Buy · $99

Last updated 2 October 2026

How a $99 Mac app updates itself: notarisation, Sparkle and a signed feed

Updates are the part of indie Mac software most likely to be done badly. Ours took a few tries to get right, and this is what the final version looks like.

Build and notarise

Each release is built as a universal binary, signed with an Apple Developer ID and sent to Apple for notarisation. Apple scans it and staples a ticket to the disk image. Gatekeeper on your Mac checks that ticket before the app opens.

Sign the feed

The app checks an appcast file on adhdterminal.com once a day. Each entry carries an EdDSA signature made with a private key that never leaves our build machine. The matching public key is compiled into the app. A download whose signature does not verify is thrown away.

Install in place

Sparkle replaces the app in Applications and relaunches it. This is why we warn when the app is run from the disk image: a mounted image is read-only, and there is nothing to replace.

What is sent

The update check sends the app name and version. No identifier, no system profile, no usage data. We can count checks on our server, and that is the only number we see.

All posts