Your privacy matters to us a lot. This policy explains what data we collect, why, and how we protect it. We’ve tried our best to keep it readable so you don’t need lawyers to read it.
The short version: We collect minimal data. The website uses privacy-friendly analytics and collects your email if you subscribe. The desktop app validates your license periodically and checks for updates. You can send crash and error reports if you want. During the open beta, the desktop app also sends usage stats (which features you use), tied to a random id, never to your name, with an easy off switch. Your file contents never reach us, and file names are replaced with placeholders before anything leaves your Mac. We don’t sell your data.
1. Who we are
Rymdskottkärra AB (the “data controller”) is responsible for your personal data. We’re a Swedish company located at Vattmyragränd 47, 177 39 Järfälla, Sweden. Few people know that the company name actually means “Space wheelbarrow”.
For privacy-related questions, contact us at [email protected].
2. What data we collect
On the website (getcmdr.com)
- Email address: if you subscribe to our newsletter or contact us
- Page analytics: we use Umami, a privacy-focused analytics tool that we host on our own server. It tells us which pages are visited, where traffic comes from, and approximate location (country level). Umami doesn’t use cookies and doesn’t collect any personal information.
- Website behavior: we use PostHog to see how visitors interact with the website, like session recordings and heatmaps. This helps us spot confusing layouts and improve the experience. PostHog sets a first-party cookie to maintain your session, but doesn’t track you across other websites.
- Downloads: the version and architecture you chose, your country, and where the download came from. Two more things stay for 90 days, then we delete them: your browser’s user agent, to tell real downloads from bots, and a one-way hash of your IP address, to count distinct downloaders per day. That hash mixes in the date and a secret only we hold, so it can’t become your IP address again or follow you across days. The file itself comes from GitHub Releases, so GitHub sees your IP address like any web server.
- Payment info: if you buy a license, payment is handled by Paddle. We see your email address and purchase details, but never your credit card number. That’d be too much risk for us.
In the desktop app
- License key: stored locally on your machine. The app verifies it cryptographically offline, and periodically checks our server to see if your subscription has expired or been extended. During these checks, we also send a hashed device identifier so we can detect key sharing. We don’t use this to track you or your activity, only to count distinct devices per license.
- Organization name: for commercial licenses, we store the organization name you provide at checkout, to display it in the app’s About window.
- Crash reports (opt-in): the app version, macOS version, where in our code the crash happened, and the crash message, cleaned of personal data on your Mac first. No file names, no file contents. If you’ve added a beta contact email, you can tick a box to attach it so we can reply; we include it only when you do, and delete it after 90 days. Switch crash reports on or off anytime in Settings > Updates & privacy.
- Error reports (opt-in): a zip of recent app logs plus your app and macOS version, sent from
Help > Send error report. The app shows you what’s inside before it goes anywhere. File and folder names
are replaced with placeholders on your Mac first, so a path arrives as something like
$HOME/Documents/<file>.pdf. Kept for 90 days. - Feedback you send: your message, your app and macOS version, and your email address if you add one so we can reply. No install id travels with it, so feedback can’t be connected to your usage stats.
- Usage stats (open beta): which features you use, basic preferences (like light or dark mode), and your app version, macOS version, and Mac architecture. The app sends these at launch and about once an hour while it’s open. They’re tied to a random id created on your Mac, never to your name, email, or license. That id stays the same between launches, which is how we tell 100 people opening the app once from one person opening it 100 times. That makes these stats pseudonymous rather than truly anonymous: we can’t work out who you are, but the records do link to each other. No file names, contents, paths, search terms, or prompts. On by default during the beta, off anytime in Settings > Updates & privacy.
- Beta contact email (optional): if you share it, it’s stored on your Mac and sent only to our mailing list so we can reach out. We never send it with your usage stats, so the two can’t be connected.
We never collect your file contents, search queries, AI prompts, keystrokes, or screenshots. File names reach us only as placeholders, in the cleaned logs of an error report you chose to send. Beyond the usage stats, the desktop app’s network calls are license validation (including the device identifier above), checking for updates, and sending crash or error reports if you’ve opted in.
What we DON’T collect
- The contents of your files, ever. We don’t want to know your files. Your file and folder names don’t reach us either: in an error report they’re replaced with placeholders on your Mac, keeping only the file extension and everyday folder names like Documents or Downloads. We see the shape of what happened, not what you were working on.
- Your prompts, the AI’s answers, tool calls, etc. With a cloud provider, the app talks to it directly using your own API key: the conversation never passes through our servers. What you send is between you and that provider, under their terms. With Cmdr you can also keep everything on your Mac with a local model.
- Crash reports, if you opt in, carry only technical diagnostics: code locations, app and system version, and a crash message cleaned on your Mac first. Never file contents.
- Your keystrokes or screenshots. During the open beta we do see which features are used, never their content.
- And we never train models on your data!
3. Why we collect this data (legal basis)
Under GDPR (EU law to protect your rights over your data), we need a legal basis for processing your data, which is pretty nice and fair and we apply it to all our users globally, not just EU citizens. Here is a list:
- License validation and subscription status checks: As a business baseline, we need to know who has a valid license and who doesn’t.
- Legitimate interest: Website analytics, download records, and the beta usage stats show us how people find and use Cmdr, which directly shapes the roadmap. This is strictly not about tracking any particular user. We actively avoid that. We read these numbers in aggregate; the random id lets us count people without knowing who they are, and we never use it to look someone up. The usage stats come with an easy opt-out in Settings > Updates & privacy.
- Consent: Email addresses to send you news that hopefully interest you, including the optional beta contact email. (You can unsubscribe anytime from all communications we send, except for stuff we need to send like updates to this very policy.)
- Consent: Crash reports, error reports, and feedback, each sent only when you choose to send it. You can opt out of crash reports anytime in Settings.
4. How we use your data
- To process your license purchase
- To maintain and improve Cmdr
- To send you product updates (if you subscribed)
- To respond to your support requests
- To analyze website traffic and improve our communication
5. Who we share data with
We only share data with service providers who help us operate Cmdr:
- Paddle (payments): processes purchases, handles taxes and invoicing. Based in the UK with GDPR-compliant processing. Paddle’s privacy policy
- PostHog (website behavior and desktop usage stats): session recordings and heatmaps to help us improve the website experience, and the PII-free feature stats the desktop app sends during the open beta, tied to the random id described above. Cloud-hosted in the EU. PostHog’s privacy policy
- Cloudflare (hosting): runs our API server on its global CDN for license validation, downloads, and crash, error report, and feedback intake. Download records, crash reports, feedback, and beta usage stats live in Cloudflare D1 (SQLite); error report bundles live in Cloudflare R2. Cloudflare’s privacy policy
- Discord (how we hear about problems): crash reports, error reports, feedback, and beta signups ping a private channel only we can read, so we notice things fast. An email address you attached to feedback or a signup is in that ping. Discord is a US company. Discord’s privacy policy
- GitHub (download hosting): the app and its updates come from GitHub Releases, so GitHub sees your IP address when you download or update Cmdr, like any web server. We don’t send GitHub anything about you. GitHub’s privacy statement
- Listmonk (newsletter and beta list): self-hosted on our server. Stores your email address and subscription status, including the optional beta contact email you can share in the desktop app. No data leaves our infrastructure except when sending emails via AWS SES.
- AWS SES (email delivery): sends newsletter and confirmation emails on our behalf. AWS privacy policy
Our page-level website analytics (Umami) are self-hosted on our own server. No data is shared with any third party for that.
We don’t sell your data. We don’t share it with advertisers or anyone not listed above.
6. Where we store your data
Page-level website analytics (Umami) and our newsletter system (Listmonk) are self-hosted on our own server in Europe. Our license, telemetry, and report server runs on Cloudflare Workers on a global CDN, with its database and file storage in Cloudflare’s network. PostHog and Paddle are GDPR-compliant and have appropriate data processing agreements in place.
Discord and GitHub are US companies, so our Discord notifications and the downloads GitHub serves involve a transfer outside the EU, under those companies’ own data protection terms.
7. How long we keep your data
A daily job on our server enforces these, so they hold whether or not anyone remembers to check.
- Purchase records: kept for seven years (Swedish accounting law requirement)
- Email subscriptions: kept until you unsubscribe, then we have no use for it.
- Website analytics: typically two years, then aggregated further, or deleted. Old data is less helpful.
- Downloads: the hashed IP address and user agent go after 90 days. What’s left (version, architecture, country, and where the download came from) points to no one, and we keep it while it’s useful.
- Update checks: individual records go after seven days, leaving the daily totals per version.
- Desktop usage stats: two years, then deleted.
- Crash reports: your email address, if you attached one, and the id grouping your reports go after 90 days. The technical part (version, signal, and where in our code it happened) has no time limit: it names nobody, and it’s how we chase down long-standing stability issues.
- Error reports: 90 days.
- Feedback: we keep your message so we can act on it. An email address you gave for a reply goes after two years.
8. Cookies
PostHog sets a first-party cookie to maintain your session while you browse our website. This is used for session recordings and heatmaps. It doesn’t track you across other websites. Umami, our page analytics tool, doesn’t use cookies at all.
We don’t use third-party advertising cookies or cross-site tracking.
9. Your rights (GDPR)
EU residents have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data (“right to be forgotten”)
- Portability: receive your data in a machine-readable format
- Object: object to processing based on legitimate interest
- Withdraw consent: for newsletter subscriptions, unsubscribe anytime
To exercise these rights, email us at [email protected]. We’ll respond within 30 days.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.
That said, we try to be nice to everyone, not just EU citizens.
10. Children’s privacy
Cmdr is not directed at children under 16. We don’t knowingly collect data from children. If you believe we have, please contact us and we’ll delete it.
11. Changes to this policy
We may update this policy occasionally. We’ll notify you of significant changes via email (if you’ve purchased a license) or by posting on our website. The “Last updated” date at the top tells you when it was last revised.
12. Contact
Questions about your data? Want to exercise your rights? Email us at [email protected].