Tidewell
  • Home
  • Privacy Policy

Privacy Policy

The short version: your installed package list and brew commands never leave your Mac, we collect the minimum needed to sell and support the software, and we do not sell personal information to anyone.

Last updated: August 1, 2026 · Effective: August 1, 2026 · Version: 2.1

1. Who is responsible for your data

The data controller is Tidewell Software LLC, 2261 Market Street, Suite 4018, San Francisco, CA 94114, United States. For any privacy question or request, write to privacy@tidewell.app or call +1 (415) 555-0198. Our data protection contact is our Privacy Team.

2. What stays on your Mac

This is the most important section in this policy, so it comes first.

Package management is entirely local. When Tidewell reads your installed brew packages, runs brew commands, or caches formula metadata, that data is processed on your computer and is never transmitted to us or to anyone else. There is no cloud sync step, and the app does not need a network connection to browse installed packages or review command history.

Command logs and cached formula data are stored locally in your Application Support folder. We have no copy of them and no ability to access them.

3. What we collect, and why

Category Examples Why we need it
Account and purchase data Name, email address, country and state, licence key, plan, order history, invoices To sell you a licence, deliver the key, issue invoices, handle renewals and refunds, and identify you when you contact support
Payment data Card type, last four digits, billing address, transaction identifiers To take payment and handle chargebacks. Full card numbers are handled by our payment processor and never reach our systems
Support correspondence Messages you send us, plus the macOS version and Mac model you choose to share To answer your question and keep a record of the issue
Licence activation data A one-way hash of a hardware identifier, app version, macOS version, activation timestamps To enforce the seat limit of your plan. The hash cannot be reversed into a device identifier
Diagnostics — opt-in only Crash stack traces, anonymous feature-use counters, error codes To find and fix defects. Off by default; you choose during setup and can change it any time in Settings → Privacy
Website usage Pages viewed, referrer, approximate region from IP, device and browser type To understand which pages are useful and to keep the site secure. Analytics cookies are only set if you accept them

We do not collect biometric data, precise geolocation, contact lists, browsing history, keystrokes, or the contents of any file on your computer. We do not build advertising profiles and we do not use your data to train machine learning models.

4. Legal bases for processing

Where the GDPR or similar law applies, we rely on:

  • Performance of a contract — account, purchase, licensing and support data, which we need in order to provide what you paid for.
  • Legitimate interests — site security, fraud prevention, and aggregate reporting that does not identify you.
  • Consent — opt-in diagnostics, optional analytics cookies, and marketing emails. You can withdraw consent at any time without affecting anything else.
  • Legal obligation — tax and accounting records.

5. Who we share data with

We do not sell personal information, and we do not share it with data brokers or advertising networks. We use a small number of service providers who process data on our behalf under contract, and only for the purpose stated:

Provider Purpose Location
Paddle.com Market Ltd Payment processing, invoicing, subscription billing Ireland
Google Workspace Transactional email — licence keys, receipts, renewal reminders United States
Vercel Inc. Website and application hosting, server logs United States
Plain Support ticketing and correspondence history United States
Plausible Analytics Aggregate website analytics — only active if you accept analytics cookies European Union

We may also disclose information where legally required — in response to a valid subpoena, court order or lawful government request — or to establish or defend legal claims. If we are ever involved in a merger or acquisition, personal data may transfer to the acquirer, and we will notify you before that happens and before this policy changes.

6. How long we keep it

  • Purchase and tax records — seven years, as required by US tax law.
  • Account and licence data — while your licence is active, then 24 months, so that reinstalls and support requests still work.
  • Support correspondence — 36 months.
  • Opt-in diagnostics — 90 days, then deleted or irreversibly aggregated.
  • Server access logs — 30 days.
  • Analytics data — 14 months.

You can ask us to delete your account data sooner; see section 7. We will comply except where we are legally required to retain records, in which case we will tell you which category and why.

7. Your rights in California and other US states

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas or another state with comprehensive privacy legislation, you have the right to:

  • Know and access the categories and specific pieces of personal information we hold about you, and where we got them;
  • Delete personal information we hold about you, subject to legal retention requirements;
  • Correct inaccurate personal information;
  • Portability — receive your data in a portable, machine-readable format;
  • Opt out of the sale or sharing of personal information for cross-context behavioural advertising, and of profiling with legal effects;
  • Non-discrimination — we will never degrade your service, raise your price or refuse support because you exercised a privacy right.

Notice regarding sale and sharing: in the twelve months preceding the date above, we did not sell personal information, and we did not share personal information for cross-context behavioural advertising. We do not process sensitive personal information for purposes requiring a right to limit.

To exercise any right, email privacy@tidewell.app with the subject line "Privacy request", or call +1 (415) 555-0198. We verify requests by confirming control of the email address associated with your purchase, and for deletion we may ask for one additional matching detail such as an order number. We respond within 45 days and may extend once by a further 45 days with notice. An authorised agent may submit a request on your behalf with written permission that we can verify. If we deny a request you may appeal by replying to our decision, and we will respond to the appeal within 45 days.

8. Your rights under GDPR

If you are in the United Kingdom, the European Economic Area or Switzerland, you additionally have the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests, and the right to withdraw consent at any time. Requests go to the same address as above.

You also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first, but that is your choice, not a precondition.

9. Cookies and similar technologies

This site uses a deliberately small number of cookies. Strictly necessary cookies are set without consent because the site cannot function without them. Analytics cookies are only set after you choose "Accept all" in the cookie banner, and you can change your mind at any time by clearing site data in your browser.

Name Category Purpose Duration
tidewell.cookie-choice Strictly necessary Remembers your cookie preference so the banner does not reappear. Stored in local storage, not sent to any server. 12 months
tidewell_session Strictly necessary Maintains your session during checkout and in your account area Session
tidewell_csrf Strictly necessary Protects forms against cross-site request forgery Session
_plausible Analytics — optional Aggregate page-view measurement. Not used for advertising or profiling. 24 months

We do not use advertising cookies, cross-site trackers, session recording or heat-mapping tools. We honour the Global Privacy Control signal, and browsers sending it are treated as having declined optional cookies.

10. Security

Data in transit is encrypted with TLS 1.2 or higher. Data at rest in our systems is encrypted. Administrative access to production systems requires multi-factor authentication and is limited to staff who need it. We review access quarterly and keep audit logs of changes.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators without undue delay and in any case within 72 hours of becoming aware, telling you what happened, what data was involved and what we are doing about it.

11. Children

Tidewell is intended for adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact privacy@tidewell.app and we will delete it promptly.

12. International transfers

We are based in the United States and our systems are hosted in United States. If you use the Service from outside the US, your account data will be transferred to and processed in the US. For transfers from the UK, EEA or Switzerland we rely on the European Commission's Standard Contractual Clauses together with a transfer risk assessment. A copy of the clauses is available on request from privacy@tidewell.app.

13. Changes and contact

We will post any change to this policy on this page with an updated date. For material changes we will email registered users at least 30 days before they take effect.

Tidewell Software LLC
Attn: Privacy
2261 Market Street, Suite 4018
San Francisco, CA 94114
United States
privacy@tidewell.app · +1 (415) 555-0198

Cookies on this site

We use cookies that are strictly necessary to run the site and process orders. Optional analytics cookies help us see which pages are useful — they are never used for advertising profiles and you can decline without losing any functionality.

Details