Your privacy matters to us a lot. This policy explains what data we collect, why, and how we protect it. We’ve tried our best to keep it readable so you don’t need lawyers to read it.
The short version: We collect minimal data. The website uses privacy-friendly analytics and collects your email if you subscribe. The desktop app validates your license periodically and checks for updates. It sends crash reports (on by default, with an easy off switch), and you can send error reports if you want. During the open beta, the desktop app also sends usage stats (which features you use), tied to a random id, never to your name, with an easy off switch. Your file contents never reach us. Usage stats and crash reports carry no file names, and in an error report you send, file and folder names are replaced with placeholders, with one narrow gap we explain below. We don’t sell your data.
1. Who we are
Rymdskottkärra AB (the “data controller”) is responsible for your personal data. We’re a Swedish company located at Vattmyragränd 47, 177 39 Järfälla, Sweden. Few people know that the company name actually means “Space wheelbarrow”.
For privacy-related questions, contact us at [email protected].
2. What data we collect
On the website (getcmdr.com)
- Email address: if you subscribe to our newsletter or contact us
- Page analytics: we use Umami, a privacy-focused analytics tool that we host on our own server. It tells us which pages are visited, where traffic comes from, and approximate location (country level). Umami doesn’t use cookies and doesn’t collect any personal information.
- Website behavior: we use PostHog to see how visitors interact with the website, like session recordings and heatmaps. This helps us spot confusing layouts and improve the experience. PostHog keeps its session in your browser’s memory only, so it sets no cookie, and it doesn’t track you across other websites.
- Downloads: the version and architecture you chose, your country, and where the download came from. Two more things stay for 90 days, then we delete them: your browser’s user agent, to tell real downloads from bots, and a one-way hash of your IP address, to count distinct downloaders per day. That hash mixes in the date and a secret only we hold, so it can’t become your IP address again or follow you across days. The file itself comes from GitHub Releases, so GitHub sees your IP address like any web server.
- Payment info: if you buy a license, payment is handled by Paddle. We see your email address and purchase details, but never your credit card number. That’d be too much risk for us.
- Licenses we give away: sometimes we hand a license out instead of selling it, for an evaluation, a partner company, or a thank-you for a bug report. We keep the email address we sent it to, the organization name if there is one, and a short internal note on who it’s for and why, so we can answer questions about it later. It’s never linked to how you use the app, and we keep it for as long as the license exists.
In the desktop app
- License key: stored locally on your machine. The app verifies it cryptographically offline, and periodically checks our server to see if your license has been revoked, or your subscription has expired or been extended. During these checks, we also send a hashed device identifier so we can detect key sharing. We don’t use this to track you or your activity, only to count distinct devices per license.
- Organization name: for commercial licenses, we store the organization name you provide at checkout, to display it in the app’s About window.
- Crash reports (on by default): the app version, macOS version, where in our code the crash happened, and the crash message, cleaned of personal data on your Mac first. For a crash with no message, we also include the memory addresses the code stopped at and the address Cmdr itself was loaded at, which is what lets us turn those numbers back into a place in our code. They’re randomized by macOS on every launch and say nothing about you or your Mac. We read the crash report macOS writes for the same crash and take two things from it: the one-line reason the crash happened, and the list of function names the code was in. We pick those out by name and leave the rest of that file on your Mac, including the id that identifies your machine and the name of whatever app launched Cmdr. No file names, no file contents. If you’ve added a beta contact email, you can tick a box to attach it so we can reply; we include it only when you do, and delete it after 90 days. Crash reports are on by default, and you can turn them off in Settings > Updates & privacy.
- Error reports (opt-in): a zip of recent app logs plus your app and macOS version, sent from
Help > Send error report. The app shows you what’s inside before it goes anywhere. File and folder names
are replaced with placeholders on your Mac first, so a path arrives as something like
$HOME/Documents/<file>.pdf. This covers every path, and a name repeated in the same log line as its path. One gap remains: a name that appears in a log line on its own, with no path next to it, can slip through. That’s why you see the preview first. If you’ve added a beta contact email, you can tick a box to attach it so we can reply; we include it only when you do. You can also add a note or your email address to a report you already sent, and that goes to the same place. Everything here is kept for 90 days. - Feedback you send: your message, your app and macOS version, and your email address if you add one so we can reply. No install id travels with it, so feedback can’t be connected to your usage stats.
- Usage stats (open beta): which features you use, basic preferences (like light or dark mode), and your app version, macOS version, and Mac architecture. The app sends these about once every three hours while it’s open. They’re tied to a random id created on your Mac, never to your name, email, or license. That id stays the same between launches, which is how we tell 100 people opening the app once from one person opening it 100 times. That makes these stats pseudonymous rather than truly anonymous: we can’t work out who you are, but the records do link to each other. No file names, contents, paths, search terms, or prompts. On by default during the beta, off anytime in Settings > Updates & privacy.
- Beta contact email (optional): if you share it, it’s stored on your Mac and sent only to our mailing list so we can reach out. We never send it with your usage stats, so the two can’t be connected.
- Days you opened Cmdr: the app notes each day you open it, in a file on your Mac, so a tip can wait until you’ve settled in. It stays on your Mac and never reaches us.
We never collect your file contents, keystrokes, or screenshots. Usage stats and crash reports never include file names, search queries, or AI prompts. The one place these can reach us is the logs of an error report you chose to send: file names there are replaced with placeholders, but, as explained above, a name that appears on its own can get through. Beyond the usage stats, the desktop app’s network calls are license validation (including the device identifier above), checking for updates, sending crash reports (unless you’ve turned them off), and sending error reports you choose to send.
What we DON’T collect
- The contents of your files, ever. We don’t want to know your files. Your file and folder names don’t reach us either: in an error report they’re replaced with placeholders on your Mac, keeping only the file extension and everyday folder names like Documents or Downloads. (A name mentioned on its own, with no path next to it, can slip through, which is why you see the report before you send it.) We see the shape of what happened, not what you were working on.
- Your prompts, the AI’s answers, tool calls, etc. With a cloud provider, the app talks to it directly using your own API key: the conversation never passes through our servers. What you send is between you and that provider, under their terms. Cloud AI stays off until you allow it in Settings, where Cmdr lists what each feature sends. With Cmdr you can also keep everything on your Mac with a local model.
- Crash reports carry only technical diagnostics: code locations, app and system version, and a crash message cleaned on your Mac first. Never file contents.
- Your keystrokes or screenshots. During the open beta we do see which features are used, never their content.
- And we never train models on your data!
3. Why we collect this data (legal basis)
Under GDPR (EU law to protect your rights over your data), we need a legal basis for processing your data, which is pretty nice and fair and we apply it to all our users globally, not just EU citizens. Here is a list:
- License validation and subscription status checks: As a business baseline, we need to know who has a valid license and who doesn’t.
- Legitimate interest: Website analytics, download records, and the beta usage stats show us how people find and use Cmdr, which directly shapes the roadmap. Crash reports tell us where Cmdr breaks, so we can fix it. This is strictly not about tracking any particular user. We actively avoid that. We read these numbers in aggregate; the random id lets us count people without knowing who they are, and we never use it to look someone up. The usage stats and crash reports come with an easy opt-out in Settings > Updates & privacy.
- Consent: Email addresses to send you news that hopefully interest you, including the optional beta contact email. (You can unsubscribe anytime from all communications we send, except for stuff we need to send like updates to this very policy.)
- Consent: Error reports and feedback, each sent only when you choose to send it.
4. How we use your data
- To process your license purchase
- To maintain and improve Cmdr
- To send you product updates (if you subscribed)
- To respond to your support requests
- To analyze website traffic and improve our communication
5. Who we share data with
We only share data with service providers who help us operate Cmdr:
- Paddle (payments): processes purchases, handles taxes and invoicing. Based in the UK with GDPR-compliant processing. Paddle’s privacy policy
- PostHog (website behavior and desktop usage stats): session recordings and heatmaps to help us improve the website experience, and the PII-free feature stats the desktop app sends during the open beta, tied to the random id described above. The app doesn’t contact PostHog: these stats reach it through our API server. Cloud-hosted in the EU. PostHog’s privacy policy
- Cloudflare (hosting): runs our API server on its global CDN for license validation, downloads, and crash, error report, and feedback intake. Download records, crash reports, feedback, and beta usage stats live in Cloudflare D1 (SQLite); error report bundles live in Cloudflare R2. Cloudflare’s privacy policy
- Discord (how we hear about problems): error reports, feedback, and beta signups ping a private channel only we can read, so we notice things fast. The ping never includes your email address. Discord is a US company. Discord’s privacy policy
- GitHub (download hosting and issue tracking): the app and its updates come from GitHub Releases, so GitHub sees your IP address when you download or update Cmdr, like any web server. We also track our work there: an error report or feedback message you send becomes an issue in a private repository only we can read. Your message, and your email address if you attached one, go in a separate comment that we delete on the schedule below. GitHub is a US company. GitHub’s privacy statement
- Resend (license, newsletter, and notification emails): sends the email with your license key, the newsletter and its confirmation emails, and the notification emails that tell us about new crash reports, error reports, and feedback, including what you wrote and your email address if you attached one. Resend is a US company, sending our emails from its Ireland region. Resend’s privacy policy
- SMTP2Go (outgoing email): relays the emails we send from
@getcmdr.comaddresses, like our replies to you. SMTP2Go is a New Zealand company and says it stores data of EEA customers only in the EEA. SMTP2Go’s privacy policy - Hetzner (our server): hosts the website, Umami, Listmonk, and our mail server on a server
in Helsinki, Finland. Email you send to any
@getcmdr.comaddress lands in our self-hosted inbox there, and so do the notification emails above. Hetzner’s privacy policy - Listmonk (newsletter and beta list): self-hosted on our server. Stores your email address and subscription status, including the optional beta contact email you can share in the desktop app. Your signup passes through our API server on its way there, which doesn’t keep it. No data leaves our infrastructure except when sending emails via Resend.
Our page-level website analytics (Umami) are self-hosted on our own server. No data is shared with any third party for that.
We don’t sell your data. We don’t share it with advertisers or anyone not listed above.
6. Where we store your data
Page-level website analytics (Umami), our newsletter system (Listmonk), and our email inbox (mailcow) are self-hosted on our own server at Hetzner in Helsinki, Finland. Our license, telemetry, and report server runs on Cloudflare Workers on a global CDN, with its database and file storage in Cloudflare’s network. PostHog and Paddle are GDPR-compliant and have appropriate data processing agreements in place.
Discord, GitHub, and Resend are US companies, so our Discord notifications, the downloads GitHub serves, and the license and notification emails Resend sends involve a transfer outside the EU, under those companies’ own data protection terms. SMTP2Go, which relays the emails we send, is a New Zealand company, a country the EU recognizes as giving adequate data protection.
7. How long we keep your data
A daily job on our server enforces these, so they hold whether or not anyone remembers to check.
- Purchase records: kept for seven years (Swedish accounting law requirement)
- Email subscriptions: kept until you unsubscribe, then we have no use for it.
- Website analytics: deleted after two years. A monthly job removes everything older than 23 months.
- Website server logs: our web server notes each request’s time, page, referring site, browser, and preferred language, but never your IP address. We delete them after 30 days.
- Downloads: the hashed IP address and user agent go after 90 days. What’s left (version, architecture, country, and where the download came from) points to no one, and we keep it while it’s useful.
- Update checks: individual records go after seven days, leaving the daily totals per version.
- Desktop usage stats: two years, then deleted.
- Crash reports: your email address, if you attached one, and the id grouping your reports go after 90 days. The technical part (version, signal, and where in our code it happened) has no time limit: it names nobody, and it’s how we chase down long-standing stability issues.
- Error reports: 90 days. That covers the whole bundle, your email address if you attached one, anything you added to the report afterwards, and what you wrote in our issue tracker copy. What’s left after that is the technical part (the report id, your app and macOS version, and where the bundle used to live), which has no time limit: it names nobody, and it’s how we keep track of a bug we haven’t fixed yet.
- Feedback: we keep your message so we can act on it. An email address you gave for a reply goes after two years.
8. Cookies
Our website sets no tracking cookies. PostHog, which we use for session recordings and heatmaps, keeps its session in your browser’s memory only while the page is open, and sets no cookie. Umami, our page analytics tool, doesn’t use cookies at all.
We don’t use third-party advertising cookies or cross-site tracking.
9. Your rights (GDPR)
EU residents have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data (“right to be forgotten”)
- Portability: receive your data in a machine-readable format
- Object: object to processing based on legitimate interest
- Withdraw consent: for newsletter subscriptions, unsubscribe anytime
To exercise these rights, email us at [email protected]. We’ll respond within 30 days.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.
That said, we try to be nice to everyone, not just EU citizens.
10. Children’s privacy
Cmdr is not directed at children under 16. We don’t knowingly collect data from children. If you believe we have, please contact us and we’ll delete it.
11. Changes to this policy
We may update this policy occasionally. We’ll notify you of significant changes via email (if you’ve purchased a license) or by posting on our website. The “Last updated” date at the top tells you when it was last revised.
12. Contact
Questions about your data? Want to exercise your rights? Email us at [email protected].