Privacy Policy
Last updated: 2026-10-08
This Privacy Policy describes how Carrington Creative Studios LLC, a Maryland limited liability company with its registered office at c/o Northwest Registered Agent Service, Inc., 306 W Redwood St, Baltimore, MD 21201, United States (“we,” “us”), handles personal data in connection with the SupaDupa macOS application and the website at supadupa.tech.
The short version: SupaDupa runs on your Mac. Your files stay on your Mac. We do not upload, index, or read the contents of your files. The personal data we hold is what you provide when you buy a license, what your app sends when it activates, and a record of how you use the app (which you can turn off in Settings → Privacy → Usage analytics).
1. Summary
| What we collect | When | Why |
|---|---|---|
| Email address | At purchase, and at license activation | Deliver the license key, contact you about your purchase, recover your key |
| Payment information | At purchase | Processed by Paddle (Merchant of Record); we never see card data |
| Country / region | At purchase | Tax compliance (VAT/GST), provided to us by Paddle |
| License key | At activation | Verify your Pro entitlement |
| Machine hash | At activation, then daily while a Pro license is active. Also on every Free-tier launch and weekly after that (anonymous, no license). | Understand how many devices a license is active on, and how many people use the Free tier; non-reversible identifier |
| Bucketed hardware metadata | At activation, then daily while a Pro license is active. Free-tier pings: on launch and weekly. | Understand the install base (Apple Silicon vs Intel, macOS version, locale, RAM range, storage range) so we can prioritize what to build |
| App version | At activation, then daily while a Pro license is active | Ensure your update window covers the version you’re running |
| Anonymous usage events | While you use the app, only if Settings → Privacy → Usage analytics is enabled (default on) | Understand which features get used, where users get stuck, and how to prioritize what to build |
| Crash reports | When the app crashes, only if Settings → Privacy → Crash Reports is enabled (default on) | Diagnose and fix bugs |
| Page views, clicks, and page-load timing (website only) | When you visit supadupa.tech | Understand how the marketing site is performing and how fast it loads |
What we do not collect:
- The names, contents, or paths of your files
- Your scan results, folder structures, or any list of files on your Mac
- Your device hostname or any other directly identifying detail of your Mac
- Cookies, ad-targeting identifiers, or fingerprinting signals on the website
- IP addresses, beyond what is incidentally visible at the moment of a network call (we do not store them)
2. Data we collect from your device
2.1 At purchase
When you buy SupaDupa, the checkout opens as an inline overlay on https://supadupa.tech/buy (powered by Paddle.js). You provide your email address and payment details directly to Paddle inside that overlay; we never see them. Paddle.com Market Limited (“Paddle”) is the merchant of record for the transaction and acts as a separate controller for checkout, billing, tax handling, and payment-related fraud prevention. Their privacy policy governs the collection of card data and billing information. See https://www.paddle.com/legal/privacy.
We receive from Paddle:
- Your email address
- Your country (for tax purposes)
- The order ID and customer ID (so we can look up your license if you contact support)
- Refund events and update-extension purchase events
We do not receive your card number, CVV, or full billing address.
2.2 At license activation
When you paste your license key into the app and click Activate, the app sends a single HTTPS request to our license backend containing:
- Your license key
- A machine hash: a one-way, salted hash of your Mac’s hardware identifier, computed on your Mac. The hash is specific to SupaDupa and cannot be reversed; we cannot derive your hardware identifier or any other device-identifying detail from it.
- Your app version.
- Bucketed hardware metadata: processor type (Apple Silicon or Intel), macOS version, system language and region, the kind of Mac (for example MacBook or iMac), a memory-size range, a disk-size range, and how full the disk is (low, medium, high, or critical). Each value is a coarse range or category, never an exact figure, so together they describe the install base without working as a fingerprint.
The license key is then stored locally on your Mac. It is digitally signed and verified on your device; it is not synced to iCloud or sent anywhere except during the periodic check-ins described below.
We previously also sent your device hostname (e.g. “Carrington’s MacBook Pro”). We removed this in May 2026 because hostnames can contain people’s names. Existing hostname records in our backend are being cleared as a routine pruning task.
2.3 Periodic check-ins
About once a day while a Pro license is active, the app sends the same machine hash, app version, and bucketed hardware metadata to our license backend. This serves three purposes:
- Confirm that the license has not been refunded (so the app can cleanly degrade to Free if it has)
- Update the “last seen” timestamp so we can understand the natural distribution of devices per license
- Communicate the current app version so we can decide whether your update window covers it
The check-in is best-effort. If the network call fails — your Mac is offline, our backend is down, you are on a captive-portal Wi-Fi — the app continues to work. We never lock you out of features you have already activated because of a failed online check.
2.4 Anonymous device record (Free tier)
If you are using SupaDupa without a Pro license, the app sends an anonymous record on launch and weekly thereafter, containing the same machine hash, app version, and bucketed hardware metadata described in §2.2 — but no license key, no email, no identifying information. We use this to understand how many people use the Free tier, what hardware they run on, and how often Free users return.
The machine hash on the Free record is the same hash the app would send if you later activated Pro. This lets us understand “trial duration” — how long someone uses Free before upgrading — without ever linking either record to your real identity until you yourself bind your email to the license at activation. You can also opt out of analytics entirely (see §2.6).
2.5 Crash reports (optional, on by default, easy to disable)
When SupaDupa crashes, the app can send a crash report to Sentry containing the stack trace, OS version, app version, and a short anonymous device identifier. This is gated by the Settings → Privacy → Crash Reports toggle. The setting defaults to on but can be turned off at any time, and the change takes effect immediately — no restart required.
Some crashes happen deep in the operating system’s own frameworks and can’t be captured as a plain stack trace. For those, the app writes a crash dump (a “minidump”) — a snapshot of the program’s memory at the moment it crashed — and sends it to Sentry so we can diagnose the failure. A memory snapshot is technical data (register values, the call stack, and program state), not your files, scan results, or license key, which we never deliberately collect. But because it is a snapshot of live memory, it can incidentally contain limited fragments of technical data — including file paths that the app was working with when it crashed. We do not target or extract that data; it is an unavoidable property of a memory snapshot, and it is the reason crash dumps are treated as more sensitive than the anonymous, counts-only usage analytics in §2.6.
Crash dumps follow the same Settings → Privacy → Crash Reports consent as everything else in this section, with two safeguards: the dump is written only to your Mac at crash time and is not uploaded until the app’s next launch — and if Crash Reports is turned off, any pending dump is deleted from your Mac unsent. So turning the toggle off means no crash dump ever leaves your machine.
2.6 Usage analytics (optional, on by default, easy to disable)
While you use SupaDupa, the app sends anonymous events to PostHog describing what you do — for example, that you started a scan, viewed an upgrade prompt, used a Pro feature, or changed a setting. Events carry small numeric properties (how many files a scan found, what file-type counts, how long a job took) but never file names, paths, or contents. We use these to understand which features matter, where users get stuck, and how to prioritize what to build next.
Events are identified by the same anonymous machine hash described in §2.2 until you activate a Pro license; after activation, events on that device are associated with your purchase email so that customer support and conversion analysis can be done at the customer level (rather than at the per-device level).
This is gated by the Settings → Privacy → Usage analytics toggle. The setting defaults to on but can be turned off at any time, and the change is honored immediately — no restart required. When the toggle is off, no new events are sent and the in-memory event buffer is dropped.
We also aggregate these events across all users to produce summary metrics (for example, “users scanned X TB of files this month” or “Y% of users have low storage pressure”). Aggregates are anonymous by construction.
2.7 Update checks
While the app is open, it checks our update server (dl.supadupa.tech) about once an hour for new versions. The update server sees only your IP address and basic request information such as the app and macOS version. It is not connected to your license or your purchase record.
2.8 Support email
When you email hello@supadupa.tech, we receive your email address, the subject and body of your message, and any attachments you choose to include. Inbound mail is forwarded by Cloudflare Email Routing to a managed inbox we operate; Cloudflare acts as a service provider in this path and does not store the messages persistently after delivery.
We use support emails to respond to your question, recover license keys, process refund requests, and handle privacy-rights requests. We retain support correspondence for 24 months after the issue is resolved so we can recognize repeat issues and respond to follow-ups, after which it is deleted. We do not feed support email contents into automated decision-making systems, and we do not use them to train machine-learning models.
2.9 Local AI model download (not yet in a released build)
Some planned features run a language model on your Mac. The model file is large, so it is not included in the app download. The first time you turn on a feature that needs it, the app downloads the model once from dl.supadupa.tech — the same first-party domain the auto-updater already uses. The app shows you the download size first, and the download happens only if you choose to enable the feature.
The direction of this transfer matters. It downloads a model to your device. It does not upload your files, file names, paths, or anything derived from them. Once the model is on your Mac it runs entirely locally: analysing your files needs no network connection, and the results are never sent anywhere. The download server sees what any file download exposes — your IP address, the app version, and your OS version — and nothing tied to your license or your files.
Because this call only ever receives data, it adds nothing to the collection table in §1.
This section describes a feature that is not yet in a released build. It is documented ahead of the release so that the list in §3 is complete on the day it ships.
3. Network calls the app makes
This is the complete list of network calls SupaDupa makes. If a future release adds a new outbound endpoint, this list will be updated and the change noted in the changelog.
| Endpoint | When | Data sent | Can be disabled? |
|---|---|---|---|
| Update check (dl.supadupa.tech) | Hourly while the app is open | App version, OS version | Yes — disable Settings → Updates → Automatic |
| License activation (one-time per device) | When you click Activate | License key, machine hash, app version, bucketed hardware metadata | Required to use Pro features |
| License status check-in | Daily while you have an active Pro license | Machine hash, app version, bucketed hardware metadata | No (it’s the mechanism that detects refunds and version eligibility; daily is what lets a refund take effect within a day rather than a week) |
| Anonymous Free-tier device ping | On launch and weekly while you do NOT have an active Pro license | Machine hash, app version, bucketed hardware metadata. No license key, no email. | Not separately — opting out of usage analytics in Settings does not disable this ping. Email us if you want to be excluded. |
| Usage analytics events (PostHog) | As you use the app | Event name and a small number of properties (counts, buckets, feature names). No file names, paths, or contents. | Yes — toggle Settings → Privacy → Usage analytics |
| Sentry crash report | On the next launch after a crash | Stack trace, OS version, app version; for OS-level crashes, a memory-snapshot crash dump that may incidentally contain limited technical data such as file paths (see §2.5) | Yes — toggle Settings → Privacy → Crash Reports; when off, pending dumps are deleted unsent |
| Model download for local AI features (dl.supadupa.tech) | Once, and only if you enable a local AI feature that needs the model | App version, OS version, and your IP address, as with any file download. No license key, machine hash, file names, paths, or file contents. The transfer is inbound — see §2.9 | Yes — it happens only if you enable the feature |
Other than the endpoints listed above and ordinary network behavior outside our control (for example DNS, TLS, or operating-system-level certificate checks), SupaDupa is not designed to make other application-level outbound requests. We do not embed third-party ad SDKs, marketing SDKs, or attribution SDKs.
4. The website (supadupa.tech)
4.1 Analytics
We use PostHog to understand how visitors use the marketing site: which pages are viewed, which links and buttons are clicked (for example Download or Buy), and whether a checkout completes. It sets no cookies: the identifier it uses lasts only until you close the tab, it uses no cross-site identifiers, and it does no fingerprinting. Website visitors are anonymous — PostHog only creates a profile when you complete a purchase, at which point the email you gave Paddle is used to link your checkout to your later in-app license activation (the same email-based identity the app uses, see §2.2). Until you purchase, your website activity is not tied to your identity. PostHog is the same provider used for in-app usage analytics (§2.6).
We also use Cloudflare Web Analytics to count page views and measure how quickly pages load and respond for real visitors. It is provided by Cloudflare, Inc., which also hosts and delivers this site. It sets no cookies, does not track you across sites, and gives us aggregate figures only. See https://www.cloudflare.com/privacypolicy/.
4.2 Cookies and the Paddle checkout
The marketing site does not set any cookies of its own.
The Paddle checkout overlay is loaded only when you visit the /buy page — not on the homepage, not on /pricing, not on any other page. When you land on /buy, the page loads Paddle’s checkout script, which renders the checkout overlay from Paddle’s own servers. Any cookies set during checkout are set by Paddle and governed by Paddle’s privacy policy.
4.3 Email signup (release notes)
If you enter your email address into the “Subscribe to release notes” form on the changelog page, we store your email in a Resend audience. You will receive an email when we ship a notable release. There are no marketing campaigns, no upsells, and no third-party data sharing. Each email contains an unsubscribe link, and you can also email us to be removed.
5. Where data is stored
| Data | Stored where |
|---|---|
| License key (on your device) | Locally on your Mac |
| License records, Pro device records, Free-tier device records | Google Cloud (United States) |
| Usage analytics events | PostHog (US cloud) |
| Order history | Paddle |
| Crash reports | Sentry |
| Email subscriber list | Resend |
| Website analytics | PostHog (US cloud) and Cloudflare |
We use Google Cloud and the other named providers as data processors. Each maintains its own security and privacy practices; we have selected providers that we consider responsible operators of the data they handle.
6. How we use your data
We use the data described above only to:
- Deliver and recover your license key
- Verify your Pro entitlement
- Notify you about your purchase, refund, or update window expiration
- Diagnose crashes (only if you have crash reporting enabled)
- Understand the device-count distribution across active licenses
- Understand the hardware and software environments the app runs on, so we can prioritize what to support and improve
- Understand which features get used, where users get stuck, and what to build next (only if you have usage analytics enabled)
- Produce anonymous aggregate summary metrics about the install base (e.g. “users have scanned X TB of files”)
- Comply with tax law
We do not:
- Sell your data, ever
- Share your data with advertisers, brokers, or marketing services
- Use your data to train machine-learning models
- Profile you for behavioral targeting
- Combine your data with third-party data sets
7. Legal bases, legitimate interests, and transfer safeguards
If you are in the EEA or UK, we rely on the following legal bases for the processing described in this policy:
| Activity | Data involved | Legal basis |
|---|---|---|
| Selling the app and delivering the license | Email address, country, order ID, customer ID, license key | Performance of a contract |
| Activating Pro and enforcing the update window | License key, machine hash, app version, bucketed hardware metadata | Performance of a contract |
| Daily license status check-ins | Machine hash, app version, bucketed hardware metadata | Performance of a contract and our legitimate interests in preventing license abuse, honoring refunds, and confirming version eligibility |
| Anonymous Free-tier device pings | Machine hash, app version, bucketed hardware metadata | Our legitimate interests in understanding the size of the user base and the hardware mix we need to support |
| Usage analytics events | Anonymous event names + small counts/buckets; device-bound or email-bound depending on whether the device has activated Pro | Our legitimate interests in product improvement, balanced against your easy opt-out via Settings → Privacy → Usage analytics |
| Purchase, refund, and support emails | Email address, order/license records, the contents of your support message | Performance of a contract and our legitimate interests in customer support and account administration |
| Crash reports | Stack trace, OS version, app version, short anonymous device identifier; for OS-level crashes, a memory-snapshot crash dump that may incidentally contain limited technical data such as file paths (§2.5) | Your consent, which you can withdraw at any time by turning off Settings → Privacy → Crash Reports; pending dumps are deleted unsent when it is off |
| Release-notes emails | Email address | Your consent, which you can withdraw at any time using the unsubscribe link or by emailing us |
| Tax, accounting, and anti-fraud records | Country, order ID, customer ID, refund records | Compliance with legal obligations and our legitimate interests in keeping accurate business records and preventing abuse |
Our legitimate interests are narrow: preventing license abuse, keeping a minimal device registry so one license is not used by unrelated people, diagnosing service issues, understanding which features matter to users so we can prioritize the roadmap, maintaining basic business records, and communicating with customers about purchases, refunds, and update eligibility.
Data required for the contract: your purchase email address, license key, machine hash, and app version are required for us to sell, activate, and support the Pro license and any 12-month update extension you choose to buy. If you do not provide them, you can still use the free tier but we cannot activate or administer Pro. Crash reports, usage analytics, and release-notes emails are optional.
Paddle acts as a separate controller for checkout, billing, tax handling, and payment-related fraud prevention. We receive limited purchase data from Paddle so we can deliver and support your license. For our own systems, we use Google Cloud, PostHog, Sentry, Resend, and Cloudflare as processors or service providers.
If you are in the EEA or UK, your personal data may be transferred to the United States. For transfers by our processors, we rely on Standard Contractual Clauses or equivalent lawful transfer mechanisms. You can request information about the safeguards relevant to your data by emailing hello@supadupa.tech.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, this section applies to you.
8.1 Categories of personal information we collect
In the preceding 12 months, we have collected the following categories of personal information:
- Identifiers: email address, license key, order ID, customer ID, and hashed device identifier
- Commercial information: purchase, refund, and update-extension purchase records
- Internet or other electronic network activity information: app version, bucketed hardware metadata, license check-in events, crash-report metadata if crash reporting is enabled, usage-analytics events if usage analytics is enabled, and aggregate website analytics
- Customer support information: the contents of support emails you send us and related correspondence
We collect this information directly from you, from your app when it activates or checks in, from Paddle in connection with your purchase, and from service providers that process data on our behalf.
8.2 Business and commercial purposes
We use this information only for the narrow purposes described in this policy, including to:
- Deliver and recover your license key
- Activate Pro features and administer your update window
- Detect refunds and version eligibility
- Maintain a minimal device registry to prevent license abuse
- Provide customer support
- Diagnose crashes if crash reporting is enabled
- Maintain tax, accounting, and fraud-prevention records
- Measure aggregate website traffic without cross-site behavioral tracking
Retention periods are described in §9 Data retention.
8.3 Sales, sharing, and sensitive personal information
We do not sell personal information.
We do not share personal information for cross-context behavioral advertising.
We do not knowingly collect or use Sensitive Personal Information as defined by California law, and we do not use or disclose sensitive personal information for purposes that would trigger a right to limit its use.
8.4 Your California rights
Subject to applicable law, California residents may have the right to:
- Know the categories of personal information we collected, used, disclosed, and retained about you
- Request access to the specific pieces of personal information we collected about you
- Request deletion of personal information we collected from you
- Request correction of inaccurate personal information we maintain about you
- Opt out of the sale or sharing of personal information
- Limit the use and disclosure of sensitive personal information
- Receive equal service and pricing even if you exercise your privacy rights
- Use an authorized agent to make a request on your behalf
Because we do not sell or share personal information and do not use sensitive personal information in a way that triggers a limitation right, there is currently nothing for us to opt you out of on those points. You may still contact us if you have questions.
8.5 How to submit a verifiable consumer request
Email hello@supadupa.tech from the email address associated with your license or purchase.
To verify your request, we will:
- Match the sender address against the email address associated with the license or purchase record, and
- Send a confirmation step to that same email address before acting on the request
If we cannot verify that you are the person associated with the record, we may ask for limited additional information or deny the request.
Authorized agents may submit requests by emailing hello@supadupa.tech with proof of their authority to act for you. We may still require you to verify your identity directly with us.
8.6 Non-discrimination
We will not discriminate against you for exercising any privacy rights available to you under California law.
9. Data retention
| Record | Retention |
|---|---|
| License records | Indefinite while the license is active; archived 24 months after refund or expiration |
| Pro device records | Updated rolling; pruned 24 months after last seen |
| Free-tier device records | Updated rolling; pruned 24 months after last seen |
| Usage-analytics events | Up to 7 years (PostHog default); we may shorten this in a future revision |
| Email subscriber records | Until you unsubscribe |
| Crash reports | 90 days (Sentry default) |
| Order records (Paddle) | As required by tax law in your jurisdiction (typically 7 years) |
| Website analytics events (PostHog) | Up to 7 years (PostHog default), the same as usage-analytics events |
| Website analytics (Cloudflare) | Aggregate figures only, kept under Cloudflare’s own retention policy |
You can request earlier deletion at any time using the contact details below.
10. Your rights
Depending on where you live, you may have rights under the GDPR (EEA/UK), the CCPA/CPRA (California), or other privacy laws. These can include:
- The right to access the data we hold about you
- The right to correct inaccurate data
- The right to delete your data (“right to be forgotten”)
- The right to export your data in a portable format
- The right to object to or restrict processing
- The right to lodge a complaint with your data protection authority
To exercise any of these rights, email us at hello@supadupa.tech. We will respond within 30 days.
For the data Paddle holds about you (payment and billing records), you should contact Paddle directly via their privacy policy.
11. International transfers
We are based in the United States and use US-based data processors (Google Cloud, PostHog, Sentry, Resend, Cloudflare). If you are in the EEA or UK, your personal data is transferred to the US under the data processors’ Standard Contractual Clauses or equivalent safeguards.
12. Security
We protect your data with reasonable technical and organizational measures:
- Data is encrypted in transit between the app, the website, and our services
- Signing keys and service credentials are kept in a managed secrets service with restricted access, and are never logged
- Payment notifications from Paddle are verified before we act on them
- License keys are digitally signed and verified on your device
- Device identifiers are hashed on your Mac before they are sent
No system is perfectly secure, but we work to minimize what we collect so that the impact of any breach would be small.
If a security incident affecting personal data occurs, we will notify affected individuals and any required regulators in accordance with applicable law. Breach-notification duties generally follow where the affected person lives, so more than one jurisdiction’s rules can apply to a single incident. As a Maryland entity we are subject to the Maryland Personal Information Protection Act (Md. Code, Com. Law § 14-3504), which requires us to investigate promptly and in good faith, to notify affected individuals unless that investigation reasonably concludes that misuse is not likely, and to notify the Maryland Office of the Attorney General before notifying those individuals. Where another jurisdiction imposes stricter timelines or content requirements (for example GDPR Article 33’s 72-hour controller-to-supervisory-authority window), we follow the stricter standard.
13. Children
SupaDupa is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. When we do, we will:
- Update the “Last updated” date at the top of this page
- For material changes that affect how we collect or use your data, post a note in the next app release’s changelog and email registered customers
15. Contact
Email: hello@supadupa.tech
Carrington Creative Studios LLC c/o Northwest Registered Agent Service, Inc. 306 W Redwood St Baltimore, MD 21201 United States