Privacy Policy (GDPR)
This policy describes how we process personal data in connection with notchflow.eu and the NotchFlow macOS app. We minimize data collection by design — most app data stays on your Mac.
1. Data controller
MTBIZ Marcin Tymków
Michałowice 61
49-314 Pisarzowice, Poland
Tax ID (NIP): 7471912158
Email: hello@notchflow.eu
2. Scope
This policy covers the website, premium license purchases, email contact, and app behavior where data leaves your device. Third-party services (GitHub, Polar, etc.) have their own policies.
3. What we process
3.1. Website
The site is static — no accounts or login required.
Google Analytics 4 — with your consent via the cookie banner, we collect anonymous visit statistics (e.g. pages viewed, time on site, device/browser type, approximate geographic origin). Google Analytics loads only after you click “Accept analytics”. Rejecting tracking does not limit access to the site. You can withdraw consent anytime via “Cookie settings” in the footer.
We use Google Consent Mode v2 — analytics is denied by default and Google ad signals are not enabled.
- Server logs — IP address, request time, URL, browser/OS (short-term hosting logs)
- Theme preference and cookie consent — stored in browser
localStorage, not sent to our server - Google Fonts — your browser loads fonts from Google; Google may receive your IP per its privacy policy
We do not set our own cookies except those set by Google Analytics after consent.
3.2. Email contact
If you email us, we process your address, message content, and any details you include voluntarily.
3.3. Premium purchases
Polar processes payments as Merchant of Record (email, billing data, payment info). We receive order details needed to fulfill the license but do not store payment card data.
3.4. NotchFlow app (macOS)
No user account required. Notes, clipboard, shelf files, and settings are stored locally in Application Support.
Data may leave your device only when:
- License validation — license key and device name sent to Polar (premium only)
- Updates — official builds fetch appcast metadata from notchflow.eu (Sparkle)
- Lyrics (opt-in) — track title and artist sent to lrclib.net if enabled in Settings → Privacy
- Album artwork — fetched from Spotify CDN servers during playback
- Downloads — via GitHub Releases (GitHub’s policy applies)
3.5. What we do not collect
- No telemetry in the macOS app
- No ad profiling or remarketing
- No upload of clipboard, notes, shelf files, or browsing history to our servers
- No ad identifiers or cloud user accounts
4. Legal bases (GDPR)
- Website analytics (Google Analytics) — consent (Art. 6(1)(a))
- Website operation and security — legitimate interest (Art. 6(1)(f))
- Email replies — legitimate interest or pre-contract steps
- Premium sales and license validation — contract (Art. 6(1)(b))
- Tax and accounting — legal obligation (Art. 6(1)(c))
5. Recipients
- Google LLC (Google Analytics) — website visit statistics, only after consent (Google privacy policy)
- Polar — payments and license validation (Polar privacy policy)
- Website hosting provider — serving notchflow.eu and appcast
- Google LLC — Google Fonts
- GitHub (Microsoft) — release hosting
- lrclib.net — optional lyrics lookup
- Spotify CDN — album artwork
We do not sell personal data.
6. Transfers outside the EEA
Some providers (Polar, Google, GitHub) may process data in the US or other countries. Transfers follow GDPR requirements including standard contractual clauses where applicable.
7. Retention
- Email correspondence — up to 3 years after the matter is closed
- Order data — as required by tax law (generally 5 years)
- Server logs — up to 90 days
- Google Analytics data — per GA account settings (typically up to 14 months); consent can be withdrawn anytime
- Local app data — until you delete it or uninstall the app
8. Your rights
Under GDPR you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interest. You may lodge a complaint with a supervisory authority in your EU country.
Privacy contact: hello@notchflow.eu
9. Cookies and local storage
Essential (localStorage): theme preference (notchflow-theme) and cookie consent choice (notchflow-cookie-consent) — not sent to our server.
Analytics (Google Analytics): set only after clicking “Accept analytics” in the banner. Used to measure site traffic. You can reject, withdraw consent via “Cookie settings” in the footer, or clear data in browser settings.
Google may set cookies such as _ga and _ga_*. Details: Google cookie policy.
10. Clipboard, local API, and permissions
Clipboard monitoring is off by default. The Raycast integration uses a loopback HTTP server (127.0.0.1) with a Keychain token — API traffic never leaves your Mac. Calendar, camera, Accessibility, and notification banner reading process data locally in RAM and are not saved to disk.
11. Security
We use HTTPS, data minimization, and no central user database for the app. See our Security page for distribution details.
12. Changes
We may update this policy when features or providers change. The current version is always published here with its effective date.