Privacy Policy
Last updated: August 2026
In short. Clean Rabbit scans your disk on your own device. File names, paths and file contents are never uploaded, not to us and not to anyone else. The only personal data we hold is your account email address, basic sign-in metadata and your marketing preferences.
You never have to accept marketing in order to use the app, and you can export or delete everything we hold from your account page. The full policy follows.
1.Who We Are
White Rabbit Foundry Limited (“WRF”, “we”, “us”, “our”) operates Clean Rabbit, a desktop application for macOS, Windows and Linux that helps you recover disk space, together with this website at https://cleaner.whiterabbitfoundry.com.
We are registered in England and Wales under company number 15222598.
We act as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains what we collect, why we collect it, and what you can do about it.
For any question about this policy, or to exercise any of the rights described in it, write to hello@whiterabbitfoundry.com. We have not appointed a Data Protection Officer, as we are not required to. Data protection questions go to the same address and are handled by us directly.
2.Data We Collect
Clean Rabbit is a local tool with a small account attached, so the complete list is short:
- Account data: your email address, the internal user identifier assigned to your account, and the date the account was created. Your email address is the only identifier we ask for. There is no name, postal address, telephone number or payment detail, because the app is free.
- Sign-in metadata: the time of your most recent sign-in, and a short-lived record of a pending sign-in request while it is in progress. Pending requests expire after 15 minutes and are then deleted.
- Marketing preferences: whether you have opted out of emails about Clean Rabbit and similar WRF products, whether you have opted in to broader marketing, and the date those settings last changed.
- Consent records: a dated log of each change to those preferences, so that we can evidence what you chose and when.
- App usage events: the desktop app reports a small number of aggregate events, such as which tool was opened and whether a scan finished. There is no persistent device identifier, and no file names, paths, sizes or contents are included. This is on by default and you can switch it off in the app’s Settings, which stops all telemetry.
- Correspondence: if you email us for support, we hold your message and our reply for as long as we need it to deal with your query.
Our authentication provider records technical data incidental to delivering a sign-in, such as the IP address a request came from, for security and abuse prevention. We do not use it for profiling or analytics.
3.How We Use Your Data
Each purpose below is followed by the lawful basis we rely on for it:
- Providing the Service (contract): creating and maintaining your account, sending the one-time links that sign you in, and connecting your desktop app to your account.
- Service communications (legitimate interest): security notices, important defect or data-loss warnings, and notice of changes to this policy or our terms.
- Product emails about Clean Rabbit and similar WRF tools (legitimate interest): occasional updates sent to existing users who have not opted out. See section 5.
- Broader marketing (consent): messages about our other products and occasional partner content, sent only if you have switched that option on.
- Support (legitimate interest): answering your questions and investigating problems you report.
- Improving the app (legitimate interest): a small number of aggregate usage events from the desktop app, so that we can see which tools people actually use and whether scans complete. You can switch this off in the app’s Settings.
- Website analytics (consent): counting page views and downloads, but only if you accept analytics cookies. See section 12.
- Security and abuse prevention (legitimate interest): rate limiting, and detecting misuse of the sign-in system.
- Legal compliance (legal obligation): responding to rights requests and keeping the records the law requires us to keep.
We do not sell your personal data to third parties, and we do not use your content for advertising. We do not build profiles of our users. We do not use your data to train AI models. We make no automated decisions that produce legal or similarly significant effects.
4.Lawful Bases
In full, the bases named in section 3 are those set out in Article 6 of the UK GDPR:
- Contract (Article 6(1)(b)): creating and maintaining your account, and signing you in. Registration is required to use the app, so this is the basis for it.
- Legitimate interests (Article 6(1)(f)): service communications, emails about Clean Rabbit and similar products of ours, support, keeping the sign-in system secure, and the aggregate usage events the desktop app reports. Our interest is in supporting and improving a product you already use. We have weighed that against your interests, the app’s telemetry carries no persistent identifier and nothing about your files, and you can object at any time or simply switch it off in Settings.
- Consent (Article 6(1)(a)): broader marketing, and the website analytics cookies described in section 12. Both are optional, separate from each other, and off by default. You may withdraw either at any time, and withdrawing is as easy as giving.
- Legal obligation (Article 6(1)(c)): retaining limited records for accounting and legal purposes, and complying with rights requests.
5.Marketing and Your Choices
You never have to accept marketing in order to use Clean Rabbit. Making a service conditional on marketing consent would make that consent invalid under Article 7(4) of the UK GDPR, and we do not do it. Every feature of the app works identically whether you are opted in or opted out of everything optional.
Registration
Registration is required to use the app. We rely on contract for it, not on consent, and it is the only thing we ask of you.
Emails about Clean Rabbit and similar WRF products
When you register we may send you occasional emails about Clean Rabbit and comparable WRF tools. This is a soft opt-in under regulation 22(3) of the Privacy and Electronic Communications Regulations 2003: you are an existing user of a similar product of ours, you are offered a clear opt-out at the point of registration, and every such email carries a one-click unsubscribe link. The lawful basis is legitimate interests.
The opt-out box is presented to you when you first sign in, already ticked, with the option to untick it there and then. You can also switch it off at any time from your account page, or from the unsubscribe link in any of those emails. Opting out costs you nothing else.
Broader marketing and product news
Anything wider than that, meaning our other products and occasional partner content, requires your separate and specific consent. The box is unticked by default, it is a distinct control from the one above, and you can withdraw consent at any time from your account page or an unsubscribe link.
Service emails
Some emails are not marketing and cannot be switched off while you hold an account: the sign-in links you have asked for, security notices, and material changes to our terms or this policy. If you do not want to receive these, close your account.
The unsubscribe link in our emails works without signing in, as it must.
6.Data We Do Not Collect
This is the most important section of this policy, because it covers what people reasonably worry about when they run a disk cleaner. Scanning happens entirely on your own device.
- File names and folder paths: we do not upload, read or store them. Results are held in memory on your machine and shown to you.
- File contents: we never read your files off your machine. The duplicate finder hashes files locally in order to compare them, and those hashes are used on your device and then discarded.
- Scan results and clean history: we do not know what you scanned, what you found, what you deleted, or how much space you recovered.
- Your installed applications and startup items: read locally to populate those screens, and never sent anywhere.
- Anything identifying in the app’s telemetry: the desktop app reports a few aggregate events, such as which tool was opened and whether a scan completed. It attaches no persistent device identifier, and it never includes file names, paths, sizes or contents. Switching it off in Settings stops it entirely.
- Payment information: Clean Rabbit is free and we have no payment system.
- Special category data: we neither ask for it nor want it.
7.Third-Party Processors
We keep this list as short as we can. Each company below acts as our processor under a written contract and may only process data on our instructions.
- Google Firebase and Google Cloud (Google Cloud EMEA Limited): authentication, the database holding your account record, our server functions, hosting for this website, and delivery of the sign-in emails you receive. Our project runs in the europe-west2 (London) region.
- Google Cloud Storage (Google Cloud EMEA Limited): hosting of the installer files you download, in the same europe-west2 (London) region. Downloading does not require an account and is not linked to one. Standard web server logs apply.
We do not currently use a separate email marketing provider. If that changes we will name the provider here before any message is sent through it.
We do not pass your data to advertisers, to data brokers, or to anyone else for their own purposes.
8.International Transfers
Your account data is stored in the United Kingdom, in the europe-west2 (London) region, and our server functions run in that same region.
Some of our processors are established in the United States and may access data from there for support and operational purposes. Where that happens, the transfer is covered by the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, or by UK adequacy regulations where those apply, together with the supplementary measures we consider appropriate.
You can ask us for details of the safeguards in place for a particular transfer by writing to hello@whiterabbitfoundry.com.
9.Data Retention
- Account data: kept for as long as your account is open.
- After you close your account: retained for 12 months for accounting, legal and dispute-resolution purposes, then permanently deleted.
- Consent records: kept for as long as we need them to evidence the consent you gave or withdrew.
- Unsubscribe records: kept for as long as necessary to make sure we do not email you again after you have asked us not to.
- Pending sign-in requests: deleted 15 minutes after they are created, or immediately once they have been used.
- Support correspondence: kept while your query is open and for a reasonable period afterwards, then deleted.
Nothing about your files is retained anywhere, because none of it ever reaches us.
10.Your Rights Under UK GDPR
You have the right to:
- Be informed about how we use your data, which is what this document is for.
- Access a copy of your data. You can do this yourself at any time from your account page, which produces a JSON file of everything we hold, including your consent history.
- Rectification of inaccurate data. Email us to change the address on your account.
- Erasure of your data. Delete your account from your account page, or ask us to do it for you.
- Restrict processing in certain circumstances.
- Data portability. The export is machine-readable JSON for exactly this reason.
- Object to processing carried out on the basis of our legitimate interests, including direct marketing. If you object to direct marketing we will stop, with no exceptions and no need for you to give a reason.
- Withdraw consent at any time where we rely on it.
Most of these you can exercise yourself, in seconds, from your account page. For anything else, write to hello@whiterabbitfoundry.com. We will respond within one month, and will tell you if we need longer because a request is complex. Exercising your rights is free.
11.Security
The strongest security measure here is structural: we do not collect the sensitive data in the first place. What we do not hold cannot be breached.
For what we do hold:
- All traffic between the app, this website and our servers is encrypted in transit using TLS.
- There are no passwords to steal. Sign-in uses one-time links that expire and can only be used once.
- Database access is governed by security rules, so an account can read and write only its own record.
- Unsubscribe tokens are random, are never included in a data export, and are compared in constant time.
- Access to production systems is limited to those who need it and is protected by multi-factor authentication.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and tell you without undue delay where the law requires it.
12.Cookies and Analytics
This website uses no advertising cookies and no tracking pixels. We do use Google Analytics 4, but only if you agree to it.
What the analytics are for
We look at aggregate page views, the sites people arrive from, and how many downloads each platform gets. That tells us which pages are doing their job and which are not. It is not used for advertising, none of Google’s advertising features are switched on, and we do not build profiles of individual visitors.
It runs only with your consent
Analytics cookies are not strictly necessary, so under regulation 6 of the Privacy and Electronic Communications Regulations 2003 they need your consent before they are set. Until you choose Accept, no analytics cookie is written and your browser does not even request Google’s script. Declining is a single click, sits alongside Accept as an equal choice, and the site works identically either way.
You can change your mind whenever you like. Choose Cookie settings at the foot of any page to switch analytics on or off. Turning it off stops any further collection and deletes the analytics cookies already in your browser. If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as a refusal, so analytics stays off and we do not ask you at all.
The cookies themselves
- _ga (expires after 2 years): distinguishes one browser from another so that repeat visits are not counted as new people.
- _ga_<container-id> (expires after 2 years): used by Google Analytics 4 to keep track of the current session.
Google Analytics 4 anonymises IP addresses by default. It does not log or store full IP addresses, and we have no access to them.
Who processes it
Google Ireland Limited acts as our processor for analytics. Google may access data from outside the United Kingdom for support and operational purposes, in which case the transfer is covered by the safeguards described in section 8.
Storage that is not about analytics
When you sign in, our authentication provider stores a token in your browser’s local storage so that you stay signed in. The sign-in pages also store your email address and your marketing choices briefly, in the same place, so that the two halves of the sign-in flow join up. All of this is strictly necessary to provide a service you have asked for, and is exempt from the consent requirement in the Privacy and Electronic Communications Regulations. Signing out or clearing your browser storage removes it.
The desktop application itself does not use cookies at all.
13.Children
Clean Rabbit is not directed at children, and accounts are intended for people aged 16 or over. We do not knowingly collect personal data from anyone under 16.
If you believe a child has registered an account, tell us at hello@whiterabbitfoundry.com and we will delete it.
14.Changes to This Policy
We may update this policy as the product changes or as the law does. The date at the top of this page always shows when it was last revised.
Where a change materially affects your rights or how we use your data, we will tell you by email before it takes effect. Continuing to use Clean Rabbit after that point means the updated policy applies.
15.Complaints
If you are unhappy with how we have handled your personal data, please tell us first at hello@whiterabbitfoundry.com. Most concerns are quicker to resolve directly, and we would rather hear about them.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Complaining to us first is not a precondition of complaining to them.