- Home
- Privacy Policy
Privacy Policy
The short version: your installed package list and brew commands never leave your Mac, we collect the minimum needed to sell and support the software, and we do not sell personal information to anyone.
- Who is responsible for your data
- What stays on your Mac
- What we collect, and why
- Legal bases for processing
- Who we share data with
- How long we keep it
- Your rights in California and other US states
- Your rights under GDPR
- Cookies and similar technologies
- Security
- Children
- International transfers
- Changes and contact
1. Who is responsible for your data
The data controller is Tidewell Software LLC, 2261 Market Street, Suite 4018, San Francisco, CA 94114, United States. For any privacy question or request, write to privacy@tidewell.app or call +1 (415) 555-0198. Our data protection contact is our Privacy Team.
2. What stays on your Mac
This is the most important section in this policy, so it comes first.
Package management is entirely local. When Tidewell reads your installed brew packages, runs brew commands, or caches formula metadata, that data is processed on your computer and is never transmitted to us or to anyone else. There is no cloud sync step, and the app does not need a network connection to browse installed packages or review command history.
Command logs and cached formula data are stored locally in your Application Support folder. We have no copy of them and no ability to access them.
3. What we collect, and why
| Category | Examples | Why we need it |
|---|---|---|
| Account and purchase data | Name, email address, country and state, licence key, plan, order history, invoices | To sell you a licence, deliver the key, issue invoices, handle renewals and refunds, and identify you when you contact support |
| Payment data | Card type, last four digits, billing address, transaction identifiers | To take payment and handle chargebacks. Full card numbers are handled by our payment processor and never reach our systems |
| Support correspondence | Messages you send us, plus the macOS version and Mac model you choose to share | To answer your question and keep a record of the issue |
| Licence activation data | A one-way hash of a hardware identifier, app version, macOS version, activation timestamps | To enforce the seat limit of your plan. The hash cannot be reversed into a device identifier |
| Diagnostics — opt-in only | Crash stack traces, anonymous feature-use counters, error codes | To find and fix defects. Off by default; you choose during setup and can change it any time in Settings → Privacy |
| Website usage | Pages viewed, referrer, approximate region from IP, device and browser type | To understand which pages are useful and to keep the site secure. Analytics cookies are only set if you accept them |
We do not collect biometric data, precise geolocation, contact lists, browsing history, keystrokes, or the contents of any file on your computer. We do not build advertising profiles and we do not use your data to train machine learning models.
4. Legal bases for processing
Where the GDPR or similar law applies, we rely on:
- Performance of a contract — account, purchase, licensing and support data, which we need in order to provide what you paid for.
- Legitimate interests — site security, fraud prevention, and aggregate reporting that does not identify you.
- Consent — opt-in diagnostics, optional analytics cookies, and marketing emails. You can withdraw consent at any time without affecting anything else.
- Legal obligation — tax and accounting records.
5. Who we share data with
We do not sell personal information, and we do not share it with data brokers or advertising networks. We use a small number of service providers who process data on our behalf under contract, and only for the purpose stated:
| Provider | Purpose | Location |
|---|---|---|
| Paddle.com Market Ltd | Payment processing, invoicing, subscription billing | Ireland |
| Google Workspace | Transactional email — licence keys, receipts, renewal reminders | United States |
| Vercel Inc. | Website and application hosting, server logs | United States |
| Plain | Support ticketing and correspondence history | United States |
| Plausible Analytics | Aggregate website analytics — only active if you accept analytics cookies | European Union |
We may also disclose information where legally required — in response to a valid subpoena, court order or lawful government request — or to establish or defend legal claims. If we are ever involved in a merger or acquisition, personal data may transfer to the acquirer, and we will notify you before that happens and before this policy changes.
6. How long we keep it
- Purchase and tax records — seven years, as required by US tax law.
- Account and licence data — while your licence is active, then 24 months, so that reinstalls and support requests still work.
- Support correspondence — 36 months.
- Opt-in diagnostics — 90 days, then deleted or irreversibly aggregated.
- Server access logs — 30 days.
- Analytics data — 14 months.
You can ask us to delete your account data sooner; see section 7. We will comply except where we are legally required to retain records, in which case we will tell you which category and why.
7. Your rights in California and other US states
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas or another state with comprehensive privacy legislation, you have the right to:
- Know and access the categories and specific pieces of personal information we hold about you, and where we got them;
- Delete personal information we hold about you, subject to legal retention requirements;
- Correct inaccurate personal information;
- Portability — receive your data in a portable, machine-readable format;
- Opt out of the sale or sharing of personal information for cross-context behavioural advertising, and of profiling with legal effects;
- Non-discrimination — we will never degrade your service, raise your price or refuse support because you exercised a privacy right.
Notice regarding sale and sharing: in the twelve months preceding the date above, we did not sell personal information, and we did not share personal information for cross-context behavioural advertising. We do not process sensitive personal information for purposes requiring a right to limit.
To exercise any right, email privacy@tidewell.app with the subject line "Privacy request", or call +1 (415) 555-0198. We verify requests by confirming control of the email address associated with your purchase, and for deletion we may ask for one additional matching detail such as an order number. We respond within 45 days and may extend once by a further 45 days with notice. An authorised agent may submit a request on your behalf with written permission that we can verify. If we deny a request you may appeal by replying to our decision, and we will respond to the appeal within 45 days.
8. Your rights under GDPR
If you are in the United Kingdom, the European Economic Area or Switzerland, you additionally have the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests, and the right to withdraw consent at any time. Requests go to the same address as above.
You also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first, but that is your choice, not a precondition.
9. Cookies and similar technologies
This site uses a deliberately small number of cookies. Strictly necessary cookies are set without consent because the site cannot function without them. Analytics cookies are only set after you choose "Accept all" in the cookie banner, and you can change your mind at any time by clearing site data in your browser.
| Name | Category | Purpose | Duration |
|---|---|---|---|
tidewell.cookie-choice |
Strictly necessary | Remembers your cookie preference so the banner does not reappear. Stored in local storage, not sent to any server. | 12 months |
tidewell_session |
Strictly necessary | Maintains your session during checkout and in your account area | Session |
tidewell_csrf |
Strictly necessary | Protects forms against cross-site request forgery | Session |
_plausible |
Analytics — optional | Aggregate page-view measurement. Not used for advertising or profiling. | 24 months |
We do not use advertising cookies, cross-site trackers, session recording or heat-mapping tools. We honour the Global Privacy Control signal, and browsers sending it are treated as having declined optional cookies.
10. Security
Data in transit is encrypted with TLS 1.2 or higher. Data at rest in our systems is encrypted. Administrative access to production systems requires multi-factor authentication and is limited to staff who need it. We review access quarterly and keep audit logs of changes.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators without undue delay and in any case within 72 hours of becoming aware, telling you what happened, what data was involved and what we are doing about it.
11. Children
Tidewell is intended for adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact privacy@tidewell.app and we will delete it promptly.
12. International transfers
We are based in the United States and our systems are hosted in United States. If you use the Service from outside the US, your account data will be transferred to and processed in the US. For transfers from the UK, EEA or Switzerland we rely on the European Commission's Standard Contractual Clauses together with a transfer risk assessment. A copy of the clauses is available on request from privacy@tidewell.app.
13. Changes and contact
We will post any change to this policy on this page with an updated date. For material changes we will email registered users at least 30 days before they take effect.
Tidewell Software LLC
Attn: Privacy
2261 Market Street, Suite 4018
San Francisco, CA 94114
United States
privacy@tidewell.app
· +1 (415) 555-0198