Your privacy
Privacy Policy
Before you publish: every {{LIKE_THIS}}
marker below is a detail only you can supply — your legal entity, address,
jurisdiction and contact addresses. See
drivepurge.com/legal/README.md for the full checklist. These
documents are a starting draft prepared to reflect how DrivePurge actually
works; they are not legal advice, and a lawyer qualified in your
jurisdiction should review them before you sell to the public.
The short version. The DrivePurge app does its scanning entirely on your Mac. It never uploads your file names, folder structure or file contents — not to us, not to anyone. The only time the app talks to a server is when you activate a licence, and all it sends then is your licence key, a one-way fingerprint of the Mac, and a device name so you can tell your machines apart. This website sets no cookies and runs no analytics.
1. Who is responsible for your data
The controller for the personal data described in this policy is {{LEGAL_ENTITY_NAME}}, {{LEGAL_FORM}}, registered at {{REGISTERED_ADDRESS}}, company number {{COMPANY_NUMBER}} (“we”, “us”). You can reach us at {{PRIVACY_EMAIL}}.
We have not appointed a Data Protection Officer, because we are not required to under Article 37 GDPR. Privacy questions go to the address above and are answered by a person, not a ticket queue.
2. What the app does on your Mac
DrivePurge measures how much space each folder on your disk uses and draws that as a map. All of that work happens locally, in memory, on your computer:
- File names, folder paths, file contents and scan results are never transmitted anywhere. They are not written to any server, ours or otherwise.
- There is no analytics SDK, no telemetry, no crash reporting and no advertising identifier in the app.
- Deleting means moving to your Mac's Trash. We never see what you removed.
- Aside from licence activation, the app works with the network switched off.
3. What we collect, and why
When you buy a licence
Payments are handled by Dodo Payments, which acts as the merchant of record — meaning Dodo, not us, is the seller on the transaction and is responsible for collecting and remitting VAT and sales tax. Dodo processes your payment details as an independent controller under its own privacy policy; we never see or store your card number, bank details or full billing address.
From a completed order we receive and store: your email address, the name you gave at checkout, the order and payment identifiers, the product purchased, and the country used for tax purposes.
When you activate the app
- Licence key
- So we can confirm the licence is genuine and has not been revoked.
- Device fingerprint
- Your Mac's hardware identifier is combined with a secret value and put through a one-way hash before it leaves your computer. We store only the resulting hash. It lets us count how many Macs a licence is used on, and it cannot be reversed to identify your hardware.
- Device name
- The name your Mac already advertises on your local network, so that you can recognise your own machines in a list and release one when you replace it.
- IP address and timestamps
- Recorded with the activation request to detect and block licence-sharing and brute-force attempts. IP addresses are stored hashed, not in the clear.
When you email us
We keep your message and address so we can reply and so we have a record of what was agreed if you later come back about the same issue.
When you visit this website
This site sets no cookies and runs no analytics. It is served by Cloudflare, which processes connection data — including your IP address — to deliver the page and to protect the site from attack. Fonts are loaded from Google Fonts, which receives your IP address as part of that request; if you would rather it did not, a content blocker will stop it without breaking the page.
4. Our legal grounds for using it
| What | Why | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Licence key, device hash, device name | Delivering the licence you bought and honouring the three-Mac limit | Performance of a contract — Art. 6(1)(b) |
| Email, name, order details | Sending your key, providing support, handling refunds | Performance of a contract — Art. 6(1)(b) |
| Hashed IP, activation timestamps | Preventing licence abuse and securing the service | Legitimate interests — Art. 6(1)(f) |
| Order and tax records | Meeting accounting and tax obligations | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have weighed them against your rights and concluded that keeping a paid licence from being shared across hundreds of machines is a limited, expected use that a customer would not find surprising. You can object to it at any time — see section 8.
5. Who else processes it
| Provider | Role | What it handles |
|---|---|---|
| Dodo Payments {{DODO_LEGAL_ENTITY}} | Merchant of record; independent controller | Payment, invoicing, tax, licence key delivery |
| Cloudflare, Inc. (USA) | Processor | Website hosting, the licence API, and the licence database |
| {{EMAIL_PROVIDER}} | Processor | Support correspondence |
We do not sell personal data, share it for advertising, or hand it to data brokers. We will disclose data to a public authority only where we are legally compelled to, and we will tell you unless the law forbids it.
6. Where your data goes
Our licence database runs on Cloudflare infrastructure and may be processed in the United States. Transfers outside the EEA and the UK are covered by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, which form part of our agreement with Cloudflare.
7. How long we keep it
| Data | Kept for |
|---|---|
| Licence and activation records | As long as the licence is valid, then 24 months |
| Order and tax records | {{TAX_RETENTION_YEARS}} years, as required by law |
| Hashed IPs and activation logs | 12 months |
| Support correspondence | 24 months after the conversation ends |
8. Your rights
If you are in the EEA or the UK, the GDPR gives you the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, where we have no overriding reason to keep it;
- restrict how we use it while a dispute is resolved;
- receive it in a portable, machine-readable form;
- object to processing we base on legitimate interests; and
- withdraw consent, where we relied on it, without affecting what came before.
Write to {{PRIVACY_EMAIL}} and we will respond within one month. There is no charge. We do not use your data for automated decision-making or profiling.
If you think we have got this wrong, you can complain to your local data protection authority — for us that is {{SUPERVISORY_AUTHORITY}} — but we would appreciate the chance to put it right first.
9. If you are in California
In the twelve months before this policy was published we collected the following categories of personal information under the CCPA/CPRA: identifiers (email address, name, hashed device fingerprint, hashed IP address) and commercial information (your purchase). We collected it to deliver and support the product, and we retain it as set out in section 7.
We have not sold or shared personal information, and we do not process sensitive personal information for the purpose of inferring characteristics. We do not knowingly collect data from anyone under 16.
You have the right to know, delete, correct and opt out, and not to be discriminated against for exercising those rights. Send the request to {{PRIVACY_EMAIL}}; we will verify it by replying to the email address on your order.
10. Children
DrivePurge is not directed at children and we do not knowingly collect their data. If you believe a child has given us personal data, tell us and we will delete it.
11. Changes
When this policy changes we update the date at the top of the page. If a change materially affects how we use your data, we will email licence holders before it takes effect.