How Floodtide works
How updates are found
Floodtide scans /Applications and ~/Applications, plus any folder you add, reads each app's version from its own Info.plist, and asks all six sources it supports, in this order:
- Sparkle: the app's own update feed, read directly from its bundle. It wins outright.
- Floodtide Catalog: a small signed feed that names which source to read for apps nothing else can match.
- Electron feed: the app's own Electron update feed, with its SHA-512 verified before install.
- Homebrew Cask: matched against the community index of Mac software, read over HTTPS so Homebrew need not be installed. An app Homebrew did install stays Homebrew's to update.
- GitHub Releases: one unambiguous Mac asset from a trusted repository, never a guess between several.
- Mac App Store: what the store is offering on this Mac, read from the store's own records rather than Apple's public listing, so an app your Mac is not being offered is never counted as an update you are missing.
A manual source you set for an app, from its row's menu or in Settings under Updates, is checked ahead of all six. It is not a seventh source: it names which Sparkle feed or GitHub repository to read for that app, and the reading goes through the same Sparkle and GitHub sources listed above.
App Store apps update in place, inside Floodtide: pressing Update leaves the row on the new version like any other, no App Store window opens and no password is asked for. Floodtide carries its own copy of the tool that talks to the store, signed and notarised with the app, and runs it as you rather than as an administrator. That route needs Floodtide's installer set up once, from Settings, and the row says so when it is not. Three kinds of store app are handed back to the App Store, and the row says which: one whose download runs past about 675 MB, such as Xcode or the Microsoft Office apps, because an update running for hours here would tell you less about itself than the store does; an iPhone or iPad app running on Apple silicon, which only the store can update; and an app you are signed out for or bought under a different Apple Account.
Two updaters are named rather than installed, because the apps belong to them: apps Setapp manages, and apps in Microsoft AutoUpdate's own register. Floodtide shows the pending version beside them with a button that opens the updater responsible. An app no source can resolve is listed as uncovered instead of guessed at.
Every source is asked at once and each answer is recorded, so a broken feed is still reported even when another source answers in its place. Any app's row can show exactly what each source said.
If Homebrew is installed, Floodtide adds a Homebrew pane listing every cask, formula and tap it manages, most of which are not apps at all, and upgrades them by runningbrew upgrade rather than working around it. That pane is separate from the Homebrew Cask source above: the source is about apps whose updates come from a cask, the pane is about everything Homebrew has on the Mac.
What happens during an install
Download, checksum or signature verification, then an atomic swap. The version it replaced is kept, and Undo Last Update restores it in one click. Settings, Backups decides how long that copy is kept, three days, a week, two weeks or a month, a week by default, and which folder it is kept in, on another disk if you like. Turning backups off stops new copies being made; a failed install still rolls back either way, from a separate copy taken while the app is being swapped. After every install Floodtide compares code signatures. A new build signed worse than the old one, or by a different developer, is rolled back and you decide.
Every step of an install has a time limit sized to the app, so nothing can sit on Installing for ever, and a step that overruns ends the update saying which step it was, with your app untouched or put back. Stop All reaches an install right up to the moment the new copy is swapped in; that swap alone cannot be interrupted safely and says so. No check is shortened to make any of this work.
The password prompt
Apps in folders macOS protects need administrator rights to replace, exactly like dragging a new copy in yourself. Floodtide batches every such app in a run behind one standard macOS authorization prompt, announced before it appears. Floodtide never sees, transmits, or stores the password; macOS performs the swap.
Privacy
The complete list of network traffic Floodtide produces:
- Update checks against each app's own feed, the Homebrew catalog, GitHub's API, Electron update feeds, Microsoft's update manifests and Floodtide's own signed catalog. Those servers see your IP address the way any website does; nothing about your app inventory is attached.
- For apps that came from the Mac App Store, Floodtide asks Apple's public lookup service for the current version. That request carries the app's bundle identifier and your storefront country, nothing else, and Apple already knows which of its apps you have. What the store is actually offering this Mac is read locally, from the store's own records on the disk, and leaves no request of its own.
- License activation: your key and an anonymous device identifier, nothing else.
- Coverage sharing, only if you opt in: app name, bundle ID, version, covered or not. The exact payload is shown in Settings before the switch turns on. No device identifiers ride along.
- Anonymous usage, only if you opt in: at most once a day, a random ID this copy invented for itself, whether it is on trial, licensed or lapsed, how many trial days remain, and the app version. Never your email, your key, an identifier for this Mac, or anything about your apps. Settings shows the exact line and turns it off. The request also carries your IP address; the server turns it into a rough country and stores only that, never the IP itself. Existing installs receive the same one-time choice before anything is sent.
- Website measurement: a daily rotating keyed hash deduplicates visits, coverage searches, downloads and checkout starts. The hash cannot be reversed into an IP address and changes every day. Stored fields are the event, page, source/campaign when present, broad country and whether automation was filtered. No raw IP or full browser string is stored.
- Website analytics run on our own endpoint. No third-party analytics or advertising scripts are loaded. Campaign labels can travel through internal links and purchase forms; no persistent visitor identifier or tracking cookie is added.
There is no third-party crash reporter in the Mac app. Optional passwordless website accounts show licences and seats; buying and activating with a key never requires one. Website and anonymous app activity is retained for up to 13 months. Account sessions expire after 30 days. Deleting an account removes its sign-in record and sessions; licence and purchase records remain where needed to deliver the product, handle refunds and meet accounting obligations.
Deletion and refunds
From the account page you can release a Mac, sign out every session, or delete the optional account. For a copy of your data or deletion help, email raf@bhopstudio.com from the purchase email.
The 14-day trial is there so you can test coverage before paying. If Floodtide is not right for you, email raf@bhopstudio.com within 14 days of purchase for a refund. This does not limit your statutory consumer rights.
Licensing
One license covers 3 Macs. Deactivate a Mac from within the app or release the opaque activation from the optional account page. After the 14-day trial, scanning stays free forever; installing needs a license.
For app developers
Floodtide's Mac app update manifest draft proposes one strict JSON document for publishing a Sparkle feed, GitHub repository, or current release. The draft includes a schema, example, and local validator.
Support
Email raf@bhopstudio.com, or join the Floodtide Discord. Either way you are talking to the person who wrote the code.