Privacy policy
Last updated: 6 September 2026
1. Who we are and what this policy covers
File Sniff is provided by Peth Pty Ltd (ACN 652 727 136), an Australian company. In this policy, “we”, “us” and “our” refer to Peth Pty Ltd. “You” refers to a person using File Sniff or contacting us.
This policy covers the File Sniff website at www.filesniff.dev, its free browser-based file checker, the File Sniff apps for Mac, iPhone and iPad, and enquiries about these services. It describes the current website and pre-release apps. It does not describe the data practices of our other products.
Personal information means information about an identified or reasonably identifiable person. We handle personal information in accordance with applicable privacy law, including the Australian Privacy Act 1988 and Australian Privacy Principles where they apply. The additional rights described below apply where EU or UK data protection law applies to our processing.
2. Local file analysis
File Sniff identifies and inspects files on your device. We do not receive file contents, filenames, paths, file hashes or inspection results simply because you run a local scan.
The native apps may read file contents and metadata needed for the features you choose, including image metadata, embedded provenance and file signatures. Analysis does not upload this information to us. Files available through a cloud drive or file provider may be downloaded or synchronised by that provider under your device settings; this is separate from File Sniff’s analysis.
The browser checker reads only files you select or drop into it. It does not send their contents or names to a server, execute or render their contents, or save results in cookies or browser storage. Results stay in the current page until cleared, replaced by another batch, or the page is closed or reloaded. Choosing Save results as JSON downloads a results file to your device.
The native apps may keep local preferences, temporary copies used for sharing or export, and diagnostic files within their app containers. The iOS share extension and app can exchange selected files through a shared app container on your device. Copies, exports and files saved to destinations you select may remain there until you delete them. Your operating system or backup provider may include local app data in its backups.
3. Optional external services and sharing
VirusTotal actions on Mac
If you choose the VirusTotal lookup action, File Sniff calculates a SHA-256 hash locally and opens a VirusTotal report URL in your browser. The hash is sent to VirusTotal as part of that request, together with information normally sent by your browser, such as your IP address. A hash is not the file itself, but it can identify a particular file and reveal that you are checking it. The URL may also appear in your browser history or synchronised browsing data.
The separate upload action opens VirusTotal’s upload page and reveals the file in Finder. File Sniff does not automatically upload it. If you then submit the file on VirusTotal’s site, that site receives its contents. Uploaded samples may be shared with VirusTotal’s partners and customers; avoid submitting confidential files or information you are not authorised to share. These actions are optional and are not needed for local identification.
VirusTotal is an external service with its own terms and privacy information. Its handling of information is separate from ours.
Exports, support attachments and links
If you share an export, send us an attachment, or open an external link, information is handled by the destination you choose. Review exports before sharing: filenames, paths and metadata may be personal or confidential. We receive file information only if you independently provide it to us, for example in a support enquiry.
4. Information we and our providers may receive
Website requests. Cloudflare delivers and protects the website. In doing so it may process IP addresses, request times, requested URLs, browser or device information, and other network or security information. We may receive operational information made available through the hosting service. These requests deliver the website; they do not upload files selected in the checker.
Communications. If you contact us, we receive the contact details and message contents you provide, and any attachments or troubleshooting information you choose to include. Please share only information needed to handle your enquiry. You can use the local checker without giving us a name, email address or account.
Contact form and spam protection. When enabled, our contact form collects an optional name, email address, enquiry type and message. We use Cloudflare Email Service to send these details to our team’s inbox. The form does not accept attachments. Cloudflare Turnstile processes browser, device and network signals to prevent automated abuse; it loads only on the contact page. See Cloudflare’s Turnstile privacy information.
App Store services. Apple handles App Store downloads, payments, refunds and related account services. We do not receive your payment card details from those transactions. Apple may make transaction information, sales reports, reviews, or diagnostics available to developers according to its services and your settings. See Apple’s privacy policy.
Local Mac diagnostics. The current Mac app stores a limited set of Apple MetricKit crash and hang diagnostic files locally. That implementation does not transmit those files to us. This is distinct from information Apple may handle through its own diagnostic-sharing services.
5. Cookies, analytics and advertising
The current File Sniff website does not add analytics scripts, advertising pixels, marketing cookies, or cross-site tracking. The current apps do not include third-party advertising or usage-analytics SDKs. We do not sell information obtained through File Sniff or share it for targeted advertising.
Local app preferences are not advertising identifiers. Cloudflare’s infrastructure may process operational and security information as described above; see Cloudflare’s privacy policy. External websites you choose to visit may use their own cookies or tracking technologies.
6. Why we use information and our legal bases
We use information we actually receive to respond to enquiries, provide requested support, maintain and protect the website, investigate faults or abuse, administer purchases or disputes where relevant, and meet legal obligations. We do not use local file analysis as a source of marketing data.
Where EU or UK data protection law applies, Peth Pty Ltd acts as controller for the personal information it processes for these purposes. Depending on the circumstances, the lawful basis is performance of a contract or steps you request before a contract; our legitimate interests in operating a reliable service, responding to enquiries and preventing abuse; compliance with legal obligations; or consent where required. If we rely on consent, you may withdraw it without affecting processing that was lawful before withdrawal.
We do not use File Sniff to make decisions about people with legal or similarly significant effects through automated processing.
7. Disclosure and overseas handling
We may provide information we hold to personnel and service providers who need it for hosting, communications, support or business administration; to professional advisers where necessary; or to authorities when legally required. A business transfer may involve relevant records, subject to applicable law and appropriate protections. This does not give us access to files that remain on your device.
Peth Pty Ltd is based in Australia. Cloudflare and Apple operate internationally, including in the United States, and website requests or information you provide may be processed outside Australia through their global infrastructure. Optional external services may also process information overseas. There is no File Sniff server receiving files for analysis.
Where we arrange a transfer that requires legal safeguards, we will use the safeguards required by applicable law, such as approved contractual protections or another valid transfer mechanism. Contact us for information about providers and safeguards relevant to information we hold about you.
8. Retention and security
We retain support correspondence and associated records for as long as reasonably needed to handle the enquiry, maintain relevant business records, resolve disputes and meet legal requirements. Retention depends on the type and purpose of the record rather than a single fixed period. We delete or de-identify information when it is no longer needed, subject to lawful retention requirements. Hosting and external-service records are also subject to those providers’ practices.
We take reasonable steps to protect personal information we hold. No storage or transmission method is completely secure. The local-analysis design reduces the information sent to us; it does not control what other applications, device backups or external services do with data you give them.
Clearing browser results does not delete a JSON file you downloaded. Deleting an app does not necessarily delete exports, shared files or backups. Manage those copies at their saved destinations.
9. Access, correction and other rights
You may ask what personal information we hold about you and request access or correction. Where applicable law provides them, you may also request deletion, restriction of processing or portability, or object to processing based on legitimate interests. These rights have legal conditions and exceptions.
Contact us using section 11. We may request proportionate information to verify your identity. We will explain any lawful refusal and available complaint options. We cannot retrieve or delete files or results stored only on your device or held independently by another provider.
10. Children
File Sniff is a general-purpose utility and is not directed specifically at children. We do not knowingly seek personal information from children. A parent or guardian who believes a child has provided us with personal information can contact us to request appropriate action. Store and device age restrictions apply separately.
11. Questions, requests and complaints
Write to:
Att: File Sniff Privacy Officer
C/o Peth Pty Ltd
GPO Box 2342
Brisbane QLD Australia 4001
For other ways to get in touch, visit our contact page.
Describe your concern and how we can respond. We aim to respond to privacy complaints within 30 days, or explain if more time is needed, and will meet any applicable statutory time limit.
If your concern remains unresolved, you may be able to complain to the Office of the Australian Information Commissioner or the relevant privacy regulator. Where EU or UK law applies, you may complain to your competent data protection authority, including the UK Information Commissioner’s Office, as applicable.
12. Changes to this policy
We will update this page and its revision date when our practices change. Where a change requires notice or consent, we will provide that notice or obtain consent as required. Publishing a new policy does not itself authorise unrelated use of information already collected.
Our privacy overview offers a shorter explanation. This policy provides the fuller details; both should describe the same practices.