Privacy Policy
Last updated: August 3, 2026
R2Explorer ("the App") is a native macOS application developed by mgcrea ("we", "us", "our"). Your privacy is important to us. This Privacy Policy explains how we handle your information when you use R2Explorer.
Information We Collect
R2Explorer is a local-first application. We do not collect, store, or transmit any personal data to our servers, and we operate no backend that could receive it. The App runs on your Mac and communicates directly with the Cloudflare R2 API (or other S3-compatible services) using credentials you provide. The only other thing that leaves your Mac is iCloud sync, which goes to your own iCloud account rather than to us — see iCloud Sync below.
API Tokens & Credentials
Your Cloudflare API tokens and S3-compatible credentials are stored securely in the macOS Keychain, the operating system's encrypted credential store. Your credentials are:
- Never sent to us
- Never stored in plain text
- Only used to authenticate directly with the Cloudflare R2 API or S3-compatible endpoints
- Protected by macOS Keychain encryption and access controls
- Never shared with any third party other than Apple's iCloud Keychain — and only then if you leave the "Sync credentials via iCloud Keychain" setting enabled
iCloud Keychain is Apple's end-to-end encrypted credential store: tokens synced through it are readable only by your own devices, not by Apple and not by us. Turning the setting off in Settings → General keeps every credential on the Mac that created it.
iCloud Sync
R2Explorer can keep your connections available on every Mac signed into the same Apple ID. This is handled by two independent settings in Settings → General, both enabled by default. Everything synced goes to your own iCloud account — never to us.
- Sync connections via iCloud — mirrors your connection list through iCloud key-value storage. The synced record for each connection contains only its name, connection type, Cloudflare account ID, S3 endpoint URL, and region. No API tokens, no bucket contents, and no object data are ever included. Only Cloudflare R2 and S3-compatible connections sync; local wrangler dev connections never leave the device that added them, because their project path and security-scoped bookmark cannot resolve in another Mac's sandbox.
- Sync credentials via iCloud Keychain — stores your Cloudflare API tokens and S3-compatible credentials in Apple's end-to-end encrypted iCloud Keychain, so a synced connection can open on your other devices. They remain readable only by your own devices.
Turning either setting off keeps that data on the device it was created on. Because both rely on Apple's iCloud infrastructure, Apple's handling of it is governed by Apple's Privacy Policy.
Object Storage Data
Files, objects, and bucket metadata you browse, upload, or download through R2Explorer travel directly between your Mac and the Cloudflare R2 API (or your configured S3-compatible service). We never intercept, store, or have access to your storage data.
Analytics & Tracking
R2Explorer does not include any analytics, telemetry, or tracking frameworks. We do not collect usage data, crash reports, or behavioral information.
Apple Crash Reporting
If you have opted into sharing crash data with app developers through macOS Settings, Apple may provide us with anonymized crash reports. This is controlled entirely by your macOS preferences and is not something we can enable or configure.
Third-Party Services
The App communicates with the following third-party services:
- Cloudflare R2 API — to manage your buckets and objects, using credentials you provide
- S3-compatible endpoints — if you configure connections to other S3-compatible storage providers
- Apple App Store — for license validation and in-app purchases, managed by Apple
- Apple iCloud — if you leave iCloud sync enabled, to carry your connection metadata and, separately, your credentials between your own devices. See iCloud Sync above for exactly what is included
We recommend reviewing Cloudflare's Privacy Policy for information about how Cloudflare handles data transmitted through their APIs.
App Sandbox
R2Explorer runs within the macOS App Sandbox, which restricts the App's access to your system. The App can only access files and resources you explicitly grant it permission to use.
Children's Privacy
R2Explorer is not directed at children under the age of 13. We do not knowingly collect any information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date.
Contact Us
If you have questions about this Privacy Policy, please contact us at support@mgcrea.io.