Privacy Policy
Last updated: 19 July 2026
This policy explains what data MacMusicKeys handles and who else is involved. MacMusicKeys is run by Marian Vinicay, a sole trader based in New York, United States. We have built the Service to collect as little as possible.
The short version: we never see your name, email, or card details - those stay with Paddle, our payment provider. The App keeps your license and signed trial grant on your own Mac. When you start your free trial, it sends an app-specific one-way hash derived from the Mac's platform identifier and the local macOS account's directory identifier, so reinstalling under that account cannot restart its trial; neither raw identifier is sent. A new owner's local account can receive its own trial. If either source identifier is unavailable, no hardware-only hash is sent; our server creates a random trial identifier instead. If the App loses its local trial record - for example after a reinstall, or if local app data is cleared - it also sends that same hash once, before you click anything, to ask whether this Mac already has a trial; if it finds none, nothing is stored and it keeps waiting for you to start the trial as usual. While trialing or licensed, the App also sends a separate random identifier it generates (not tied to your hardware) and the date to count trial starts, subscriptions, and enforce the 5-device-per-license limit. It does not track how you use the App. We run no advertising and no cross-site tracking.
1. What we store, and what we never see
Our license server stores small records so the App can issue a trial and verify a subscription:
- your license key (e.g.
MMK-XXXX-XXXX-XXXX); - the Paddle subscription and transaction identifiers tied to your purchase; and
- the subscription status (active / inactive) and a refresh date; and
- a random device identifier the App generates (deliberately not derived from your hardware) and the date it last contacted us - used to enforce the 5-device-per-license limit and to count how many people start a trial and subscribe. This identifier is recorded once you start the free trial - or, if the App silently confirms an existing trial after losing its local record (see section 2), at that point instead. It is never recorded by a check that finds no existing trial, and is not linked to how you use the App; and
- an app-specific SHA-256 hash derived from the Mac's platform identifier and the local account's Open Directory GUID, together with the start and expiry dates of its trial grant, so deleting local data or reinstalling under that account cannot restart the trial - including via the silent check above, which asks whether a trial already exists for this hash before ever creating one. We never receive or store either raw identifier, your account name, or your account password. If the App cannot obtain both source identifiers, it omits this hash and our server generates a random UUID for that trial issuance.
These identifiers can be linked back to you through Paddle, so we treat this record as personal data. What our server never receives or stores is your name, email address, billing address, or payment-card details - that information is held by Paddle, not by us.
2. Data the App keeps on your Mac
The App stores your license key, signed trial grant, and the random device identifier
locally, in the macOS Keychain on your device. It contacts our license server
(api.macmusickeys.com):
- while licensed, it periodically sends your license key together with the random device identifier, to check that your subscription is still active and to enforce the 5-device limit;
- when you explicitly start the free trial, it sends the random device identifier and, when available, the one-way platform-and-account hash to obtain a signed seven-day grant. If that hash is unavailable, our server creates a random trial identifier instead. While the trial is running, it periodically sends only that random device identifier and the date, so we can count how many people start a trial and subscribe. The periodic contact carries no platform-derived hash, license key, or usage data; and
- if the App is waiting for you to start a trial but has no valid local trial record - for example right after a reinstall, or if local app data was cleared - it sends the same one-way hash once, before you click anything, to ask our server whether this Mac already has a trial. If it finds none, nothing is stored and the App keeps waiting for you to start the trial. If it finds one, the server reissues its original signed grant and dates - never a new trial - and the App resumes automatically, without ever showing the Start Trial button.
The App does not send your listening history, the contents of Music, keystrokes, or any analytics about how you use the App - the identifier and date tell us that a device exists and was active, not what you did with it. As with any internet request, our server (via Cloudflare) may briefly log the connecting IP address for security and abuse prevention.
3. Buying a subscription (Paddle)
Purchases are handled by Paddle as our Merchant of Record. When you check out, you provide your details directly to Paddle, which processes your payment and collects any tax. Paddle's handling of your data is governed by Paddle's Privacy Policy. We receive a license record from Paddle (see section 1) but not your payment information.
4. Delivering your license key by email
Right after a successful first purchase, our server asks Paddle for the email address you used and sends your license key to it once, as a backup to the on-screen key. That single email is sent through Amazon SES. We do not add you to any mailing list and do not store your email address on our server afterwards.
5. The website
The website is served through Cloudflare. We use Cloudflare Web Analytics, which is privacy-friendly and does not use tracking cookies or fingerprinting to follow you across sites. Pages load the checkout script from Paddle; loading that resource means your IP address is visible to Paddle, as with any embedded resource. The only cookies you may encounter are those Paddle sets during checkout - we set no advertising or analytics cookies of our own, so there is no cookie banner.
6. The contact form
The contact form does not send anything to a server of ours. It opens a pre-filled message in your own email app addressed to us; you choose whether to send it. If you do email us, we keep that correspondence in our inbox (Proton Mail) to answer you and for our records.
7. Who else processes data (sub-processors)
- Paddle - payment processing as Merchant of Record.
- Cloudflare - website hosting, the license server, request logs, and cookieless Web Analytics.
- Amazon SES - sending the one-off license-key email.
8. How long we keep it
We keep your license record for as long as your subscription exists and for a reasonable period afterwards, and as needed to meet legal, tax, and accounting obligations. Paddle and our other providers keep their own records under their own policies.
9. Your rights
Depending on where you live - including if you are in the EU, UK, or a US state with a privacy law - you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. Because most of your data sits with Paddle, some requests are best directed there. For anything we hold, email [email protected] and we will respond as required by applicable law. You can also complain to your local data-protection authority.
10. Children
MacMusicKeys is not directed at children under 13, and we do not knowingly collect data from them.
11. Changes to this policy
If we change this policy, we will update the "Last updated" date above. Material changes will be reflected here.
12. Contact
Questions about privacy? Email [email protected].
Pricing · Refunds · Cancel · Terms of Service · Back to MacMusicKeys