Skip to content

Privacy, briefly.

Version 1.0 · effective 21 August 2026
sha256 41294da2b26a0d1206a8d65c51339dfcbd1b0e74696e97f198e05d4480b055d4

The short version

This site runs no analytics, sets no cookies, embeds no third-party scripts and does no tracking of any kind. There is no JavaScript on it at all.

The only personal information collected is what you type into a form or give to a payment processor in order to buy something.

What is stored, and why

  • Your name and email address, because they are printed inside your license key and are how the license reaches you.
  • A record of each payment — processor, transaction reference, amount and date — which is the commercial ledger behind your license.
  • A one-way fingerprint of each license issued to you. The license key itself is never stored on this server, so a breach of it cannot yield a usable key.
  • A record that you agreed to the license agreement at checkout: which agreement, its version, effective date and SHA-256 hash, what you were buying, and when. Your IP address is not part of that record.
  • Anything you write in the support or recovery forms, for as long as it takes to answer you.

What is never stored

Card numbers never touch this server. Checkout happens entirely at Square or PayPal, and only the resulting transaction reference comes back.

The applications themselves do not phone home. Once a license key is on your Mac it is verified offline, forever, with no contact with this site.

How long it is kept

  • Purchase records, license fingerprints and their metadata, and agreement assent records: kept indefinitely — they are the license ledger, and they are what lets a lost key be re-issued years later.
  • Raw payment-processor notifications: 90 days.
  • Fulfillment logs: 180 days.
  • Mail delivery logs: 30 days.

Where it lives

Today it runs on hardware I own and operate. I may move it to a cloud tenant under my own control if that turns out to be better for reliability or security, and it may not be in your country. What matters is that the protections below travel with it either way.

The database is encrypted at rest, and backups are encrypted separately with a key that never exists on the server. Holding the disk is not the same as holding the data.

Payment processing is handled by Square and PayPal, and email delivery by Microsoft 365. Those are the only third parties involved, and each receives only what it needs to do its job.

Asking for a copy, or for deletion

Write to awake.support@flaming.ws and I will send you a copy of everything held about you.

I will also delete, on request, anything that is not part of the financial record of your purchase — your support messages, form submissions and any correspondence between us.

  • What I cannot delete on request is the record of the payment itself: the processor, the transaction reference, the amount, the date, the one-way fingerprint of the license issued against it, and the record of the agreement you accepted when you bought.
  • That record is kept because business and tax law requires records of sales to be retained for several years, because it is what I would need to answer a chargeback or a dispute, and — stated plainly rather than buried — because it is how repeated buy-then-refund cycles become visible.
  • It is also what makes it possible to re-issue your license years later if you lose it. Deleting it would end that.

Changes to this policy

I may update this policy at any time — because the store changes, because where it runs changes, or because the law does. The current version is always the one on this page, published with a version number, an effective date and a SHA-256 hash; earlier versions stay available.

If a change ever means collecting something I do not collect today, this page will say so before it starts.

Anything else

Questions, corrections, or anything that does not fit the above: awake.support@flaming.ws. A human reads it.