← Drench

Privacy

Drench keeps what it needs to send you build notifications, for only as long as it needs it. Your App Store Connect keys never reach Drench’s server.

No Drench accounts

You don’t make an account with Drench: it works with the App Store Connect keys you add. Its server doesn’t know your name or email address, keeps nothing that identifies your App Store Connect account, and Drench doesn’t use advertising identifiers or track you across apps and websites.

Your App Store Connect keys

The API keys you add are stored in your Keychain. If you use iCloud Keychain, it syncs them to your other devices with end-to-end encryption, so those devices can add the same teams; Apple can’t read them. The keys never reach Drench’s server. Drench uses them to sign requests that go straight from your device to Apple’s App Store Connect API, and the apps, builds, and workflows Drench shows you stay between your device and Apple, apart from the app and build IDs described under Xcode Cloud webhooks.

Notifications, Live Activities, and widgets

When Drench registers for notifications, which it does each time you open it, its server stores:

  • The push tokens Apple issues to the app, its widgets, and its Live Activities, and whether each is a development or production token
  • The App Store Connect IDs of the apps you follow, which build events you chose to see as alerts, whether a follow is paused because it’s beyond the free plan, and when your device last confirmed it can see each app
  • For a build in a Live Activity, the Live Activity’s push token, the build’s ID, and the workflow’s name

Push tokens identify an installation of Drench, not a person. Turning off notifications for an app removes it from the server. A Live Activity’s record is deleted when its build finishes, or within two days if the build never reports a result.

When you follow an app, and about once a day after that, Drench checks that you can still see it, the same way it does for a webhook address (below). It checks sooner when your team key stops working. If App Store Connect says you can’t see the app, the server removes the follow at once. A device that hasn’t confirmed access to an app for 7 days gets no more notifications for it, and after 30 days the follow is deleted.

When Apple reports that a push token is no longer valid, for example after you delete the app, the server deletes that device’s record and the apps it follows. A device that follows no apps is deleted after 30 days without Drench being opened on it.

Xcode Cloud webhooks

Xcode Cloud sends build events to Drench through the webhook you set up. Each app’s webhook address contains a key made for that app alone, so no one else can send Drench events for it.

Before giving you that address, Drench checks that you can see the app. Your device sends Drench’s server a token, signed on your device, that lets it read only that app’s bundle ID, and only for two minutes. The server makes that one request to Apple and keeps nothing from it.

For each build, the server keeps its ID and statuses for about a week, so it never notifies you about the same change twice. To show whether your webhook works, the app asks the server whether it received your latest build, by that build’s ID.

Pull request titles and numbers are included in notifications but not stored. Our hosting provider, Vercel, keeps request logs for a limited time, and these can include the contents of webhook events, such as commit and pull request details.

Drench Pro

Subscriptions are sold and managed by Apple. Drench receives a signed record of your subscription’s status from Apple on your device, and never sees your payment details or Apple Account.

Feedback

The Share feedback button in Drench’s settings opens a new email to us in your mail app. Drench adds your device model, its operating system version, the version of Drench, and your language and region setting at the end of the email. You can change or remove them before you send it.

The email goes from your mail app to us like any other email. Drench and its server don’t see or keep it.

Analytics

None. The app contains no analytics, crash reporting, or advertising SDKs, and this website doesn’t set cookies or run analytics.

Questions

To ask a question, email dan.eden+drench@me.com.

Last updated 30 September 2026.