Privacy Policy
Last updated: [PLACEHOLDER — effective date]
Draft — not legal advice. Every factual statement below was verified against the Plumby source, the entitlement worker's D1 schema, and this website's code on 2026-07-27, and re-verified for the update-check and feedback rows on 2026-08-17; the citations are in the notes at the bottom. What is not verified is whether the wording satisfies GDPR, CCPA/CPRA, or Delaware law — that needs a data-privacy attorney. Replace every
[PLACEHOLDER], resolve every[⚠️ LEGAL REVIEW], then remove this line and setdraft: false(that also flips the page fromnoindexto indexable).Two changes on 2026-08-17, both verified against the source. The in-app feedback box was missing from a list that calls itself complete, and is now section 2's fourth row. The update-check row and the new "Counting update checks" describe the intended end state of two engineering changes that were in flight when this was written: the app moving the licence key out of the update URL and into an HTTP header, and the worker starting to count update checks in aggregate. Confirm both are actually deployed before setting
draft: false— this page would otherwise describe software that does not exist yet. A per-marker triage of everything still open lives inresearch/privacy-policy-triage.md.
Plumby is a native macOS utility made by Ordinary Nerds, L.L.C. ("we", "us"), 2810 N Church St STE 89093, Wilmington, DE 19802, United States.
This policy covers three things, and they are deliberately separated below because they collect different data: the app on your Mac, this website, and buying a licence.
The short version
- Plumby analyses your Mac locally. What it measures — file sizes, paths, processes, network connections, battery and memory figures — is computed on your machine and is never uploaded to us. It is not sent anywhere when you run a scan, a cleanup, or a repair.
- Plumby never reads the contents of your files. It reads file metadata: name, path, size, and dates.
- There is no account. Nothing you do in the app is tied to a profile, because no profile exists.
- Plumby does not report what you do with it. No feature usage, no crash reports, no behavioural data. Nothing about what you scanned, what you deleted, which apps you run, or how often you open the app ever reaches us. The one thing we count is update checks, and we count them in aggregate — the tally has no IP address, no licence key, and no row for your machine. "Counting update checks" below says exactly what is in it.
- Some things do leave your Mac, and pretending otherwise would be the opposite of the point. They are listed exactly in "What the app sends" below: a licence check, an update check, the feedback box when you choose to use it, and three lookups that only run when you open the feature that needs them.
- We do not sell your personal information and we do not share it for cross-context behavioural advertising.
1. What the app measures, and where it stays
To map disk, memory, processes, and network activity, Plumby may ask for Full Disk Access. That permission never leaves your device.
With it, Plumby reads file metadata — sizes, paths, and dates — to show you where space went. It does not read, upload, or transmit the contents of your documents, photos, or projects.
Everything Plumby shows you is produced on your Mac and stays there. Closing the app does not upload a summary; there is no cloud sync and nothing to sync to.
2. What the app sends, and when
This is the complete list. Each entry says what triggers it and what is in it.
| When | Where it goes | What it contains |
|---|---|---|
| You activate or re-check a licence | licenses.plumby.app, which forwards to Keygen |
Your licence key, a device fingerprint, and your Mac's name |
| Automatic update check, once a day | updates.plumby.app (via Sparkle) |
Which version of Plumby you are running, which major version of macOS, whether the Mac is Apple Silicon or Intel, and which update channel. If you have activated a licence, the key goes too — in an HTTP header, never in the web address. Sparkle's optional system-profile reporting is switched off |
| You send a message from the feedback box | licenses.plumby.app, which relays it to us as email |
What you typed, the reply address you chose to give (you can leave it blank), and your Plumby version, build, macOS version and processor type. If you switch on the optional diagnostics attachment, it adds your Mac model, memory and disk sizes, which permissions you have granted, and whether you are licensed or on the trial — the state, never the key |
| You open Clean ▸ App Updates | api.github.com and itunes.apple.com |
The names/identifiers of installed apps being version-checked |
| You use the public IP tool | api.ipify.org |
Nothing but the request itself — the service replies with your public IP, which means it necessarily sees it |
Three of these deserve plain speech rather than a table cell:
The device fingerprint is a SHA-256 hash of your Mac's hardware UUID, salted to Plumby. We cannot reverse it into a serial number, but it is stable for your machine, so it is a pseudonymous device identifier and we treat it as personal data. It exists for one purpose: enforcing the 2-Mac limit on a licence.
Your Mac's name is sent with the licence check so you can tell your machines apart when you deactivate one. macOS often derives that name from your account name, so it frequently contains your real name. [⚠️ LEGAL REVIEW — this is the most personal field the app transmits. If the 2-Mac list can be made usable without it, sending it becomes unnecessary and this row should disappear.]
Your licence key travels in a header, not in the web address. Earlier builds put it in the update URL as ?key=…. Web servers write full URLs into their logs as a matter of routine, so a key in a URL is a key copied into a log file — and a Plumby licence key is the only credential this product has. It now travels in an X-Plumby-License header, which is not logged that way. If you have never activated a licence, no key is sent and the update check is anonymous.
The GitHub, Apple, and ipify lookups go to companies we do not control, under their own privacy policies. They run only when you open the feature that needs them.
Counting update checks
Plumby asks updates.plumby.app once a day whether there is a newer version. We keep a count of those checks. A count is all we keep.
Each check adds one to a tally of:
- which version of Plumby asked;
- which major version of macOS it is running on — "macOS 15", not "15.4.1";
- whether the Mac is Apple Silicon or Intel;
- which update channel it is on;
- the two-letter country the request came from, which Cloudflare works out from the connection. We store the country. We do not store the address it came from;
- whether the request carried a licence key or was anonymous — which of the two, never whose.
Here is what is deliberately absent, because the absences are the point: no IP address, no licence key, no device fingerprint, no Mac name, and no row for your machine. There is no per-device record, so there is nothing that links one day's check to the next, nothing to look up when someone asks what a particular Mac has been doing, and nothing to hand over if they insist. What exists is a set of running totals.
It exists for one reason. Before we turn off support for an old macOS version, or stop shipping fixes to an old build, we need to know how many people are still on it. Without a count, that decision is a guess made at your expense. Nothing else is done with these numbers: they do not feed advertising, they are not sold, and they are not joined to your licence record — the tally does not contain a key to join on.
How long these counts are kept is answered in section 9, with everything else we keep.
3. This website
This site uses OpenPanel, a cookieless, privacy-friendly analytics tool, to record page views and which buttons are clicked. There are no cookies, no cross-site tracking, and no advertising identifiers.
Analytics only start after OpenPanel loads in your browser; with JavaScript disabled, nothing is recorded. [⚠️ LEGAL REVIEW — whether cookieless analytics need consent under ePrivacy/GDPR in your target markets, and whether an opt-out control is required on the page.] [PLACEHOLDER — confirm OpenPanel's IP handling and anonymisation setting for this project.]
The site is served by Cloudflare, which processes request data (including IP addresses) to deliver and protect it.
4. Buying a licence
Checkout is handled by Stripe on our /buy page. We never see or store your card number — it is entered in Stripe's own hosted fields, and card data never touches our servers.
What we do store, in a Cloudflare D1 database, is the licence record:
- your email address;
- your licence key and its Keygen identifier;
- Stripe identifiers for the checkout session, the subscription (annual plans), and the payment;
- whether the plan is annual or lifetime, and the date updates run until;
- whether the key-delivery email was sent, and when the record was created and changed.
Your email is used to deliver the licence key and to support you about that purchase. It is sent through Resend, our transactional email provider.
[⚠️ LEGAL REVIEW — if you ever want to email customers about anything other than their own purchase, that is a separate, consented purpose and must be added here first.]
5. Support
If you email us, we keep the message and your address so we can answer and refer back to it.
A message sent from the app's feedback box arrives with us the same way — as an email in the same mailbox — so it is kept the same way. The one difference is at the door: to stop a script using the box as a pipe into our inbox, the relay counts how many messages an address has sent today. It stores a salted SHA-256 hash of your IP address, never the address, and the salt is a secret held by the service, so the table cannot be turned back into a list of who wrote in. Those rows are deleted after 7 days.
6. Legal basis (GDPR)
[⚠️ LEGAL REVIEW — counsel should confirm each basis below.]
| Processing | Basis |
|---|---|
| Licence key, fingerprint, Mac name, email | Contract — we cannot deliver or enforce a licence without them |
| Update checks | Legitimate interests — shipping security and bug fixes |
| The aggregate count of update checks | Legitimate interests — knowing which versions and which macOS releases are still in use before support for one is withdrawn. Counsel should note that this tally contains no identifier, so whether it is personal data at all is a prior question to the basis |
| Website analytics | Legitimate interests, or consent where local law requires it |
| Support correspondence, including the feedback box | Legitimate interests |
| Tax and accounting records | Legal obligation |
7. Who else processes your data
| Processor | Role | Where |
|---|---|---|
| Stripe | Payments | United States / global |
| Keygen | Licence issuing and validation | [PLACEHOLDER — hosting region] |
| Resend | Transactional email (licence delivery) | [PLACEHOLDER — hosting region; see section 8] |
| Cloudflare | Website hosting, CDN, Workers, D1 database | Global edge; licence database runs in the Asia-Pacific region |
| OpenPanel | Website analytics | [PLACEHOLDER — hosting region] |
We do not sell personal data, do not share it for cross-context behavioural advertising, and do not build advertising profiles.
[⚠️ LEGAL REVIEW — a signed Data Processing Agreement is needed with each of the five, and the transfer mechanism for EU personal data (Standard Contractual Clauses or an adequacy decision) must be named here.]
8. International transfers
We are a United States company, so personal data from the EU, EEA, UK, or Switzerland reaches United States processors — Stripe for payments, and Keygen for licence issuing.
One deliberate exception, stated because "largely United States based" was doing too much work in the sentence this replaced:
- Licence records sit in Cloudflare D1, and this database runs in the Asia-Pacific region. That is a transfer to neither the US nor the EU, and it needs naming rather than hiding under "global edge". There is one copy: read replication is switched off, so the data is not additionally distributed to other regions. No jurisdictional restriction (such as Cloudflare's EU-only option) is set on it.
[⚠️ LEGAL REVIEW — name the safeguard actually in place for each destination: SCCs, the EU-US Data Privacy Framework, or another mechanism. The destinations above are separate questions, not one. This section cannot ship as a placeholder.]
[PLACEHOLDER — where licence-delivery email is processed. An earlier draft stated the
Resend sending domain was configured in eu-west-1, which would put it inside the EU. That
is not recorded anywhere in the worker's configuration and could not be confirmed, so the
claim has been removed rather than published unverified — a privacy policy that overstates
where data stays is worse than one that admits it does not yet know. Read the region off the
Resend dashboard for the sending domain and restore the statement, or state the US.]
9. How long we keep it
Stated honestly, because the code is the source of truth here: the licence database currently has no automatic deletion. A licence record persists until it is deleted by hand.
That is a defensible position for a lifetime licence — the record is the proof of what you bought — but it is a decision, not an accident, and it needs writing down as one:
- Licence records — [PLACEHOLDER — retention period. For lifetime licences, "for the life of the licence" is a legitimate answer; say it explicitly.]
- Payment records — retained as long as tax and accounting law requires. [PLACEHOLDER — period, per Delaware and federal rules.]
- Support email, including feedback-box messages — [PLACEHOLDER — period.]
- Feedback rate-limit rows — 7 days, then deleted. That one is not a placeholder: it is what the code does.
- The aggregate count of update checks — [PLACEHOLDER — period, or the criteria. See "Counting update checks".]
- Website analytics — [PLACEHOLDER — OpenPanel's configured retention.]
[⚠️ LEGAL REVIEW — GDPR requires a stated period or the criteria used to determine it. "Indefinitely" without a reason will not satisfy it.]
10. Your rights
Depending on where you live, you may have the right to access the data we hold about you, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable format, and to complain to your data protection authority.
Californians additionally have the right to know what is collected, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising any of these.
To make a request, email [PLACEHOLDER — privacy@plumby.app]. We aim to respond within 30 days.
One practical note: a deletion request that removes your licence record also removes our record of your purchase, which is what lets us re-send a lost key or recognise you at renewal. We will tell you before that happens.
[⚠️ LEGAL REVIEW — identity verification for requests, and the interaction between a deletion request and the payment records we must retain for tax purposes.]
11. Security
Licence data is held in Cloudflare D1 and reached only over HTTPS. Card data never reaches our systems. Your licence key and the fingerprint's source value are stored in your Mac's Keychain, not in a plain file.
No system is perfectly secure, and we do not claim otherwise.
[PLACEHOLDER — breach notification commitment and timeline; GDPR Art. 33 requires 72 hours to the supervisory authority.]
12. Children
Plumby is not directed at children and we do not knowingly collect data from anyone under [PLACEHOLDER — 13 in the US / 16 in much of the EU].
13. Changes
We may update this policy. The "last updated" date at the top always reflects the current version.
[PLACEHOLDER — how material changes are announced. With no mailing list, the honest answer is likely "on this page, with the date changed", and the policy should say exactly that rather than imply an email that will never arrive.]
14. Contact
Privacy questions, or a request under section 10: [PLACEHOLDER — privacy@plumby.app]
Ordinary Nerds, L.L.C. 2810 N Church St STE 89093 Wilmington, DE 19802 United States
[⚠️ LEGAL REVIEW — whether an EU/UK representative under GDPR Art. 27 is required, given EU customers and no EU establishment.]