Privacy Policy
Effective July 22, 2026
Overview
Windsock is a native client for Bluesky and other compatible AT Protocol services. The app connects directly to the services associated with the account you choose; Pixel Fox Studios LLC does not operate an account, content, or analytics server for Windsock.
Information the app processes
- Account and authentication data: your decentralized identifier, handle, account presentation details, OAuth access and refresh tokens, and the DPoP key used to authenticate requests. Credentials and keys are stored in the macOS data-protection keychain on your Mac.
- Social content: profiles, feeds, posts, notifications, lists, and conversations requested from your social provider. Windsock keeps local caches, reading positions, notification state, drafts, mute rules, and app preferences so the app can work as expected.
- Content and actions you submit: posts, profile changes, messages, reactions, follows, list changes, moderation preferences, notification read state, and media you select are sent to the relevant AT Protocol service to perform the action you requested. Security-scoped file bookmarks can be stored locally for media attached to saved drafts.
- Purchase status: Windsock uses Apple StoreKit to offer and restore the app purchase. Apple processes the transaction; Windsock reads the resulting purchase entitlement.
Direct messages
Bluesky direct messages are not end-to-end encrypted. They are stored by Bluesky’s central chat service and can be accessed by Bluesky and the people in the conversation. Do not use direct messages for sensitive information.
Analytics, advertising, and tracking
The Windsock app does not include a third-party analytics SDK, advertising SDK, or developer-operated crash-reporting service. These static website pages contain no advertising pixels, analytics scripts, cookies, or forms. The services you connect to, Apple, and the website hosting provider may process network or transaction information under their own policies.
Storage, retention, and deletion
Windsock stores its credentials, database, preferences, and draft attachment access on your Mac. Signing out removes that account’s saved credentials and purges its disposable post/feed caches and reading positions. Drafts, mute rules, and local notification state remain in the shared app database unless you remove them or the app’s data. The shared, session-independent image cache also remains after sign-out. Settings provides controls to clear both the post/feed caches and the shared memory/disk image cache, and to reveal the local data folder. Removing the app does not delete content already submitted to your social provider; use that provider’s controls for server-side content and account requests.
Policy changes and questions
Material changes will be posted on this page with a new effective date. Visit Windsock Support or email hello@pixelfoxstudio.com with questions.