SmartCrab, LLC
S4 Viewer Privacy Policy
S4 Viewer is a native macOS client for Amazon S3 and S3-compatible object stores. This Privacy Policy explains what information S4 Viewer handles, why it handles it, and which services may receive that information.
At a glance. S4 Viewer does not require a SmartCrab account and does not include advertising, behavioral tracking, or a SmartCrab-hosted analytics service.
1. Information S4 Viewer handles
Connection profile information
When you create a connection profile, S4 Viewer stores the information needed to identify and use that profile: a name, endpoint URL, region, bucket name, addressing preference, and creation and update timestamps. This information is stored in the app's SwiftData store. The profile store is configured to use Apple's CloudKit integration, so profile information may be synchronized through iCloud according to your Apple account and iCloud settings.
S3 credentials
Your access key ID and secret access key are stored separately from the profile in the macOS Keychain using a data-protection Keychain item. The Keychain item is marked as synchronizable; when iCloud Keychain is enabled, Apple may synchronize it across your approved devices. S4 Viewer does not place these credentials in the SwiftData profile store or transmit them to SmartCrab as a separate service; it uses them to sign requests sent to the S3 endpoint you configure.
Files and object data
If you choose to upload a file, S4 Viewer reads that file and sends it to the S3 endpoint configured by you. If you download or preview an object, S4 Viewer writes the result to the destination or temporary directory selected by the app and macOS. Object keys, object metadata, and object contents are handled as necessary to perform the operation you request. S4 Viewer does not send those files or objects to a SmartCrab service separate from the S3 endpoint you configure.
Diagnostics
S4 Viewer does not intentionally collect usage analytics, advertising identifiers, contact lists, precise location, or device identifiers for its own service. Startup failures may be written to the macOS unified logging system so that macOS can provide local diagnostic information. S4 Viewer does not operate a service that receives those logs.
2. How information is used
S4 Viewer uses information only to provide the features you request, including:
- saving and restoring connection profiles and credentials;
- listing, previewing, uploading, downloading, renaming, and deleting S3 objects;
- creating folders and transferring multipart uploads; and
- validating connection details and displaying errors or progress.
SmartCrab does not use information handled by S4 Viewer for advertising, profiling, or the sale of personal information.
3. Services that may receive information
Apple iCloud and CloudKit
Apple may receive and synchronize connection profile information through CloudKit, and may synchronize Keychain credentials through iCloud Keychain when you have enabled that Apple service. Apple's handling of that information is governed by Apple's own policies, including its Privacy Policy.
Your S3 or S3-compatible provider
S4 Viewer sends signed requests to the endpoint you configure. Depending on the operation, the provider may receive an access key identifier, signed authorization data, bucket and object names, request metadata, and uploaded or downloaded content. The provider may retain request logs and other information under its own terms and privacy policy. You are responsible for selecting a provider and credentials with permissions appropriate for your use.
macOS system services
S4 Viewer uses macOS services such as the Keychain, file panels, temporary storage, and Quick Look. Those services may process information under Apple's platform policies and your macOS settings. S4 Viewer does not add third-party analytics or advertising SDKs.
4. Security
S4 Viewer uses the macOS Keychain for credentials, signs S3 requests with AWS Signature Version 4 using CryptoKit, and runs with App Sandbox protections. These measures reduce risk but cannot guarantee the security of your device, Apple account, credentials, network, or S3 provider.
S4 Viewer accepts both HTTPS and HTTP endpoints because some S3-compatible services require HTTP. HTTPS is strongly recommended. Requests sent over HTTP are not protected by transport encryption and may expose credentials or object data to network operators.
5. Retention and deletion
- A connection profile remains in the app until you edit or delete it. Deleting a profile also removes its associated Keychain credential from the device.
- Synchronized copies in iCloud or iCloud Keychain are governed by Apple's services and your Apple account settings. Manage those copies through Apple's settings and account controls.
- Objects uploaded to an S3 provider remain there until you or an authorized provider administrator deletes them, or the provider's retention rules remove them.
- Downloaded files and previews remain wherever macOS or you saved them. Temporary preview files are removed by S4 Viewer when they are no longer needed, subject to normal operating-system behavior.
6. Your choices
You can choose whether to create a profile, which endpoint and credentials to use, whether to enable iCloud Keychain, which local files to grant to S4 Viewer, and when to delete profiles, local files, or S3 objects. You can also revoke credentials and change retention or access settings through your S3 provider.
7. Children's privacy
S4 Viewer is a general-purpose utility and is not directed to children. SmartCrab does not knowingly collect personal information from children through S4 Viewer.
8. Changes to this policy
We may update this Privacy Policy when S4 Viewer or its data practices change. The updated version will be published at this URL with a revised effective date.
9. Contact
For privacy questions or requests, contact SmartCrab, LLC through the SmartCrab contact page. Please do not include secret keys, passwords, or other credentials in a message.
This policy covers S4 Viewer. Information submitted through the SmartCrab website is handled separately by that website and its contact service.