Your machines never leave your Mac.
What 1VMTool sends and what it never sends. Machines, disks, snapshots, names, paths, keys and addresses stay on your Mac. Anonymous product counts are on by default and off in one click.
What stays local, always
1VMTool is a desktop application, not a service. There is no account, no sync and no server holding anything of yours. Every one of the following exists only on your disk and is never transmitted:
- Virtual machine disks, memory state, snapshots and archives.
- Machine names, file paths and the contents of any shared folder.
- SSH keys, guest host keys and anything typed into a guest.
- IP addresses, hostnames and the ports a guest is listening on.
- Container names, images, logs and Compose files in the managed Docker engine.
- Licence keys, beyond the activation call described below.
Anonymous product counts
The app reports anonymous usage counts through Aptabase so we can see which features are used and which are not. It is on by default and turned off in Settings in one click. The integration is deliberately narrow: the SDK tracks nothing on its own, every event is an explicit call in our code, and machine names, paths, keys, addresses and free text never leave the process. Turning it off sends one final event recording that you did, then stops.
Network calls the app makes
- Update checks. Sparkle polls the public releases repository for a newer signed build. Declining an update stops nothing else working.
- Licence activation. Activating, deactivating or refreshing a Pro key contacts Lemon Squeezy, our merchant of record. If the check cannot reach the network, Pro stays on.
- Things you ask for. Guest images, macOS IPSWs, the Debian base image for the managed Docker engine, prepared-environment packages and anything a container pulls. The app says how big each one is before fetching it, and fetches none of them on its own.
- Anonymous counts, as described above, unless disabled.
The MCP endpoint
The local MCP endpoint is off until you enable it, listens on this Mac only, and requires a bearer token you create and scope yourself — by level (read, operate, create, destroy) and by which machines it may touch. Every tool call is written to an audit log you can read with 1vm mcp audit. A coding agent gets exactly the access you granted it and no more.
This website
1vmtool.com uses Google Analytics to count visits. It sets cookies and records the usual page-level information; it is not connected to anything the desktop app does, and the app does not report to it. Downloads are served from GitHub, whose own privacy terms apply to that request.
Children
1VMTool is a developer tool and is not directed at children under 13. We do not knowingly collect information from them.
Changes, and how to ask
If this page changes materially, the date above moves and the change is described in the changelog. Questions, corrections and requests go to the 1VMTool feedback board, which is public, or by email to hello@stoicsoft.com.
1VMTool is published by StoicSoft. Not affiliated with Apple Inc., Microsoft, or Docker, Inc.