← Back to Plumby

Privacy Policy

Last updated: [PLACEHOLDER — effective date]

Draft — not legal advice. Every factual statement below was verified against the Plumby source, the entitlement worker's D1 schema, and this website's code on 2026-07-27; the citations are in the notes at the bottom. What is not verified is whether the wording satisfies GDPR, CCPA/CPRA, or Delaware law — that needs a data-privacy attorney. Replace every [PLACEHOLDER], resolve every [⚠️ LEGAL REVIEW], then remove this line and set draft: false (that also flips the page from noindex to indexable).

Plumby is a native macOS utility made by Ordinary Nerds, L.L.C. ("we", "us"), 2810 N Church St STE 89093, Wilmington, DE 19802, United States.

This policy covers three things, and they are deliberately separated below because they collect different data: the app on your Mac, this website, and buying a licence.

The short version

  • Plumby analyses your Mac locally. What it measures — file sizes, paths, processes, network connections, battery and memory figures — is computed on your machine and is never uploaded to us. It is not sent anywhere when you run a scan, a cleanup, or a repair.
  • Plumby never reads the contents of your files. It reads file metadata: name, path, size, and dates.
  • There is no account. Nothing you do in the app is tied to a profile, because no profile exists.
  • Plumby has no analytics and no telemetry. The app does not report feature usage, crashes, or any behavioural data to us.
  • Some things do leave your Mac, and pretending otherwise would be the opposite of the point. They are listed exactly in "What the app sends" below: a licence check, an update check, and three lookups that only run when you open the feature that needs them.
  • We do not sell your personal information and we do not share it for cross-context behavioural advertising.

1. What the app measures, and where it stays

To map disk, memory, processes, and network activity, Plumby may ask for Full Disk Access. That permission never leaves your device.

With it, Plumby reads file metadata — sizes, paths, and dates — to show you where space went. It does not read, upload, or transmit the contents of your documents, photos, or projects.

Everything Plumby shows you is produced on your Mac and stays there. Closing the app does not upload a summary; there is no cloud sync and nothing to sync to.

2. What the app sends, and when

This is the complete list. Each entry says what triggers it and what is in it.

When Where it goes What it contains
You activate or re-check a licence licenses.plumby.app, which forwards to Keygen Your licence key, a device fingerprint, and your Mac's name
Automatic update check updates.plumby.app (via Sparkle) The version you are running. Sparkle's optional system-profile reporting is switched off
You open Clean ▸ App Updates api.github.com and itunes.apple.com The names/identifiers of installed apps being version-checked
You use the public IP tool api.ipify.org Nothing but the request itself — the service replies with your public IP, which means it necessarily sees it

Two of these deserve plain speech rather than a table cell:

The device fingerprint is a SHA-256 hash of your Mac's hardware UUID, salted to Plumby. We cannot reverse it into a serial number, but it is stable for your machine, so it is a pseudonymous device identifier and we treat it as personal data. It exists for one purpose: enforcing the 3-Mac limit on a licence.

Your Mac's name is sent with the licence check so you can tell your machines apart when you deactivate one. macOS often derives that name from your account name, so it frequently contains your real name. [⚠️ LEGAL REVIEW — this is the most personal field the app transmits. If the 3-Mac list can be made usable without it, sending it becomes unnecessary and this row should disappear.]

The GitHub, Apple, and ipify lookups go to companies we do not control, under their own privacy policies. They run only when you open the feature that needs them.

3. This website

This site uses OpenPanel, a cookieless, privacy-friendly analytics tool, to record page views and which buttons are clicked. There are no cookies, no cross-site tracking, and no advertising identifiers.

Analytics only start after OpenPanel loads in your browser; with JavaScript disabled, nothing is recorded. [⚠️ LEGAL REVIEW — whether cookieless analytics need consent under ePrivacy/GDPR in your target markets, and whether an opt-out control is required on the page.] [PLACEHOLDER — confirm OpenPanel's IP handling and anonymisation setting for this project.]

The site is served by Cloudflare, which processes request data (including IP addresses) to deliver and protect it.

4. Buying a licence

Checkout is handled by Stripe on our /buy page. We never see or store your card number — it is entered in Stripe's own hosted fields, and card data never touches our servers.

What we do store, in a Cloudflare D1 database, is the licence record:

  • your email address;
  • your licence key and its Keygen identifier;
  • Stripe identifiers for the checkout session, the subscription (annual plans), and the payment;
  • whether the plan is annual or lifetime, and the date updates run until;
  • whether the key-delivery email was sent, and when the record was created and changed.

Your email is used to deliver the licence key and to support you about that purchase. It is sent through Resend, our transactional email provider.

[⚠️ LEGAL REVIEW — if you ever want to email customers about anything other than their own purchase, that is a separate, consented purpose and must be added here first.]

5. Support

If you email us, we keep the message and your address so we can answer and refer back to it.

6. Legal basis (GDPR)

[⚠️ LEGAL REVIEW — counsel should confirm each basis below.]

Processing Basis
Licence key, fingerprint, Mac name, email Contract — we cannot deliver or enforce a licence without them
Update checks Legitimate interests — shipping security and bug fixes
Website analytics Legitimate interests, or consent where local law requires it
Support correspondence Legitimate interests
Tax and accounting records Legal obligation

7. Who else processes your data

Processor Role Where
Stripe Payments United States / global
Keygen Licence issuing and validation [PLACEHOLDER — hosting region]
Resend Transactional email (licence delivery) Ireland (EU)
Cloudflare Website hosting, CDN, Workers, D1 database Global edge; licence database primary in Singapore
OpenPanel Website analytics [PLACEHOLDER — hosting region]

We do not sell personal data, do not share it for cross-context behavioural advertising, and do not build advertising profiles.

[⚠️ LEGAL REVIEW — a signed Data Processing Agreement is needed with each of the five, and the transfer mechanism for EU personal data (Standard Contractual Clauses or an adequacy decision) must be named here.]

8. International transfers

We are a United States company, so personal data from the EU, EEA, UK, or Switzerland reaches United States processors — Stripe for payments, and Keygen for licence issuing.

Two deliberate exceptions, stated because "largely United States based" was doing too much work in the sentence this replaced:

  • Licence-delivery email is processed in Ireland. The Resend sending domain is configured in eu-west-1, so the email address you buy with is handled inside the EU rather than transferred out of it.
  • Licence records sit in Cloudflare D1, whose primary for this database is in Singapore. That is a transfer to neither the US nor the EU, and it needs naming rather than hiding under "global edge".

[⚠️ LEGAL REVIEW — name the safeguard actually in place for each destination: SCCs, the EU-US Data Privacy Framework, or another mechanism. Note that the three destinations above are three different questions, not one. This section cannot ship as a placeholder.]

9. How long we keep it

Stated honestly, because the code is the source of truth here: the licence database currently has no automatic deletion. A licence record persists until it is deleted by hand.

That is a defensible position for a lifetime licence — the record is the proof of what you bought — but it is a decision, not an accident, and it needs writing down as one:

  • Licence records[PLACEHOLDER — retention period. For lifetime licences, "for the life of the licence" is a legitimate answer; say it explicitly.]
  • Payment records — retained as long as tax and accounting law requires. [PLACEHOLDER — period, per Delaware and federal rules.]
  • Support email[PLACEHOLDER — period.]
  • Website analytics[PLACEHOLDER — OpenPanel's configured retention.]

[⚠️ LEGAL REVIEW — GDPR requires a stated period or the criteria used to determine it. "Indefinitely" without a reason will not satisfy it.]

10. Your rights

Depending on where you live, you may have the right to access the data we hold about you, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable format, and to complain to your data protection authority.

Californians additionally have the right to know what is collected, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising any of these.

To make a request, email [PLACEHOLDER — privacy@plumby.app]. We aim to respond within 30 days.

One practical note: a deletion request that removes your licence record also removes our record of your purchase, which is what lets us re-send a lost key or recognise you at renewal. We will tell you before that happens.

[⚠️ LEGAL REVIEW — identity verification for requests, and the interaction between a deletion request and the payment records we must retain for tax purposes.]

11. Security

Licence data is held in Cloudflare D1 and reached only over HTTPS. Card data never reaches our systems. Your licence key and the fingerprint's source value are stored in your Mac's Keychain, not in a plain file.

No system is perfectly secure, and we do not claim otherwise.

[PLACEHOLDER — breach notification commitment and timeline; GDPR Art. 33 requires 72 hours to the supervisory authority.]

12. Children

Plumby is not directed at children and we do not knowingly collect data from anyone under [PLACEHOLDER — 13 in the US / 16 in much of the EU].

13. Changes

We may update this policy. The "last updated" date at the top always reflects the current version.

[PLACEHOLDER — how material changes are announced. With no mailing list, the honest answer is likely "on this page, with the date changed", and the policy should say exactly that rather than imply an email that will never arrive.]

14. Contact

Privacy questions, or a request under section 10: [PLACEHOLDER — privacy@plumby.app]

Ordinary Nerds, L.L.C. 2810 N Church St STE 89093 Wilmington, DE 19802 United States

[⚠️ LEGAL REVIEW — whether an EU/UK representative under GDPR Art. 27 is required, given EU customers and no EU establishment.]