mac-apps

Privacy Policy

Last updated: January 1, 2026

mac-apps ("we", "us", "our") respects your privacy. This policy describes what we collect, how we use it, and the choices you have. The short version: we collect almost nothing, and what we do collect stays anonymous.

1. Summary

  • No analytics, no telemetry, no tracking pixels.
  • No reading of your files, photos, contacts, calendars, or browsing history.
  • No collection of your device serial number, MAC address, or hardware identifiers.
  • Your license is verified via an anonymous hash of your Apple ID or device.
  • You can use every feature offline.
  • Anonymous usage statistics are required for app operation and cannot be disabled (see Section 2.3).

2. Data we collect

2.1 Local data (stored on your Mac)

To deliver its core function, MidClick stores the following data locally using AES-256-GCM encryption with HMAC-SHA256 integrity verification:

  • Daily usage counter (e.g. "you have used 47 of 300 middle-clicks today")
  • Your license status (free vs Pro) and activation data
  • An encrypted version of your license key (Pro users)
  • An anonymous hash of your Apple ID (if signed into iCloud) or device fingerprint
  • Your app preferences (sensitivity, debounce, app lists, language)

This data is stored in ~/Library/Application Support/com.midclick.app/ and is never transmitted to our servers except as part of license activation (see below).

2.2 Data we receive (only for license verification)

When you activate a Pro license, we send the following to our payment processor (Creem):

  • Your license key
  • An anonymous hash (SHA-256) of either your Apple ID or device fingerprint
  • The current timestamp (for one-time license validation)

We never receive your actual Apple ID, your real name, your email address, or any other personally identifiable information through the app itself. The email address you provide at purchase is held by Creem and is only used to send you your license key and refund confirmations.

2.3 Anonymous Usage Statistics

To improve our products, the MidClick app sends anonymous usage statistics to our servers once per day. This data isnon-personal and cannot identify you:

  • install_id — a random UUID generated on first launch, used only to distinguish unique installations. It contains no user identity information.
  • Date and daily middle-click count — the total number of three-finger taps performed in a calendar day (00:00–23:59 local time).
  • App version — the version of MidClick you are running (e.g. "1.0.2").
  • macOS version — the version of macOS on your Mac (e.g. "macOS 14.5").
  • License status — whether you are using the free or Pro version (not the license key itself).

This data is collected solely for product analytics (e.g., understanding which macOS versions to support, how many users upgrade to Pro). It is never shared with third parties and is never used for advertising or profiling.

This data collection is a required component of the app and cannot be disabled. It is the only data that leaves your Mac. Uninstalling the app stops all future transmissions and the data is retained only as long as your installation exists in our aggregated analytics.

3. How we use your data

We use the data we receive solely to:

  • Verify that your license key is valid
  • Enforce the "up to 5 personal Macs per Apple ID" limit
  • Detect license sharing across unrelated accounts
  • Deactivate licenses when refunds are issued

We do not use your data for advertising, profiling, or any form of marketing automation.

4. Third parties

We use the following third-party services to operate our business. Each has its own privacy practices:

  • Creem — payment processing and license management (Merchant of Record)
  • Cloudflare — website hosting and webhook delivery
  • GitHub — source code hosting and issue tracking

We do not embed any third-party analytics, advertising networks, or social media trackers on our website or in our apps.

5. Cookies & web tracking

Our website does not use cookies for analytics or advertising. We may use strictly necessary cookies if you log in to the Creem customer portal (controlled by Creem, not us).

6. Children's privacy

Our products are not directed at children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect data from children.

7. International data transfers

License verification requests are processed in the United States and the European Union (via Creem's infrastructure). Anonymous hashes are not personal data under GDPR, but we apply the same protections regardless of jurisdiction.

8. Your rights

You have the right to:

  • Access the personal data we hold about you (typically: nothing)
  • Request deletion of your data (uninstall the app; contact us for any cloud records)
  • Export your license key via the Creem customer portal
  • Opt out of all future communications

To exercise any of these rights, email baishuang81@gmail.com.

9. Data retention

Local data is retained until you uninstall the app or delete it manually. License records on our servers are retained for the duration of the license plus 7 years for tax and audit purposes, then permanently deleted.

10. Security

All local data is encrypted at rest using AES-256-GCM with a key derived from a build-time secret and your device's hardware UUID. Tampering is detected via HMAC-SHA256 and causes a graceful fallback to free mode. License communications use HTTPS with TLS 1.2 or higher.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced via in-app notification and on our blog. The "last updated" date at the top of this page reflects the current version.

12. Contact

Questions? Concerns? Reach our privacy team atbaishuang81@gmail.com. We respond within 3 business days.