Internet Activity
Privacy Policy
Last updated: August 15, 2026
Internet Activity is a local network-activity monitor and network-access control utility for macOS.
Information the app observes
To provide its core features, Internet Activity uses Apple's Network Extension framework to observe network activity on the Mac. Depending on what macOS makes available for a socket flow, this may include application and process identity; inbound and outbound byte counts; network protocol and connection direction; remote hostname, IP address, and port; and connection timing and status.
The packet sensor separately reports packets whose protocol is non-TCP/UDP or could not be parsed. It does not provide process identity, so Internet Activity does not assign those bytes to an app or process. macOS may also omit identity or destination information for a socket flow; the app then uses a generic label or leaves the unavailable field empty rather than guessing.
Collection, sharing, and tracking
Internet Activity does not transmit observed network activity or derived traffic history to the developer or any third party. This information is processed only on the Mac where the app is running.
The app contains no advertising, analytics SDK, telemetry service, user account, third-party SDK, or cloud synchronization. It does not sell or share network activity, and it does not use the information for tracking or advertising.
Storage and retention
Traffic history, pins, and Block/Allow rules are session-only and kept in memory. The app does not write them to disk. Quitting does not persist the dashboard's local session data; it is discarded when the process terminates. Because the developer receives no copy, there is no server-side traffic history to access or delete.
On quit, Internet Activity also requests immediate clearing of the provider's in-memory Block rules. If that message is not delivered, a provider that remains responsive clears its rules when the three-second dashboard lease expires.
System permissions and user control
macOS asks the user to approve Internet Activity's system extension and network filter before monitoring can start. The app uses the filter for the visible network-activity dashboard and user-initiated Block/Allow controls.
macOS may also ask for App Management access when Internet Activity reads an observed executable's app name and bundle identifier. If that access is denied, the app falls back to the process evidence macOS still provides or uses a generic label.
The approved system extension remains installed after ordinary quit so macOS does not ask for approval on every launch. On clean quit, Internet Activity retries disabling its own saved filter configuration. After force-quit, that saved switch may remain enabled because a terminated app cannot update system preferences; if the provider remains responsive, its expired lease nevertheless makes the filter pass-through. On relaunch, Internet Activity first disables stale saved configuration before starting a new monitoring session.
The three-second lease is app-level protection implemented by the provider and requires that provider to remain responsive. Behavior after a completely crashed, frozen, or unresponsive provider is controlled by macOS.
Internet Activity writes only its own content-filter configuration. It does not request that macOS disable encrypted DNS or Private Relay, and it does not intentionally change proxy, route, or DNS configuration. Users can manage its network filter and system extension through macOS System Settings.
Changes
If the app's data practices change, this policy and the App Store privacy disclosures will be updated before the changed version is distributed.
Contact
Questions about this policy can be sent to support@internetactivity.app.