# Safe & honest

> What Desktop Pals do and don't do, in plain English: no accounts, no tracking, no data collection, no ads, no crypto mining. Standalone pals only ever read two podcast feeds; PalPlayer also checks for updates.

In the early 2000s a “free desktop buddy” often came with adware, spyware or worse. These don't. Here's exactly what Desktop Pals do – checked line by line against the code that ships in them.

## The short version

- **No accounts.** Nothing to sign up for, no email address, no licence key.
- **No tracking.** No analytics, no telemetry, no crash reporting, no “usage statistics”. Nothing about you or your computer is ever sent anywhere.
- **No data collection.** The pals don't read your files, your screen, your keyboard or your clipboard, and they never ask for your camera or microphone. (Dot's microphone is a drawing.)
- **No ads, no crypto mining, no bundled extras.** The download is the pal and nothing else.
- **Nothing running in the background.** When you close a standalone pal, it's gone. It doesn't start itself when your computer starts, and it doesn't install any services, helpers or updaters. ([PalPlayer](https://palstudio.whitefishcreative.co.uk/safe/#palplayer) is different: it can start at login and update itself, both of which you can switch off.)
- **Almost no internet.** Dot and The Cynical Developer each read one public podcast feed so they can tell you about new episodes. The Creatures pals never go online at all.

## What goes over the internet

The whole list:

| Pal | Fetches | How often | Why |
| --- | --- | --- | --- |
| [Dot](https://palstudio.whitefishcreative.co.uk/pals/dot/) | `dotnetcore.show/llms.txt` (the show's public summary, which lists its feed), then the show's public RSS feed at `thedotnetcorepodcast.libsyn.com/rss` | About 15 seconds after it starts, then hourly | To tell you about new (and old) episodes of The Modern .NET Show |
| [The Cynical Developer](https://palstudio.whitefishcreative.co.uk/pals/cynical-developer/) | The podcast's public RSS feed at `cynicaldeveloper.com/feed/podcast/` | About 15 seconds after it starts, then hourly | To tell you about new (and old) episodes of The Cynical Developer |
| [Norns](https://palstudio.whitefishcreative.co.uk/pals/norns/), [Grendel](https://palstudio.whitefishcreative.co.uk/pals/grendel/), [Ettin](https://palstudio.whitefishcreative.co.uk/pals/ettin/) | Nothing | Never | – |

A feed check is an ordinary web request for a public file – the same thing your podcast app does. It carries no account, no ID and nothing about you; the only label it adds says “PalStudio/1.0 (+feed reader)”. Like any web request, the server at the other end sees your IP address, just as it would if you visited the site.

You can switch it off: untick **Check for new episodes & posts** in the pal’s menu and it stops. If you’re offline, the pal simply stays quiet about episodes and tries again later.

### Links

A pal only opens a web page when **you click** on it – “Yes please” on an episode, for example – and it opens in your normal browser. It can only open links that came from its own feed, plus the WhiteFish Creative website from its About box. Nothing opens on its own.

## PalPlayer

[PalPlayer](https://palstudio.whitefishcreative.co.uk/palplayer/) runs pals from pal packs, so it does a few things a standalone pal doesn’t:

- **It updates itself and your official pals.** Now and then it fetches one public file from this website listing the latest versions. The request carries no ID, no account and nothing about you or your pals – the same as opening a web page. Downloads are checked against our signature before anything is installed. Switch it off any time: **PalPlayer → Settings → Update automatically**.
- **Get pals lists the official pals.** Only when you open the **Get pals** tab, PalPlayer fetches the list of pals (one public file, plus each pal’s picture) from this website – again with no ID and nothing about you. A pal you choose to get is checked against our signature before it can be added.
- **It can start at login**, if you tick **Start at login** on a pal.

Pal packs are data only – pictures, sounds and lines – never programs. When you add one, PalPlayer shows you what it’s allowed to do (for example “Never goes online” or “Reads news from …”) before you say yes. Community pals, made by other people, are always labelled **Community**.

## What a pal can see

- **Where your mouse pointer is.** That’s how Dot’s eyes follow it, how “Come here” knows where to walk, and how the pal knows you’re hovering over it (so clicks go to the pal, and everything else goes straight through to your windows). The position is used there and then and never stored or sent anywhere.
- **The size of your screen**, so it knows where it can walk.
- **Whether your computer is in light or dark mode**, so it can match.
- **The time of day** – The Cynical Developer checks his phone at 9:05 and dozes off at 3pm; the Creatures pals go to sleep late at night.

That’s it. No keyboard, no screen contents, no files, no clipboard, no contacts, no location, no camera, no microphone.

## What’s kept on your computer

Each pal keeps a small settings folder, and it stays on your computer:

- **Your choices** – light/dark, sound and quiet hours, which Creatures type you picked and how many are in your herd.
- **Which episodes it’s already told you about** (Dot and The Cynical Developer only), so it doesn’t announce the same one twice.
- The usual working files that every app built on Electron (the framework the pals use, the same one behind many desktop apps) keeps for itself.

It lives in a folder whose name starts with `DesktopPals-`:

- **Mac:** `~/Library/Application Support/`
- **Windows:** `%APPDATA%` (usually `C:\Users\you\AppData\Roaming\`)

Delete it any time; the pal just starts fresh. See [how to uninstall](https://palstudio.whitefishcreative.co.uk/faq/#uninstall).

## How it’s built and signed

- **Mac:** every Mac download is signed with WhiteFish Creative Limited’s Apple Developer ID and **notarised by Apple**, which means Apple has scanned it for malware. It opens without warnings. To check for yourself, open Terminal and run:
`spctl -a -vv -t open --context context:primary-signature Dot-1.0.0-arm64.dmg` – it should say *accepted*, *Notarized Developer ID* and *WhiteFish Creative Limited*.
- **Windows:** the pals aren’t code-signed on Windows yet (Windows certificates are a whole other adventure), so SmartScreen may warn you the first time. We’d rather tell you that than hide it. Each download lists its **SHA-256 fingerprint** so you can check the file you have is exactly the file we built.
- **Locked-down windows:** the pal’s own windows only load files that shipped inside the app – they refuse to load anything from the internet. The only code that talks to the network is the small feed reader described above.
- **No admin rights:** the Windows installer installs just for you, and the portable version doesn’t install at all.

## About the Creatures pals

Creatures, Norns, Grendels and Ettins are from Creatures 2 by CyberLife Technology / Creature Labs. The fan-made breeds are credited to their creators on each pal’s page.

## About this website

This site doesn’t use cookies, analytics or trackers either, and it doesn’t load anything from other companies’ servers. The links to the podcasts, and to [whitefishcreative.co.uk](https://whitefishcreative.co.uk), take you to those sites. The full details are in our [privacy policy](https://palstudio.whitefishcreative.co.uk/privacy/).

## Spotted something?

If a pal ever does something this page says it doesn’t, we want to know – [get in touch](https://whitefishcreative.co.uk/#contact).

---

From PalStudio – Desktop Pals by WhiteFish Creative Limited. Web page: https://palstudio.whitefishcreative.co.uk/safe/ · The whole site for AI assistants: https://palstudio.whitefishcreative.co.uk/llms.txt
