Privacy Policy

This policy covers Starkive Manifest for Mac and for iPhone, together “the apps”. They are one product and share one register.

Last updated 23 September 2026 · DePalo Consulting LLC

Local

Your register lives on your own Mac, or on your iPhone if that is the only device. The apps talk to each other over your own network. We receive none of your inventory. There is no account and no telemetry. The only thing that reaches us is a support message, if you choose to send one.

Cloud

Your register syncs through infrastructure we operate so your devices agree with each other. We do store your inventory. Some of it we can read; the most sensitive parts are encrypted on your device with a key we never receive, and those we cannot read even if asked. The rest of this page is precise about which is which.

Starkive Manifest has two workspace modes, called “This Mac and my devices” and “Starkive Cloud” in the apps, and which one you choose decides everything on this page. We would rather lose a sale than be vague here. If a sentence below is not what you assumed, that is the sentence doing its job.

1. Who we are

DePalo Consulting LLC (“we”, “us”) is the developer of the apps and the controller of the data described in section 3, and of any support message you send us. Reach us at support@depaloconsultingllc.com.

2. Local workspaces

A local workspace stores its register in a database file on your Mac, inside the app’s own container, or on your iPhone if you set one up there on its own. A paired iPhone holds its own copy and syncs directly with that Mac over your local network, using TLS with a certificate the phone pins at pairing time. Manifest does not encrypt the register file itself; FileVault on the Mac and a passcode on the iPhone do that.

If an iPhone already holds asset changes the first time it pairs with a Mac, it keeps them and asks what to do: send them to this Mac, hand them over for review on the Mac, keep them on the iPhone for now, or discard them. None of those changes is sent until you choose. Before it sends, the phone asks the Mac whether any of the serial numbers or asset tags are already in use there. That question and its answer go between your own two devices, over your own network, and nothing about it reaches us.

In this mode there is no telemetry or analytics, and none of your inventory reaches us. The only thing we receive is a support message, if you send one. No account is required. If you write to us from Get help in the app, we keep what you wrote and its subject, the reply address you gave, the topic, the app version and build, the iOS or macOS version, and which kind of workspace you are in. If the app has anything else worth telling us, like the last sync fault or how many photographs are still waiting, it adds that too, and there is a switch to leave it out. Those extra lines can also name your organisation, and in a cloud workspace the account you are signed in as; they are on by default, and the same switch leaves them out. The form lists every line before you send it, and none of it is your inventory: no assets, no serials, no photographs.

Two things in this mode may send data somewhere that is not us, and both are yours to switch on:

  • Backups you choose to make. If you enable iCloud Drive backup, snapshots are written to your iCloud account under Apple’s terms. We have no access to them. Manifest does not encrypt these snapshots, or CSV exports; Apple’s iCloud protections apply, and Advanced Data Protection adds end-to-end encryption if you need it. On an iPhone that keeps its own register, the register and its photographs are part of the iPhone’s own iCloud backup if you have that turned on, and they stay in it when the phone pairs with a Mac. An iPhone that only holds a copy of a Mac’s or Starkive Cloud’s register leaves the register out of its backup.
  • Integrations you configure. Directory and device management sync (such as Okta, Microsoft Entra, Intune, Jamf Pro and Google Workspace), warranty or lease lookups (such as Dell, Lenovo, HP, Apple and CSI Leasing) and any webhook you add run from your Mac using credentials you supply, directly to that service. Serial numbers and similar identifiers go to the service you asked. Nothing routes through us.

3. Cloud workspaces

A cloud workspace syncs through a Supabase project we operate, hosted in the United States (AWS us-east-1), so that a Mac and a phone can hold the same register without being on the same network. This is the mode in which we hold your data.

What we can read

Stored so it can be indexed, searched and synced:

  • Asset records: tags, serial numbers, makes, models, types, statuses, purchase prices, purchase, warranty and lease dates, lessors, cost centres, locations, sites and stockrooms, and how a disposal was done and when.
  • The network details on an asset record: hostnames and MAC addresses, operating system and version, whether it is under device management, and when it was last seen and where that date came from.
  • The audit evidence on an asset record: whether it is approved to connect, who reviewed that and when, what it is used for, end of support, due back and received dates, invoice number, GL account, depreciation method, disposal proceeds and the ITAD vendor, and the sanitisation tool version and how the wipe was verified.
  • A yes or no for whether an asset carries regulated data, and its data classification. Which kind of regulated data it carries is encrypted (see below).
  • When an asset was written off its book value, and the name of the person who did it.
  • The names, types and choices of the custom fields you define, which kinds of asset each is offered on, and whether its values are kept off Starkive Cloud. The values you enter in them are encrypted (see below), or never sent at all.
  • Your people directory as you enter or import it: names, email addresses, departments, job titles, locations, employee IDs, worker type, manager, start and end dates, and which device each person holds. These are your colleagues’ details, in your inventory, and you are responsible for having a basis to hold them.
  • Vendors, contracts and their costs, licences, lease schedules, consumables and stock movements, requests, jobs, repairs and returns, and the status and dates of a loss or theft report.
  • For each job and request: its number (like JOB-0001 or REQ-0001), a job’s due date if you set one, and who checked a job’s report and when. We also keep a record of which blocks of numbers were given to which account and device, so that no number is ever handed out twice. Like the rest of the register, these are your organisation’s records.
  • For each attachment: which record it belongs to, its type, size and category, and who added it. The file itself is encrypted.
  • The audit trail’s outline: which asset changed, when, and the account email that made the change. A log of who revealed a protected field, and when.
  • The account email address you sign in with, the account identifier issued to you when you sign up, the email addresses of people you invite, and the names and identifiers of the devices you have admitted to the workspace.

What we cannot read

Encrypted on your device before it is sent, with an organisation key generated on your Mac or iPhone. That key is wrapped to each device you admit and to a twelve-word recovery phrase shown once, which you write down. We never receive the key or the phrase. If every one of your devices is lost and the phrase is gone, this data is unrecoverable, by you and by us. That is the trade, and it is deliberate. Until an owner sets up encryption, this data waits on your devices and is not sent at all; once it is on, it cannot be turned off.

  • Which assets fall in a card-data environment, or hold health records, controlled unclassified information, or personal data.
  • Disposal evidence: destruction witness names, sanitization certificate references, who authorised it and who verified it.
  • An asset’s lease rent, lease rate factor, residual value, and its support and recurring costs.
  • Whether a disk’s recovery key is escrowed.
  • Photographs and file attachments, including their file names and notes.
  • Condition notes and return notes.
  • The values you enter in custom fields.
  • The reasons and police report numbers written on a loss or theft report, and notes on remediation tasks.
  • What changed in each audit trail entry written by the apps. Changes made through the API, and some edits from older iPhone builds, keep the field and its new value readable.

What is never sent to us

IP addresses are not part of what we hold. You type a device’s IP address in yourself, and it stays on your own devices. The same goes for the values of any custom field you set to “Keep off Starkive Cloud”. Both can travel over your local network between your own paired Mac and iPhone. Neither is sent to Starkive Cloud, and the audit trail we hold records only that such a value changed, not what it was.

Access

Rows are separated per organisation and enforced at the database, not in the app. We do not read customer records as a matter of course; staff access happens only where you ask for support and only for as long as that takes.

4. What we never do

  • No tracking. The apps contain no advertising identifier, no analytics SDK, no crash reporter, and no third-party telemetry. We do not build a profile of you and we do not track you across apps or websites. We do not record your IP address in anything we build; the services that run Starkive Cloud and this website keep standard request logs, as every web service does.
  • No selling or sharing. We do not sell personal information and we do not share it for advertising. We never have.
  • No training. Your inventory is not used to train any model, ours or anyone else’s.
  • No cloud AI. Manifest’s AI features run on your own device using Apple’s on-device Foundation Models. Your records are not sent anywhere to be summarised, ranked, or answered.

5. Permissions the apps ask for

PermissionWhy
CameraScanning asset tags, serials and pairing codes, and photographing equipment. In a local workspace, images stay on your own devices: a photo taken on a paired iPhone is sent to your Mac over your own network.
Photo libraryAttaching a photograph you already took. Only the item you pick is read.
NFC (iPhone)Writing and reading the tags you stick on your equipment. A tag holds a link to the record and nothing else.
Local network (iPhone)Finding and connecting to your own Mac. Used for nothing else.
Local network (Mac)Discover lists the devices your Mac can see on your network so you can add them as assets, and lets a paired iPhone sync with the Mac directly. Nothing from it is sent to us.
Face ID, Touch ID or passwordUnlocking the register held on the device. Biometrics are handled by Apple; we never see them.

6. Payments

Subscriptions are sold through the App Store. Apple processes the payment and we never see your card details. We receive confirmation that a subscription is active so the app can unlock, together with the App Store transaction identifier for that subscription, which we keep.

We keep it because one transaction opens one workspace, permanently. It is what stops a single subscription being used to open a second. It is not a card number, it is not linked to anything you buy elsewhere, and it tells us nothing about your other purchases.

7. Keeping and deleting data

Local workspaces: you already hold everything. Deleting the app, or the workspace folder, deletes it.

Cloud workspaces: Starkive Cloud is hosted in the United States (AWS us-east-1), and we don’t keep your data after you leave: if your subscription ends we email you twice and permanently delete your organisation’s records and files 30 days later, and deleting your account removes them straight away. You can delete your account yourself in either app: on the iPhone, the gear at the top of Home › Account and plan › Delete this account; on the Mac, the sync status at the foot of the sidebar › Delete account. Closing the last account on a workspace deletes the workspace and everything in it. Or email us and we will do it within 30 days, backups included. You can export your register to CSV from inside the app at any time, without asking us, and we would rather you did that first.

An audit trail is deliberately not editable from the apps. That is what makes it evidence. Deleting the workspace deletes the trail with it, and we keep one receipt of the deletion: the organisation’s name, how many trail entries were removed, a fingerprint of the last one, when it happened, and which account asked. It holds nothing about any asset or person.

8. Your rights

Depending on where you live you may have rights to access, correct, export, or delete personal data we hold, to object to processing, and to complain to a regulator. For local workspaces we hold nothing of yours except any support messages you sent. For cloud workspaces write to support@depaloconsultingllc.com and we will answer within 30 days. If you ask us to erase a person, we replace their name in the audit trail and record that we did. We will not charge you for it and we will not make the product worse for you for having asked.

9. Children

The apps are business tools, are not directed at children, and we do not knowingly collect data from anyone under 16.

10. International transfers

Cloud workspaces are hosted in the United States (AWS us-east-1). If you use one from elsewhere, your data is transferred there. Local workspaces involve no transfer of your inventory at all, which for some customers is the entire reason to choose one. A support message, if you send one, is stored in the United States.

11. Changes

If we change this policy we will update the date at the top, and if a change materially affects what we hold or who can read it we will tell affected customers by email rather than relying on you to notice.

12. Contact

DePalo Consulting LLC · support@depaloconsultingllc.com

See also: how the register is protected.