Privacy Policy
Last updated: August 2, 2026
Introduction
D1Explorer ("the App") is a native macOS application developed by mgcrea ("we", "us", "our") that allows you to browse, query, and edit Cloudflare D1 and SQLite databases. This Privacy Policy explains how we handle your information when you use the App.
We are committed to protecting your privacy. D1Explorer is designed as a local-first application — your data stays on your device, and leaves it only for Cloudflare's API endpoints at your direction or, if you leave iCloud sync enabled, for your own iCloud account. See iCloud Sync below.
Information We Collect
D1Explorer does not collect, transmit, or store any personal information on our servers. We do not operate any backend services that receive your data, and no data is ever sent to us. The App runs on your Mac and talks only to Cloudflare, Apple, and nobody else.
Cloudflare API Tokens
To connect to your Cloudflare D1 databases, you provide API tokens within the App. These tokens are:
- Stored securely in the macOS Keychain on your device
- Used exclusively to authenticate with Cloudflare's API endpoints (
api.cloudflare.com) - Never transmitted to us, and never to any third party other than Apple's iCloud Keychain — and only then if you leave the "Sync credentials via iCloud Keychain" setting enabled
- Never logged or stored outside of the Keychain
iCloud Keychain is Apple's end-to-end encrypted credential store: tokens synced through it are readable only by your own devices, not by Apple and not by us. You can turn the setting off in Settings → General, which keeps every token on the Mac that created it.
Database Content
When you browse or query your Cloudflare D1 databases, all requests are sent directly from your Mac to Cloudflare's API. Query results are displayed locally in the App and are not persisted beyond the current session unless you explicitly export them. We never have access to your database content.
Local SQLite Files
When you open local SQLite files, the App accesses them using macOS security-scoped bookmarks. File contents remain on your device and are never transmitted anywhere.
iCloud Sync
D1Explorer can keep your connections available on every device signed into the same Apple ID. This is handled by two independent settings in Settings → General, both enabled by default. Everything synced goes to your own iCloud account — never to us.
- Sync connections via iCloud — mirrors your connection list through iCloud key-value storage. The synced record for each connection contains only its name, Cloudflare account ID, database ID, and database name. No API tokens and no database contents are ever included. Only remote Cloudflare D1 connections sync; local SQLite connections never leave the device that added them, because their file path and security-scoped bookmark cannot resolve anywhere else.
- Sync credentials via iCloud Keychain — stores your Cloudflare API tokens in Apple's end-to-end encrypted iCloud Keychain so a synced connection can open on your other devices. Tokens remain readable only by your own devices.
Turning either setting off keeps that data on the device it was created on. Because both use Apple's iCloud infrastructure, Apple's handling of it is governed by Apple's Privacy Policy.
Analytics and Tracking
D1Explorer does not include any analytics SDKs, tracking pixels, or telemetry. We do not track your usage patterns, feature usage, or any other behavioral data.
Crash Reporting
If you have opted in to share diagnostics with app developers through macOS Settings, Apple may share anonymized crash reports with us. This is controlled entirely by your macOS privacy settings and can be disabled at any time in System Settings → Privacy & Security → Analytics & Improvements.
Third-Party Services
The App communicates only with:
- Cloudflare API (
api.cloudflare.com) — to manage and query your D1 databases, using your own API tokens - Apple App Store — for license validation and in-app purchases, managed by Apple
- Apple iCloud — if you leave iCloud sync enabled, to carry your connection metadata and, separately, your API tokens between your own devices. See iCloud Sync above for exactly what is included
We encourage you to review Cloudflare's Privacy Policy and Apple's Privacy Policy for details on how they handle your data.
Data Storage and Security
We employ the following security measures:
- macOS Keychain for secure credential storage
- App Sandbox to restrict the App's access to system resources
- Security-scoped bookmarks for safe access to user-selected files
- HTTPS for all network communications with Cloudflare
- iCloud Keychain, Apple's end-to-end encrypted credential store, for any API tokens you choose to sync between your own devices
Children's Privacy
D1Explorer is not directed at children under the age of 13. We do not knowingly collect any personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
Contact
If you have any questions about this Privacy Policy, please contact us at support@mgcrea.io.