Privacy Policy
Privacy Policy
DeskCommit keeps display information on your Mac by default. This policy explains aggregate product-site measurement and the limited network activity required for purchases, licensing, updates, refunds, and support.
Effective: July 28, 2026 · Last updated: August 8, 2026
1. Who is responsible
The controller responsible for personal data under this policy is Yuto Takahashi, the individual business operator who supplies DeskCommit. The controller’s address is available without delay on request. Contact [email protected]. No purchase, order number, reason, or identity document is required if you only request the address.
2. Information processed or stored on your Mac
The Software processes or stores the following information locally to provide its features:
- Display identifiers, names, arrangement, resolution, refresh rate, and main-display status
- Setup names, save dates, and display settings needed for restore and Undo
- Hotkey, language, theme, onboarding status, and other app preferences
- License key, license instance ID, product information, and the last verification date
Saved setups, display identifiers, screen contents, and app usage history are not uploaded to the Supplier’s server. The current version has no product analytics, advertising SDK, third-party crash analytics, or user account system.
3. Required network activity
| Activity | Information sent or received | Purpose |
|---|---|---|
| Product-site measurement | Visits, page views, referring host, device type, web performance, and fixed events for page start, a 10-second visit, scroll milestones, visible demo-video progress, demo interaction, pricing view, purchase-button click, or guide-to-product-page click. Events include allowlisted acquisition and campaign categories and coarse operating-system, device, browser, and viewport categories | Improve site content, acquisition sources, presentation quality, and the purchase path |
| License activation | The license key you enter, the fixed device label “DeskCommit Mac,” the instance ID issued by Lemon Squeezy, and product and activation status | Verify purchase rights, enforce the two-device limit, and disable a refunded or fraudulent license |
| Update check | A normal HTTPS request to the update manifest during periodic checks after launch, and to the update file when you approve an update. It contains no unique user ID or license key | Check the latest version and release information, and deliver an approved update |
| Purchase and refund | Name, email, billing address, payment details, order number, tax information, license information, and fixed values identifying the version and language of the legal documents linked beside the purchase button | Payment, tax, receipts, product delivery, refunds, fraud prevention, and a record of the transaction terms by Lemon Squeezy |
| Aggregate purchase outcomes | From signed Lemon Squeezy purchase and refund events, DeskCommit extracts only test/live status, the fixed display language, purchase or refund date, USD-converted order and refund amounts, and whether the product and variant are allowlisted. It does not retain the name, email, billing address, payment details, order number, license key, or webhook body | Measure completed purchases and refunds by day and prevent duplicate counting without building a customer profile |
| Support | The name, email, order number, message, and optional attachments that you choose to send | Support, troubleshooting, refunds, and privacy requests |
The destination service may process an IP address, timestamp, operating system or client information, and similar standard connection logs. During activation, DeskCommit does not intentionally send your Mac serial number, display identifiers, or screen contents.
4. Purposes and legal bases
- Perform the purchase and license contracts, deliver the product, activate it, provide support, and issue refunds
- Record the version and language of the terms linked beside the purchase button
- Prevent fraud, license sharing, chargebacks, and other misuse, and protect legal rights
- Investigate defects and operate the product and distribution infrastructure securely
- Measure aggregate product-site use, acquisition sources, presentation quality, and purchase-path performance
- Meet tax, accounting, consumer-protection, legal-claim, and other legal obligations
Where local law requires a legal basis, purchase, delivery, activation, support, and refunds rely on performance of a contract; tax, accounting, and consumer-protection records rely on legal obligations; fraud prevention, security, legal-rights protection, and non-tracking aggregate improvement rely on the legitimate interests of the Supplier and users; and consent is used where law requires it. DeskCommit does not sell personal information for advertising or use it for behavioral advertising.
5. Service providers and disclosures
- Lemon Squeezy (Sold through Link, LLC): acts as Merchant of Record and provides payment, tax, order, refund, and license-activation services. Its processing is governed by the Lemon Squeezy Privacy Policy.
- Cloudflare: delivers and secures this site and provides Cloudflare Web Analytics and storage for aggregate site events. Cloudflare Web Analytics uses no cookies, and Cloudflare states that it does not collect or use visitors’ personal data for this service. Its processing is governed by the Cloudflare Privacy Policy.
- Legal recipients: information may be disclosed where necessary in response to a lawful request from a court, regulator, law-enforcement body, or other authority.
Lemon Squeezy and hosting providers may process information outside Japan. The Supplier reviews contractual or other appropriate safeguards as required by applicable law and will provide legally required information about overseas processing on request. Each provider handles information under its own terms and privacy policy.
6. Retention
- Local settings and setups: until you delete them or remove the Software’s related data
- Local license state: until deactivation, invalidation after a refund, or deletion of the related Keychain data
- Support records: normally 12 months after the last response, or longer where needed for a dispute, fraud prevention, or law
- Order, payment, and license records: under Lemon Squeezy’s policies and as required for tax, accounting, and fraud prevention
- Hosting logs: under the hosting provider’s policy and for as long as reasonably needed for security
- Hashed web-event deduplication keys and within-page session state: active for 7 days. They use only a key irreversibly derived from the random page-session ID with SHA-256, allowlisted coarse categories, and event order, and are deleted after expiry on the next event or report generation
- Daily aggregate web events and within-page funnels: up to 13 months; no individual browsing history, cross-page or cross-day tracking, or visitor profile is created
- Purchase-aggregation order state: for up to 400 days, only an order key irreversibly derived with SHA-256 from Lemon Squeezy’s random order identifier, test/live status, display language, dates, and cumulative amounts. It is needed to prevent duplicate counts from webhook retries, partial refunds, and out-of-order delivery
- Daily purchase and refund aggregates: up to 400 days; they contain no name, email address, order number, license key, or individual webhook body
- Cloudflare Web Analytics: the period available in Cloudflare’s dashboard, currently up to 6 months
Personal data controlled by the Supplier is deleted or anonymized when no longer needed for its purpose, unless retention is required by law.
7. Security
License state is stored in macOS Keychain, external connections use HTTPS, and access is limited to what is needed. Support will not ask for a complete license key or unnecessary screen contents. No Internet transmission or electronic storage method can, however, be guaranteed absolutely secure.
8. Your rights
Depending on applicable law, you may have rights to information, access, correction, deletion, suspension, restriction, objection, data portability, or stopping a third-party disclosure concerning personal data controlled by the Supplier. To protect other people’s information, a request may require limited verification, such as the purchase email address or order number. If EEA or UK data-protection law applies, you may also complain to the data-protection authority for your place of residence.
For purchase or payment data that Lemon Squeezy controls independently, use the contact described in its privacy policy. Information that must be retained by law, or that the Supplier does not hold, may not be available for deletion or access; the reason will be explained where applicable.
9. Cookies and web analytics
The DeskCommit product site uses no proprietary login, advertising cookie, marketing cookie, or device fingerprint. Cloudflare Web Analytics measures visits, page views, referring hosts, device types, and web performance. DeskCommit also aggregates fixed events for page start, a 10-second visit, 25% scroll milestones, each 25% of demo-video progress while at least half of the video is visible, demo interaction, pricing view, purchase-button click, and a guide-to-product-page click.
First-party events use a random page-session ID held only in browser memory, within-page event order, the page language, allowlisted acquisition source, UTM medium and campaign categories, button placement, content category, and coarse operating-system, device, browser, and viewport categories. The Worker irreversibly derives a key from the page-session ID with SHA-256, uses it for up to 7 days to determine ordered within-page progress such as demo or pricing to checkout, and then retains only daily aggregate counts. No analytics ID is stored in a cookie or localStorage. DeskCommit does not store a name, email address, raw URL, full query string, referring path, full User-Agent, exact operating-system version, exact screen resolution, or IP address in its analytics database. These metrics are not unique people across pages or days. These analytics scripts are currently withheld when Cloudflare identifies a request as coming from Europe. After you follow the purchase link, Lemon Squeezy’s cookie and privacy policies apply on its site.
After checkout completes, Lemon Squeezy sends signed purchase and refund webhooks to DeskCommit. DeskCommit verifies the signature and allowlisted product, then aggregates daily purchase count, order total, refund count, and refunded amount. The order key used to prevent duplicate counting is created with SHA-256 from Lemon Squeezy’s random order identifier and cannot be reversed to the original identifier. This purchase aggregation does not retain a name, email address, billing address, payment information, order number, license key, or webhook body.
10. Children
The product is not directed to children. If the law where you live requires parental consent to enter into a contract, obtain that consent before purchase.
11. Changes to this policy
This policy may be updated when data practices, functionality, service providers, or law change. A material change will be clearly posted on this page, with advance notice or consent where required.
12. Contact
For questions about this policy or information handled by DeskCommit, contact [email protected]. For requests about purchase or payment data, contact Lemon Squeezy Buyer Support.