How Floodtide works

How updates are found

Floodtide scans /Applications and ~/Applications, plus any folder you add, reads each app's version from its own Info.plist, and asks all six sources it supports, in this order:

A manual source you set for an app, from its row's menu or in Settings under Updates, is checked ahead of all six. It is not a seventh source: it names which Sparkle feed or GitHub repository to read for that app, and the reading goes through the same Sparkle and GitHub sources listed above.

App Store apps update in place, inside Floodtide: pressing Update leaves the row on the new version like any other, no App Store window opens and no password is asked for. Floodtide carries its own copy of the tool that talks to the store, signed and notarised with the app, and runs it as you rather than as an administrator. That route needs Floodtide's installer set up once, from Settings, and the row says so when it is not. Three kinds of store app are handed back to the App Store, and the row says which: one whose download runs past about 675 MB, such as Xcode or the Microsoft Office apps, because an update running for hours here would tell you less about itself than the store does; an iPhone or iPad app running on Apple silicon, which only the store can update; and an app you are signed out for or bought under a different Apple Account.

Two updaters are named rather than installed, because the apps belong to them: apps Setapp manages, and apps in Microsoft AutoUpdate's own register. Floodtide shows the pending version beside them with a button that opens the updater responsible. An app no source can resolve is listed as uncovered instead of guessed at.

Every source is asked at once and each answer is recorded, so a broken feed is still reported even when another source answers in its place. Any app's row can show exactly what each source said.

If Homebrew is installed, Floodtide adds a Homebrew pane listing every cask, formula and tap it manages, most of which are not apps at all, and upgrades them by runningbrew upgrade rather than working around it. That pane is separate from the Homebrew Cask source above: the source is about apps whose updates come from a cask, the pane is about everything Homebrew has on the Mac.

What happens during an install

Download, checksum or signature verification, then an atomic swap. The version it replaced is kept, and Undo Last Update restores it in one click. Settings, Backups decides how long that copy is kept, three days, a week, two weeks or a month, a week by default, and which folder it is kept in, on another disk if you like. Turning backups off stops new copies being made; a failed install still rolls back either way, from a separate copy taken while the app is being swapped. After every install Floodtide compares code signatures. A new build signed worse than the old one, or by a different developer, is rolled back and you decide.

Every step of an install has a time limit sized to the app, so nothing can sit on Installing for ever, and a step that overruns ends the update saying which step it was, with your app untouched or put back. Stop All reaches an install right up to the moment the new copy is swapped in; that swap alone cannot be interrupted safely and says so. No check is shortened to make any of this work.

The password prompt

Apps in folders macOS protects need administrator rights to replace, exactly like dragging a new copy in yourself. Floodtide batches every such app in a run behind one standard macOS authorization prompt, announced before it appears. Floodtide never sees, transmits, or stores the password; macOS performs the swap.

Privacy

The complete list of network traffic Floodtide produces:

There is no third-party crash reporter in the Mac app. Optional passwordless website accounts show licences and seats; buying and activating with a key never requires one. Website and anonymous app activity is retained for up to 13 months. Account sessions expire after 30 days. Deleting an account removes its sign-in record and sessions; licence and purchase records remain where needed to deliver the product, handle refunds and meet accounting obligations.

Deletion and refunds

From the account page you can release a Mac, sign out every session, or delete the optional account. For a copy of your data or deletion help, email raf@bhopstudio.com from the purchase email.

The 14-day trial is there so you can test coverage before paying. If Floodtide is not right for you, email raf@bhopstudio.com within 14 days of purchase for a refund. This does not limit your statutory consumer rights.

Licensing

One license covers 3 Macs. Deactivate a Mac from within the app or release the opaque activation from the optional account page. After the 14-day trial, scanning stays free forever; installing needs a license.

For app developers

Floodtide's Mac app update manifest draft proposes one strict JSON document for publishing a Sparkle feed, GitHub repository, or current release. The draft includes a schema, example, and local validator.

Support

Email raf@bhopstudio.com, or join the Floodtide Discord. Either way you are talking to the person who wrote the code.