# Privacy Policy

**Effective date: September 15, 2026**

This policy explains what **MFSoft LLC** ("MFSoft," "we," "us") collects, why, and what we do with it — across the MFCommander application, the `mfsoft.dev` website, and our licensing service.

MFSoft LLC is the data controller for the processing described here. Contact: <support@mfsoft.dev>.

---

## 1. The short version

**MFCommander never sends us your files.** Not their contents, not their names, not their paths, not directory listings, not the contents of any remote server, bucket, container, or cluster you browse. Not your credentials. Not ever. There is no third-party analytics SDK. The application sends privacy-minimized usage statistics that are on by default and can be switched off in Settings.

**The application does talk to us in three narrow, disclosable cases**, all described in full below:

1. **License validation** — periodically, so that refunded or fraudulent licenses can be shut off. Sends a license ID and a key fingerprint. Nothing else.
2. **Usage statistics** — a small daily summary of application and feature use. It is on by default and has a permanent off switch. It never includes files, paths, connection details, credentials, license keys, license IDs, customer details, or free text.
3. **Update checks** — if you leave them enabled. Sends an application version and platform. Nothing else.

All three can be understood completely from Sections 3, 4, and 5. None carries files, file metadata, connection details, or credentials.

**The services you connect to are a separate matter, and we are not in the middle of them.** When you connect MFCommander to a server or a cloud account — including **Google Drive** — your Mac talks to that service directly. Section 6 describes that in full.

## 2. What the application stores on your device only

These never leave your Mac and are never transmitted to us:

- Your saved connections, hosts, buckets, clusters, and paths.
- Your **credentials** — passwords, keys, and tokens — stored in the macOS Keychain where the connector supports it.
- Your license key, saved preferences, hotkeys, tabs, and window state, except for the specific bucketed configuration counters listed in Section 4.
- Everything you view, copy, move, or edit.
- Your operation history, which records the names and locations involved in file operations, but never file contents.

Operation history stays on your Mac for the period you choose — **30 days by default** — and is excluded from Time Machine backups. You can clear it, or limit it to the current session, in Settings › General. It is never sent to MFSoft or counted in usage statistics.

## 3. License activation and periodic validation

**Activation is offline.** Your license key is a signed token verified on your Mac against a public key built into the application. Activating requires no account, no sign-up, and no network connection. We do not create an account for you.

**Validation is periodic and online.** Once a license is active, MFCommander checks in with our licensing service from time to time, so that licenses which were refunded, charged back, or revoked for fraud stop granting paid features.

| | |
|---|---|
| **What is sent** | Your **license ID**, and a **one-way SHA-256 fingerprint** of your license key. Your IP address is visible to our server, as it is to any server you connect to. |
| **What is *not* sent** | File names, contents, or paths · directory listings · connection, host, bucket, or cluster details · credentials · device identifiers, serial numbers, or hardware fingerprints · usage, feature, or telemetry data · your name or email address |
| **How often** | Periodically, in the background. Never blocking, never a dialog |
| **Purpose** | Enforcing the licence — detecting refunded, charged-back, or revoked entitlements (legitimate interests, GDPR Art. 6(1)(f); performance of contract, Art. 6(1)(b)) |
| **Response** | A signed statement of your license's status, cached locally so the answer survives being offline |

**We do not use this to count devices, track installs, or profile you.** The fingerprint is a one-way hash; we send it instead of the key itself so a check never puts your key back on the wire. Our server records only the timestamp of the most recent successful check against your license record.

**It never interrupts your work.** Validation runs in the background, and MFCommander remains usable offline. How licensing itself behaves is governed by the [EULA](https://mfsoft.dev/eula); this policy covers what the check transmits.

**Turning it off:** validation is part of how a paid license works and cannot be disabled separately. The Community edition does not use license validation at all.

Usage statistics are collected and stored separately, as described in Section 4. Nothing in that section changes what a validation check sends.

## 4. Usage statistics

**These are on by default, and you can switch them off.** MFCommander sends a small daily summary of how the application is used, so we can tell which features earn their place and whether people keep using the app after installing it. It is the only way we learn anything about the Community edition, which never contacts our licensing service.

**Turning it off:** Settings › Privacy › *Send privacy-minimized usage statistics*. Switching it off stops collection immediately and discards anything not yet sent. Switching it back on generates a **new** identifier, unconnected to the old one.

**Seeing exactly what is sent:** Settings › Privacy › *Show exactly what is sent* displays the literal contents of the next report before it leaves your Mac.

| | |
|---|---|
| **What is sent** | A random **installation identifier** · report-format and policy-version numbers · the **week usage statistics were first initialized** on your Mac · your **application version**, **macOS major version**, and **processor architecture** · your **edition** (Community, trial, Pro, or Infrastructure) and, during a trial, which day of it · the number of days the app was active in the reporting period · **counts of features used**, rounded into ranges rather than exact numbers. Your IP address is visible to our server, as it is to any server you connect to; we do not store it. |
| **What is *not* sent** | File names, contents, extensions, or paths · directory listings · anything you searched for · connection, host, bucket, cluster, container, or share names · credentials · your license key, license ID, name, or email · device identifiers, serial numbers, MAC addresses, or hardware fingerprints · window titles · free-form text of any kind · any timestamp more precise than the day |
| **How often** | At most **once a day**, as a single summary. Never per action |
| **Purpose** | Understanding which features are used and whether people keep using the application, so development effort goes where it helps (legitimate interests, GDPR Art. 6(1)(f)) |
| **Retention** | Raw reports are kept for **90 days** and then deleted automatically. Monthly aggregate totals that identify no installation are kept indefinitely |

**The identifier is random and connects to no customer record.** It is generated on your Mac, is not derived from your license, your hardware, or anything about you, and is never stored alongside your name, email, order, or license. The telemetry system has no field that joins a report to a customer.

**Counts are ranges, not exact figures.** A report says you opened between six and twenty files, not that you opened eleven. Exact numbers are more identifying than they look, and nothing we are trying to learn needs them.

**Your right to object.** Because we rely on legitimate interests rather than consent, you have the right under GDPR Article 21 to object to this processing at any time. The switch in Settings is how you exercise it, and it takes effect immediately — you do not need to contact us first. You can also email us to have reports already collected deleted.

## 5. Update checks

If update checks are enabled, MFCommander asks our update host whether a newer version exists. The request carries the **application version and platform** only.

It does **not** send your license key, license ID, entitlement status, email, device identifier, file names, connector metadata, or any application data. Disable it any time in Settings.

## 6. The services you connect to, including Google Drive

MFCommander is a file manager, so most of what it does is talk to somewhere your files already live — a local disk, an SMB or SFTP server, an FTP or NFS share, an S3 bucket, a Kubernetes cluster, a Docker host, OneDrive, iCloud Drive, or **Google Drive**.

**Every one of those connections runs directly between your Mac and that service.** MFSoft operates no proxy, relay, gateway, mirror, cache, or backup in any of these paths, and receives nothing from them. We could not read what you browse there even if we wanted to, because it never reaches us.

### Google Drive

Connecting Google Drive signs you in through **Google's own consent screen**, using OAuth. MFCommander never sees or stores your Google password. You can review or revoke MFCommander's access at any time at [myaccount.google.com/permissions](https://myaccount.google.com/permissions), which takes effect immediately and independently of anything in this application.

MFCommander requests the `https://www.googleapis.com/auth/drive` scope. A file manager's job is to show you the files you already have and act on the ones you choose, so it needs to see the Drive you are browsing — the same access Finder has to your disk. Google displays this request to you before you approve it.

| | |
|---|---|
| **How your Drive data is accessed** | Directly between your Mac and Google's servers over TLS, using the access token Google issued to your Mac. No MFSoft server is in this path |
| **How it is used** | Only to carry out what you asked for in the interface in front of you — listing a folder, viewing a file, searching within an open file, creating a folder, and the copy, move, and delete operations you invoke. Nothing else |
| **How it is stored** | Folder listings and viewed file content are held in **memory** for as long as you are looking at them, and the large-file viewer fetches only the portion on screen rather than downloading the file. Two exceptions put a copy on your Mac's disk, both of them things you asked for: previewing a document in the preview pane writes a temporary copy to your Mac's temporary folder — readable only by your account, deleted when you close the preview, and cleaned up at the next launch if the app was force-quit — and copying a file to a local pane writes it exactly where you chose. Neither leaves your Mac. MFCommander's operation history also stays on your Mac: it records the names and locations involved in file operations, never file contents, for the period you choose (30 days by default), and is excluded from Time Machine backups. You can clear it or limit it to the current session in Settings › General |
| **How it is shared** | It is not. Not with MFSoft, not with any third party. It is never sold, never used for advertising or any form of profiling, and never transferred anywhere except to the destination you pick for a file operation |
| **Whether a human reads it** | No one at MFSoft can. Your Drive content never reaches our systems, so there is nothing for a person here to read, and no support process that would involve looking at it |
| **What MFSoft receives** | Nothing. No file names, contents, metadata, or folder structure · no Drive or Google account address · no access or refresh token · no record that you connected Drive at all |

**Your Google sign-in stays on your Mac.** The access and refresh tokens Google issues are held in the same encrypted store as your other saved connection secrets, described in Section 2, protected by a key that lives in your login Keychain. Removing the connection in Settings › Connections deletes those tokens from your Mac.

**Limited Use.** MFCommander's use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including its **Limited Use** requirements.

### Other connections

The same principles apply to every other connector. Hosts, share names, bucket names, cluster and container names, paths, and the credentials for all of them stay on your Mac as described in Section 2. Application usage statistics (Section 4) never include any of them: they record that a connection type was used, never which server, account, or file.

## 7. What we collect when you buy

Purchases are processed by **Polar Software Inc.**, our Merchant of Record. **Polar takes your payment details directly — MFSoft never sees or stores your card number.** Polar acts as an independent controller for its own tax and payment compliance; see [Polar's privacy policy](https://polar.sh/legal/privacy).

Polar passes us what we need to issue and support your license, which we store in our licensing service:

| Data | Why |
|---|---|
| Name and email address | Issue the license, email you the key, handle support and recovery requests |
| Order ID and edition purchased | Match the order to the license, prevent duplicate issuance |
| License ID, issue date, updates-window end date | The entitlement itself |
| License status (active / refunded / charged back / revoked) and revocation date | Answer validation checks |
| Timestamp of the last validation check | Support and abuse investigation |

Your license key is emailed to you through our transactional email provider. We send mail about your license and purchase. We do not add you to a marketing list because you bought something.

## 8. What we collect on the website

**There is no signup form.** `mfsoft.dev` does not have a waitlist, a newsletter, or a mailing-list signup, and no page asks for your email address. The only place you give us an email address is license recovery, below.

**License recovery.** If you use the recovery form, your email address is sent to our licensing service to look up and re-send your keys. We do not store a separate record of the request on the website.

**Server logs.** Our web servers keep standard request logs, including IP addresses, for security and troubleshooting.

**Website analytics.** We measure page visits, download intent, checkout starts, and where visitors came from, using analytics software **we run ourselves on our own servers**. It records the page you viewed, the referrer and any campaign parameters, your browser, operating system, device type and screen size, a coarse location derived from your IP address, a pseudonymous visitor identifier that is re-salted daily, and the named actions you take. It sets **no cookies**. Session replay is off, and your raw IP address is not retained in the analytics record. These records are deleted after **90 days**.

We do not run third-party analytics, advertising, or session-recording scripts, and we set no advertising or tracking cookies. Because we host our analytics ourselves, **no analytics company receives your visit** at all.

## 9. Where your data goes

Our licensing service and usage-statistics endpoint run on cloud hosting infrastructure in the **United States**. Our website and its analytics run on servers we operate ourselves. Payments run through **Polar**. Transactional email runs through an email provider in the United States. All of them are engaged under data processing agreements.

If you are in the European Economic Area, the United Kingdom, or Switzerland, your data is transferred to the United States. Those transfers rely on the European Commission's **Standard Contractual Clauses** and the equivalent UK and Swiss mechanisms, incorporated into our agreements with those providers.

We share personal data only with these service providers, under contracts that require them to protect it — or where we are legally compelled to, or must to establish or defend a legal claim. **We do not sell personal data, and we do not share it for cross-context behavioral advertising**, as those terms are defined under California law.

## 10. How long we keep it

| | |
|---|---|
| Purchase and license records | For the life of the license, plus the period tax and accounting law requires us to keep transaction records (generally 7 years) |
| Raw application usage reports | 90 days |
| Monthly application-usage aggregates | Indefinitely; these contain no installation identifier |
| Raw mfsoft.dev website analytics records | 90 days |
| Web server logs | Up to 90 days |
| Support correspondence | Up to 3 years after the matter is closed |

## 11. Your rights

Wherever you live, you can email <support@mfsoft.dev> to **access, correct, delete, or receive a copy of** your personal data, or to object to or restrict how we use it.

If you are in the EEA, UK, or Switzerland, you have those rights under the GDPR or UK GDPR, plus the right to withdraw consent where a purpose relies on consent and the right to lodge a complaint with your national supervisory authority. For application usage statistics, which rely on legitimate interests rather than consent, you have the **right to object under GDPR Article 21**; switching off *Send privacy-minimized usage statistics* exercises that right immediately.

If you are in California, you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal data, so there is nothing to opt out of. **We will not discriminate against you for exercising any of these rights.**

We respond within 30 days. We may need to verify your identity first — usually by confirming you control the email address on the account.

## 12. Security

License keys are cryptographically signed and verified on your own Mac. Traffic between MFCommander and our services is encrypted in transit with TLS. Our signing keys are held in a managed secrets store, separate from the systems that serve requests. Credentials for the servers you connect to stay on your Mac in the macOS Keychain, and we could not retrieve them if we wanted to.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.

## 13. Children

MFCommander is developer tooling and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

## 14. Changes

We may update this policy. Material changes will be announced by an updated effective date at the top. Where a change affects what the application transmits, the release notes for the version that introduces it are our **primary disclosure channel**, not an optional courtesy. **We will not begin collecting a new category of data from the application without publishing the policy change and those release notes first.**

## 15. Contact

MFSoft LLC — <support@mfsoft.dev> — <https://mfsoft.dev>

---

Source: https://mfsoft.dev/privacy
