Privacy Policy
Draft, not yet reviewed by a lawyer. These documents were written to match what MacTidy actually does, and they follow the usual structure for a macOS software product sold in the US and the EU. They are a starting point for your counsel, not legal advice, and they are not a substitute for review. Every [MARKED] item still has to be filled in, and the choices about governing law, the EU representative and retention periods are decisions only you can make.
1. Who we are
MacTidy is published by Neural Ops, LLC, registered at [REGISTERED ADDRESS] (“we”, “us”). For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Neural Ops, LLC is the controller of the personal data described here.
Our EU representative under Article 27 GDPR is [EU REPRESENTATIVE, OR DELETE THIS LINE IF NOT REQUIRED]. Our UK representative is [UK REPRESENTATIVE, OR DELETE].
[APPOINT A DPO? Required only in the Art 37 cases. Delete if not.]
2. The summary
MacTidy is a desktop application that runs on your Mac. It examines files, settings and installed software on that machine so it can show you what is there. That analysis happens locally. We do not receive the results, the file names, the paths or the contents.
The personal data we do hold is small: what is needed to sell you a licence, keep it working, and answer you when you write to us.
3. What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Licence data | Your licence key, the name of the device it is activated on, activation and validation timestamps. | Created when you buy, sent by the app when it checks the licence. |
| Purchase data | Your email address, billing country, the amount, tax status and an order reference. We do not receive your full card number. | Our payment provider, who is the merchant of record for the sale. |
| Support data | Whatever you put in an email to us, including anything you attach. | You, when you contact us. |
| Marketing data | Your email address, and your mobile number only if you gave it to us for that purpose. | You, if you opt in. |
| Server logs | Standard web server logs for mactidy.app, which include IP addresses. | Automatically, when you visit the site. |
We do not collect special category data as defined in Article 9 GDPR, and we do not ask for it. Please do not send it to us in a support email.
4. What the app does and does not send
This is the part most people want, so it is set out in full rather than summarised.
The app sends: your licence key and a device name, to our payment provider's licensing service, so the subscription works.
The app downloads: a public list of known malware fingerprints, from a third party threat intelligence source. That is a download. Nothing about your Mac is sent in order to receive it, and your files are compared against the list on your own machine.
The app does not send: your files, their contents, their names, their paths, your scan results, your settings, your security level, or any identifier for advertising or analytics.
The app contains no analytics SDK, telemetry, crash reporting service or advertising framework.
If you click a link in the app, your browser opens it and behaves as your browser normally does. One of those links can look a flagged file up on a public malware database, and the address of that page contains the file's fingerprint. That fingerprint is a hash, not the file, and the link only opens because you clicked it.
The AI features, where you enable them, talk to a model running on your own machine through LM Studio or Ollama. That traffic does not leave your Mac, and we do not operate a cloud model.
The same list, with hostnames, is on What leaves your Mac.
5. Why we are allowed to process it
For people in the EEA and the UK, GDPR requires a legal basis for each purpose.
| Purpose | Legal basis |
|---|---|
| Selling you a licence and making it work | Performance of a contract, Article 6(1)(b). |
| Validating a licence against the device it is on | Performance of a contract, Article 6(1)(b), and our legitimate interest in preventing licence abuse, Article 6(1)(f). |
| Answering your support email | Performance of a contract, or our legitimate interest in running a supported product, Article 6(1)(f). |
| Keeping tax and accounting records | Legal obligation, Article 6(1)(c). |
| Marketing email or SMS | Your consent, Article 6(1)(a). You can withdraw it at any time. |
| Keeping the website and service secure | Legitimate interest, Article 6(1)(f). |
6. Who we share it with
We do not sell personal data, and we do not share it for cross context behavioural advertising. We use a small number of service providers, listed on the subprocessors page, who process data on our instructions under a data processing agreement.
We may also disclose personal data where we are legally required to, or to establish or defend legal claims. If we are ever compelled to hand something over, we will tell you unless we are legally prohibited from doing so.
7. International transfers
Some of our providers are in the United States. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies. [CONFIRM WHICH MECHANISM EACH PROVIDER USES]
8. How long we keep it
| Data | Kept for |
|---|---|
| Licence and activation records | While the subscription is live, then [PERIOD]. |
| Invoices and tax records | As long as tax law requires, which is commonly six to ten years. [CONFIRM FOR YOUR JURISDICTION] |
| Support email | [PERIOD] after the conversation ends. |
| Marketing consent records | Until you withdraw consent, plus a record of the withdrawal. |
| Web server logs | [PERIOD, COMMONLY 30 TO 90 DAYS]. |
9. Security
We keep the personal data we hold to a minimum, which is the most reliable security measure available. Access is limited to people who need it. Transport is encrypted. No system is perfect, and we do not claim otherwise.
If a breach affects your personal data and creates a risk to you, we will notify the relevant supervisory authority within 72 hours where GDPR requires it, and we will tell you where the law requires that too.
10. Your rights in the EEA and the UK
You have the right to:
- ask what we hold about you, and get a copy (access);
- have inaccurate data corrected (rectification);
- have data deleted (erasure), where one of the grounds in Article 17 applies;
- restrict how we use it while a question about it is resolved;
- receive the data you gave us in a portable format, and have it sent elsewhere;
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent at any time, without affecting what we did before you withdrew it.
We do not carry out automated decision making that produces legal effects concerning you.
To exercise any of these, email [PRIVACY EMAIL]. We will respond within one month. You also have the right to complain to your supervisory authority; in the UK that is the Information Commissioner's Office.
11. Your rights in the United States
Depending on where you live, you may have rights under the California Consumer Privacy Act as amended by the CPRA, or under the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states as they come into force.
Notice at collection. The categories of personal information we collect are identifiers (name, email, IP address), commercial information (your purchase), and internet activity limited to server logs. We collect them for the purposes in section 5. We do not collect sensitive personal information for the purpose of inferring characteristics.
We do not sell personal information, and we do not share it for cross context behavioural advertising. We have not done so in the preceding twelve months. Because we do not, there is no “Do Not Sell or Share My Personal Information” mechanism to offer, and we honour Global Privacy Control signals as a matter of course by not doing the thing they object to.
Where your state law provides them, you have the right to know, to delete, to correct, to opt out, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. To make a request, email [PRIVACY EMAIL]. We will verify your request by asking you to confirm it from the email address on the order. An authorised agent may act for you with written permission.
If we deny your request you may appeal by replying to our decision. [SOME STATES REQUIRE A SPECIFIC APPEAL PROCESS AND TIMEFRAME]
12. Children
MacTidy is not for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
13. Changes
If we change this policy we will update the date at the top. If the change is material, we will tell subscribers by email before it takes effect.
14. Contact
Neural Ops, LLC
Privacy questions: [PRIVACY EMAIL]
Postal: [REGISTERED ADDRESS]
MacTidy