Docket / Privacy

Privacy policy

Docket is desktop software that runs on your Mac. This policy covers both the application and this website.

The application

Docket collects nothing. There is no account, no telemetry, no crash reporting and no licence check.

An earlier version of this policy said the only network requests the app makes are to the website you ask it to audit. That was not accurate, and a privacy policy is the last document that should be approximately true. Docket makes requests to three kinds of destination:

Every connector can be turned off individually, and an offline switch disables all of them at once, leaving only the crawl of your own site.

Audit results and your saved-site list are stored on your machine in ~/.docket/ as plain JSON files. They are never transmitted. Deleting that folder removes them permanently.

This website

This site is static and runs five third-party scripts. The first is Plausible, which counts page views. Plausible states that it uses no cookies, collects no personal data and does not track visitors across sites; it is hosted in the EU. Nothing about your audits reaches it — audits run on your Mac and this website never sees them. Standard server logs may record IP addresses and requested URLs, which are used only to keep the site running.

The second is Sled, which credits the right person when somebody recommends Docket. It is conditional: arrive through an affiliate link and a single ta_ref cookie records which affiliate sent you, so they are paid if you buy. Arrive from a search result, a bookmark or a link of ours and no cookie is set at all — which is what almost every visitor does. It records which affiliate sent a visit, never who the visitor is.

The third is the Meta pixel. It is here because we advertise on Facebook and Instagram, and without it we cannot tell which adverts bring people who actually download Docket — only how much we spent. It records that a page was viewed and sets a _fbp cookie, which lets Meta connect a visit here to an advert you saw there. Its id is 2344029433088526, visible in this page's source; that is normal for a pixel and not a secret. It sees pages on this site. It does not see your audits, which run on your Mac and are never uploaded.

This is the most intrusive thing on the site and it is the one we would least like to need. A content blocker stops it, as does Meta's own off-Facebook activity setting, and nothing here depends on it loading.

The fourth is the chat assistant in the corner of the page, which answers questions about Docket. Its script is loaded from kerr-lead-agent.kerrco.workers.dev, a server we run. The assistant stores nothing in your browser — no cookie of its own, no local storage, no session storage — and it reads nothing about your device. It draws itself in an isolated shadow root, so it cannot see or change the rest of the page. If you type a question into it, that question is sent to that server so it can be answered; if you never open it, nothing is sent. It knows only published facts about Docket, and the price it quotes comes from the payment provider rather than from this page, so it cannot quote you a price the checkout will not honour.

The fifth is on the front page only, and not on this one: a “tell me when Windows is ready” form, loaded from kerr-subscribe.kerrco.workers.dev, a server we run. Like the assistant it draws itself in an isolated shadow root and stores nothing in your browser — no cookie, no local storage, no session storage. Nothing is sent unless you type an address and press the button, and what is sent is that address and which site it came from, so the Windows list stays separate from every other list. If you never use the form, it makes no request at all.

These paragraphs have been rewritten three times as the answer changed. They once said the site “sets no cookies” and runs “one third-party script”; both were true until Sled was added. The line calling Sled the only thing here that can set a cookie was true until the Meta pixel was. The count said three until the chat assistant was added, and the description on this page still said three after the body said four — caught by our own audit and corrected to five, which is when the Windows form on the front page was counted too. This paragraph is the reason that was noticed: each correction is made above rather than quietly deleted. A privacy page that enumerates what a site does not do is only worth reading if the enumeration stays complete.

If you would rather not be counted, any content blocker stops it, and nothing on this site depends on it loading.

Data you give us

The home page has one email field. Leave your address and we will email you once, when the free audit is ready — it is not a newsletter and there is no series to subscribe to. The form sends exactly two things, and only when you press the button: the address you type, and a hidden field naming which of our sites it came from. Nothing is sent if you never use it.

What is kept is that address, the site name, and the date. No IP address, no user agent, no referer, no fingerprint — the write stores those three columns and reads nothing from the request. To be removed, ask and the row is deleted.

This section said “there is no contact form and no mailing list” until 2026-08-24. The field went live on 2026-08-18, so the denial stood for six days while addresses were being collected. It is corrected here rather than quietly rewritten, for the reason given two paragraphs above: an enumeration of what a site does not do is worth nothing unless it is kept complete, and this is the enumeration failing.

If you open an issue on GitHub, that issue is public and GitHub's privacy policy applies to it; we hold nothing separately.

Changes

If this policy changes, the updated version appears on this page.

Contact

Questions about privacy or anything else: get in touch.