only for as long as that takes.

4. What we never do

  • No tracking. The apps contain no advertising identifier, no analytics SDK, no crash reporter, and no third-party telemetry. We do not build a profile of you and we do not track you across apps or websites.
  • No selling or sharing. We do not sell personal information and we do not share it for advertising. We never have.
  • No training. Your inventory is not used to train any model, ours or anyone else’s.
  • No cloud AI. Manifest’s AI features run on your own device using Apple’s on-device Foundation Models. Your records are not sent anywhere to be summarised, ranked, or answered.

5. Permissions the apps ask for

PermissionWhy
CameraScanning asset tags and pairing codes, and photographing equipment condition. Images stay on the device in a local workspace.
Photo libraryAttaching a photograph you already took. Only the item you pick is read.
Local networkFinding and connecting to your own Mac. Used for nothing else, and never to scan for anything but Manifest.
Face ID / Touch IDUnlocking the register held on the device. Biometrics are handled by iOS; we never see them.

6. Payments

Subscriptions are sold through the App Store. Apple processes the payment and we never see your card details. We receive confirmation that a subscription is active so the app can unlock, and nothing more.

7. Keeping and deleting data

Local workspaces: you already hold everything. Deleting the app, or the workspace folder, deletes it.

Cloud workspaces: we keep your data for as long as the workspace exists. Email us and we will delete the workspace and everything in it within 30 days, backups included. You can also export your register to CSV from inside the app at any time, without asking us, and we would rather you did that first.

An audit trail is deliberately not editable from the apps — that is what makes it evidence. Deleting the workspace deletes the trail with it.

8. Your rights

Depending on where you live you may have rights to access, correct, export, or delete personal data we hold, to object to processing, and to complain to a regulator. For local workspaces there is nothing for us to produce. For cloud workspaces write to [email protected] and we will answer within 30 days. We will not charge you for it and we will not make the product worse for you for having asked.

9. Children

The apps are business tools, are not directed at children, and we do not knowingly collect data from anyone under 16.

10. International transfers

Cloud workspaces are hosted in the United States. If you use one from elsewhere, your data is transferred there. Local workspaces involve no transfer at all, which for some customers is the entire reason to choose one.

11. Changes

If we change this policy we will update the date at the top, and if a change materially affects what we hold or who can read it we will tell affected customers by email rather than relying on you to notice.

12. Contact

Depalo Consulting LLC · [email protected]

← Back to Starkive Manifest