PDigger

Security contact

Updated 13 September 2026

Report an issue

PDigger is made by eprojac Ltd. Report security issues in the website, Mac app, or local.pdigger.com proxy to admin@eprojac.com. Privacy and data-subject requests use the same address. Please mark vulnerability reports in the subject line.

Please include enough detail to reproduce the issue and avoid accessing other users’ data. We read every report.

We follow coordinated disclosure. Give us a reasonable time to fix an issue before you publish it; we are a one-person company and do not promise a response time, but we read every report. Do not access, modify, or keep other people’s data, and stop as soon as you have shown the issue exists. We do not run a bug bounty programme and do not pay for reports. We will not take legal action against good-faith research that follows these rules.

Permissions and what is recorded

PDigger asks macOS for three permissions. Screen Recording and Accessibility are needed to capture; Input Monitoring is optional.

While macOS secure input is active (password fields and similar), keyboard events and accessibility reads are skipped. Local history in ~/Library/Application Support/PDigger is integrity-hashed but is not encrypted by PDigger; it relies on FileVault. Keep FileVault on.

How PDigger is built to fail closed

We do not claim SOC 2 or a UK/EU-only region. Infrastructure runs in AWS us-east-1.

Retention

Full details are in the Privacy Policy.