Disclosure up front: Purplelink, which publishes this site, makes three of the apps used as examples: Legroom, Keyfeel and Outbound Veil. What this page says about them is my description of my own apps, taken from their product pages, not an audit or a certification by anyone else. What it says about Apple comes from Apple's pages, read on October 8, 2026. I did not test the menu paths on every macOS version, and Apple changes them, so if a name differs on your Mac, follow Apple's current Privacy & Security help.
The short answer
- Granting one of these gives an app a standing ability that stays on until you turn it off.
- A permission describes what an app is able to do. What it actually does is up to its maker, so trust rests on who made the app, where you got it, and what they say it does with the access.
- Grant a permission when the app's job needs it, and say no when it does not. A disk cleaner can work without Full Disk Access. A keyboard sound app that listens to keys in other apps needs Input Monitoring.
- You can review all three in one place, System Settings, Privacy & Security, and switch any of them off at any time.
What Apple said on October 2, 2026
Apple published a developer news item called Updates to Full Disk Access in macOS on October 2, 2026. Paraphrased, it says:
- Full Disk Access largely bypasses the controls that protect private data, and exists so backup apps can work properly.
- Some developers use it in ways that could put users at risk, exposing files, mail, messages and browsing history without the user fully understanding. For communication apps, it can also expose the people the user talks to.
- Apple will add controls so that granting this access takes "very explicit user action". It also names AI agents, saying the risk grows as they become more capable and autonomous.
What the note does not say: when the controls will arrive, which macOS version will carry them, what they will look like, or whether grants you made earlier will be affected. It says only "going forward". Until Apple ships something, I do not know how existing apps will be affected, and neither does anyone outside Apple. The note is about Full Disk Access only. It says nothing about Input Monitoring or Accessibility.
What each permission lets an app do
The first column follows Apple's own descriptions in its Privacy & Security help. The last two are general knowledge about how apps use them, not Apple's wording.
| Permission | What it allows | Apps that legitimately ask | What to weigh |
|---|---|---|---|
| Full Disk Access | Access to all files on the Mac, including data from other apps such as Mail and Messages, Time Machine backups and some administrative settings | Backup tools, some cleaners and file managers, search indexers | The widest reach into your files. Ask whether a narrower grant (a folder you pick) would do. |
| Input Monitoring | Watching input from the mouse or trackpad and seeing what you type, including while you use other apps | Keyboard sound apps, text expanders, keyboard and mouse remapping tools | It sees keystrokes. A well-built app needs only which key was pressed, but the permission itself does not limit that. |
| Accessibility | Running scripts and system commands that control the Mac | Window managers, automation tools, password managers, screen readers, text checkers | In practice, an app with it can read what is on screen in other apps, such as the text field in focus, and press buttons for you. |
They cover different things. Full Disk Access is about files stored on the Mac, Input Monitoring is about input as you make it, and Accessibility is about the interface in front of you. An app might need two of them for different features, and a good one asks for the second only when you turn that feature on.
Review and remove what you have granted
- Open the Apple menu, choose System Settings, and click Privacy & Security in the sidebar. You may need to scroll down to find it.
- Click Full Disk Access, Input Monitoring or Accessibility. Each shows a list of the apps you have allowed.
- Read the list. Anything you do not recognize, or no longer use, should go.
- Switch an app's toggle off to take the permission away. Apple's Input Monitoring help describes this step. For Full Disk Access and Accessibility, Apple's page describes adding an app with the Add button; on the versions I know, the list also lets you select an app and remove it with a minus button under the list.
- Quit and reopen the app if it was running. Some apps do not notice a change until they restart.
Turning a permission off stops future access. It does not undo anything the app did earlier. If you are worried about a specific app, remove its permission, then delete the app.
Five questions to ask before you grant any of them
- What does the app need this for, in its maker's own words? The product page or help should say which feature uses the permission. If it does not, that is a reason to wait.
- Does it work without it? Good apps degrade. A cleaner that skips protected folders, or a tool that loses one optional feature, is asking for the right amount.
- What leaves the Mac? Look for a privacy statement that names the network requests. An app that watches your keys or your screen and also has an account, analytics or uploads deserves more scrutiny than one that works offline.
- Where did it come from? The developer's own site, the Mac App Store, or a project repository you can read, not a search ad or a repackaged download. Apps notarized by Apple open without the unidentified-developer warning; one that is not will make you override a block, and that is a cue to slow down.
- Can I turn it off later without losing my work? Check that removing the permission does not leave the app stuck or your files in a different state.
What Purplelink's apps ask for
From each product page and the site's llms.txt, October 8, 2026. All three are direct downloads with a 7-day trial, no account and no analytics.
| App | Permission | Required, and what it does with it |
|---|---|---|
| Legroom | Full Disk Access | Optional, never required. It asks only if you choose to give it. It lets Legroom read folders macOS protects, such as Desktop, Documents and Downloads. Without it, Legroom skips them and says which ones it could not read. |
| Keyfeel | Input Monitoring | Required. Without it Keyfeel cannot hear your keyboard and stays silent. It reads the key code, which says which key was pressed, never the characters, and works offline. |
| Keyfeel | Accessibility | Optional, for two features: stopping scroll sounds at the end of a page, and sounds for Mission Control, Application windows and Show Desktop. |
| Outbound Veil | Accessibility | Required. Without it the app has nothing to check. It reads the text field you are typing in so it can check it for personal information. The check runs on the Mac, and nothing you type is stored or sent. |
| Outbound Veil | Input Monitoring | Only if you turn on send hold, so the app can notice the send key and hold it until you decide. If you never use send hold, you never grant it. |
- Legroom and the network: the readout, rules and measurements stay on the Mac. Apart from the Buy link, the only network use is the once-a-day update check, which carries the app's name and version and an update token, plus what any web request carries, such as an IP address. Its page says it does not clean inside system folders. The disk space guide has more on what to expect from a cleaner.
- Keyfeel and passwords: the page says that when a password field has focus, macOS stops delivering keystrokes to apps like Keyfeel, so it hears nothing there. Its only network use is the update check. The Mechvibes guide covers what it needs from sound packs.
- Outbound Veil and its limits: it will miss some things, it is not a compliance product, and it lowers the chance of a mistake rather than removing it. Its setup guide walks through granting Accessibility.
You do not have to take my word for these. You can check part of it yourself: the permission lists in System Settings show what each app has been given, and a network monitor shows what it connects to. The privacy page has the site-wide statement.
Limits of this page
- No safety guarantee. A permission is a capability. A trustworthy developer can still ship a bug, and macOS does not report what an app does with the access it has.
- Three apps described. I describe the three I make. For anyone else's, use the five questions above and read their own pages.
- Apple's plans are unknown. Whether the Full Disk Access change affects any app on this page is unknown until Apple ships it. By their pages, Legroom works without Full Disk Access, and Keyfeel and Outbound Veil do not ask for it.
Frequently asked
Is it safe to allow Full Disk Access on a Mac?
It depends on the app. Full Disk Access gives an app access to nearly everything on the Mac, including data from Mail and Messages, so grant it only to an app from a developer you trust whose job needs it, such as a backup tool. Apple said on October 2, 2026 that some developers use it in ways that could put users at risk, and that it will add controls requiring very explicit user action. It gave no date or macOS version.
Does Apple's October 2026 announcement change anything today?
Not that Apple has said. The note says Apple will add controls going forward and gives no date, no macOS version and no details. Review the Full Disk Access list in System Settings, Privacy & Security now, since it is worth doing either way.
Why does a keyboard sound app need Input Monitoring?
To play a sound when you press a key in another app, it has to be told when a key goes down, and macOS puts that behind Input Monitoring. Apple describes the permission as letting an app see what you type. Keyfeel reads the key code, which says which key was pressed, not the characters, and works offline. The permission itself does not enforce that, so check what any such app says it does.
Can an app with Accessibility read my passwords?
Accessibility lets an app read parts of other apps' interfaces, and macOS protects password fields in its own ways. Keyfeel's page says macOS stops delivering keystrokes to apps like it when a password field has focus. I would not assume every app or every kind of field is protected the same way. Grant Accessibility only to apps you would trust with what is on your screen.
How do I see which apps have these permissions?
Open System Settings, click Privacy & Security, then open Full Disk Access, Input Monitoring and Accessibility in turn. Each list shows the apps you have allowed, with a toggle to switch each off.
Do Legroom, Keyfeel and Outbound Veil need Full Disk Access?
No. Legroom asks for it only if you choose to give it, and skips protected folders without it. Keyfeel needs Input Monitoring, and Outbound Veil needs Accessibility. Neither of those two asks for Full Disk Access, according to their product pages.
Related guides
- Legroom, Keyfeel and Outbound Veil: the three Mac apps described above.
- Best disk space analyzer and cleaner for Mac (2026): what to ask of a cleaner before it deletes anything.
- Best keyboard sound apps for Mac (2026): which permission each one asks for.
- Use Mechvibes sound packs on a Mac: importing packs into Keyfeel.
- Purplelink's privacy page, all products and all guides.