Privacy
Drench keeps what it needs to send you build notifications, for only as long as it needs it. Your App Store Connect keys never reach Drench’s server.
No Drench accounts
Your App Store Connect keys
Notifications, Live Activities, and widgets
When Drench registers for notifications, which it does each time you open it, its server stores:
- The push tokens Apple issues to the app, its widgets, and its Live Activities, and whether each is a development or production token
- The App Store Connect IDs of the apps you follow, which build events you chose to see as alerts, whether a follow is paused because it’s beyond the free plan, and when your device last confirmed it can see each app
- For a build in a Live Activity, the Live Activity’s push token, the build’s ID, and the workflow’s name
Push tokens identify an installation of Drench, not a person. Turning off notifications for an app removes it from the server. A Live Activity’s record is deleted when its build finishes, or within two days if the build never reports a result.
When you follow an app, and about once a day after that, Drench checks that you can still see it, the same way it does for a webhook address (below). It checks sooner when your team key stops working. If App Store Connect says you can’t see the app, the server removes the follow at once. A device that hasn’t confirmed access to an app for 7 days gets no more notifications for it, and after 30 days the follow is deleted.
When Apple reports that a push token is no longer valid, for example after you delete the app, the server deletes that device’s record and the apps it follows. A device that follows no apps is deleted after 30 days without Drench being opened on it.
Xcode Cloud webhooks
Xcode Cloud sends build events to Drench through the webhook you set up. Each app’s webhook address contains a key made for that app alone, so no one else can send Drench events for it.
Before giving you that address, Drench checks that you can see the app. Your device sends Drench’s server a token, signed on your device, that lets it read only that app’s bundle ID, and only for two minutes. The server makes that one request to Apple and keeps nothing from it.
For each build, the server keeps its ID and statuses for about a week, so it never notifies you about the same change twice. To show whether your webhook works, the app asks the server whether it received your latest build, by that build’s ID.
Pull request titles and numbers are included in notifications but not stored. Our hosting provider, Vercel, keeps request logs for a limited time, and these can include the contents of webhook events, such as commit and pull request details.
Drench Pro
Feedback
The Share feedback button in Drench’s settings opens a new email to us in your mail app. Drench adds your device model, its operating system version, the version of Drench, and your language and region setting at the end of the email. You can change or remove them before you send it.
The email goes from your mail app to us like any other email. Drench and its server don’t see or keep it.
Analytics
Questions
Last updated 30 September 2026.