Your archive stays local. Purchase records do not.

The waitlist. If you join the waitlist, we store the email address you typed, the date, and the landing-page source label. We do not use tracking pixels, advertising identifiers, or behavioral analytics.

No analytics. This site loads no analytics, no advertising scripts, and no external fonts. Everything it needs is served from this domain. Cloudflare processes requests to host the site and its services. Paddle receives information when you choose to open its hosted checkout.

Purchases and license delivery. Paddle is our merchant of record and processes checkout, billing details, tax, receipts, and refunds under its own privacy terms. Our license service stores your normalized purchase email, Paddle customer and transaction identifiers, the plan and seat count, signed license key, refund status, and delivery audit records. Cloudflare hosts that service and sends the transactional license email. We use those records only to fulfill and support the purchase, prevent duplicate issuance, handle refunds, and meet legal recordkeeping obligations.

What we do with your address. A waitlist address is used for release news. A purchaser address is used for the receipt, license, and purchase support. We do not sell or rent either address.

Deleting it. Write to [email protected] and ask. We remove optional waitlist data and reply to confirm. Purchase and tax records may need to be retained for legal, fraud, refund, and warranty obligations; we will explain any record we cannot yet erase. No account or reason is required.

The Mac app. It runs locally, has no network entitlement, and contains no networking API. Photos and files selected through the system picker are written to a destination you choose. They are not sent to us. There is no telemetry, usage reporting, advertising, or crash upload. License validation is offline and the key is kept in macOS Keychain on that Mac.

Archive contents. The current app archives Photos and a user-selected folder, plus a user-selected local Messages snapshot and available attachments. Messages never leave your chosen storage and are excluded from cleanup. Proof logs contain source-relative filenames, sizes, timestamps, status codes, and SHA-256 hashes because those details are needed to verify the archive. Those logs stay in the destination you choose.

Changes. If this policy changes, the date above changes and the previous version stays in the public repository's history.