Dirnex

法的情報のページは英語のみです。

Privacy Policy

Last updated

This policy explains what personal data the Dirnex app and the website dirnex.app handle, why, and for how long. In short:

  • Dirnex has no account, no analytics and no ads. On its own, it goes online only to check for updates.
  • The website doesn’t track you, and sets no cookies but one, when you sign in to see your licenses. It counts visits and downloads without knowing who you are.
  • A bug report is sent only when you press Send, and you see exactly what it contains first.
  • When you buy a license, Paddle handles the payment. We never see your card.
  • We never sell your data or use it for advertising.

Who is responsible

Oleh Verkhohliad is responsible for your data (the “controller”). “We” and “us” in this policy mean him. Write to support@dirnex.app with any question or request about your data.

The website

No tracking, and one cookie only when you sign in. dirnex.app stores nothing in your browser and shows no ads. It sets no cookies, except the one that keeps you signed in on Your licenses (see “Your licenses page” below), and only once you sign in there. It loads no fonts or scripts from other sites: they come from dirnex.app itself, including Vercel’s counting script below. The one exception is Paddle’s checkout, which loads only when you press a Buy or Renew button (see “Buying a license” below).

Counting visits. To learn which pages help people and where visitors come from, the site counts visits with Vercel Web Analytics, which counts without cookies and is run by Vercel, the site’s host. When you open a page, your browser tells Vercel, through dirnex.app’s own address:

  • the address of the page, without anything after a “?” or a “#”, except the tags of a campaign link, such as utm_source;
  • the address of the site that sent you there, as your browser gives it, which is usually only the site’s name, such as reddit.com;
  • if you came through a campaign link, its source and campaign, once.

Vercel also receives your IP address and your browser’s name and version, as every web server does. It uses them only to tell roughly where you are (your country, region or city) and what kind of device and browser you use, and to count you once a day: it recognizes a visitor by a code made from the request, and throws that code away after 24 hours, so the next day you are a new visitor. It doesn’t keep your IP address with what it counts, can’t recognize you on another day or on another site, and we see only totals. If your browser blocks Vercel’s counting script, your visits aren’t counted.

Hosting. The site is hosted by Vercel. Like every web server, Vercel’s servers receive your IP address, your browser’s name and version, and the address of the page you ask for. Vercel uses this data to deliver the page and to protect the site from attacks, and keeps its logs only for a short time. See Vercel’s privacy policy.

Downloads. The Download button sends your browser to GitHub, which hosts the Dirnex app’s files. GitHub receives your request like any website does. See GitHub’s privacy statement. On the way, our server tells Vercel Web Analytics that a download happened, with the address of the page you came from (without anything after a “?” or a “#”), your IP address and your browser’s name, so a download is counted like a visit, in the same way. A browser that blocks Vercel’s counting script doesn’t stop this count.

The app

No tracking. Dirnex has no analytics and no account, and it sends no data about how you use it. It works with your files on your Mac, including with Full Disk Access when you grant it, and never sends us their names or contents. Files go only where you send them, such as a server you copy them to.

Update checks. Dirnex checks for a new version when it starts and every eight hours while it runs, by reading a list of releases from GitHub. GitHub receives your IP address and the version of Dirnex you use. Updates are downloaded from GitHub too.

Servers and clouds you connect to. When you connect Dirnex to a server or a cloud storage service, it connects directly from your Mac. Passwords are kept in your Mac’s Keychain. We never see these connections or your passwords.

Your license. A license key contains the name or email address it was issued to, its dates and a random ID. Dirnex checks the key on your Mac and never sends it anywhere. When you click Renew in Dirnex, the website address it opens includes the license’s random ID, but never your name or email address.

The activation link in a license email leads to a page that reads the key in your browser. The key is placed after a “#” in the address, so it never reaches our server.

Bug reports

Help ▸ Report a Bug in Dirnex sends a report only when you press Send, and shows you exactly what it will send beforehand. A report contains:

  • what you write: the description, and the steps and the email address if you give them;
  • the details you leave ticked: the versions of Dirnex and macOS, the Mac model, the language of Dirnex, and whether a license is present (never the key itself);
  • a crash report, only if you tick it. Dirnex removes the IDs that identify your Mac from it and shortens the path of your home folder to “~”.

The report is sent to our server and kept, with the time it arrived, in our database in Frankfurt, Germany. We get a short notification through Telegram that a new report has arrived; the notification doesn’t contain the report. Your IP address is used only to limit how many reports can be sent from one address in an hour: our server counts it in its memory and never writes it down, with the report or anywhere else.

We use a report only to find and fix the problem, and to answer you if you gave an email address. Reports are deleted after 12 months, or sooner if you ask, and our encrypted backups keep them at most 12 months longer (see “Backups” below). Deleting your data on Your licenses also deletes the reports that gave your email address.

If you choose Email Instead, the report goes by email from your own mail app, as described below.

A license we give you

When we give someone a license, for testing Dirnex, for a review or as a prize, we keep the name or email address it is licensed to, the email address we send it to, and a short note on why we gave it. We send it by email through Resend and keep it in our database in Frankfurt, Germany, for as long as the license exists, like a license you buy (below). If we sent it to your email address, you can delete it yourself on Your licenses; either way, you can ask us to delete it at any time.

Buying a license

The store opens soon. From then on, this is what happens when you buy a license.

Paddle. Licenses are sold by Paddle.com, our reseller and the Merchant of Record for every order. Paddle collects your payment details and billing information, and handles payment, tax and refunds under its own privacy policy. We never see your card number or bank details.

The checkout. When you press a Buy or Renew button, the page first asks our server whether the store is open, then loads Paddle’s checkout script and its styles from Paddle’s servers, so Paddle receives your IP address and your browser’s name and version, as any website does. The checkout then opens in a window over the page. That window is Paddle’s: what you type in it goes to Paddle, and any cookie it uses is Paddle’s, under Paddle’s policy. The page tells Paddle the language you read the site in and, for a renewal, your license’s random ID, which come back to us with the order. Until you press the button, nothing reaches Paddle.

What we keep from Paddle: your email address, your name if Paddle has it, your country, and what you bought, when, and for how much. If you buy for a company, also its name. Paddle’s notice of an order also tells our server the rest of what you gave Paddle, such as a tax number or a postal code, and your card’s type, last four digits and holder’s name. We don’t keep any of that.

What we do with it:

  • create your license and put your name or email address in it, as the name it is licensed to (for a team, the company’s name and the seat’s number);
  • send you the license, and the sign-in links for your licenses page, by email;
  • renew your license, and help you when you write to us;
  • keep the records that tax law requires.

Where it is kept. In our database in Frankfurt, Germany. Emails are sent through Resend, an email delivery service.

How long. We keep your customer and license records for as long as your license exists, because a license keeps covering its versions forever and you may need the key again. You can delete them yourself at any time on Your licenses, or ask us to. After that, your key keeps working in Dirnex, but we can no longer send it to you or renew it. Records of orders are kept for as long as tax law requires: once you delete your data, without your name, email address or company, only what was bought, when, for how much, in which country, and Paddle’s number for the order.

Your licenses page

On Your licenses, you see your licenses and their keys again, after signing in with a link we email you. We send that link only to an address a license was sent to, including a license we gave you, and the page answers the same whatever address you type. The link works once, for 15 minutes. We keep a record of each link we send (the address and the time) for about a day, to limit how many links one address can get.

Signing in sets one cookie, which keeps you signed in on that browser for 7 days, or until you sign out. It holds a random code. We keep only a scrambled copy of that code (a hash) with your email address, for as long as you stay signed in. The cookie is needed for the page to work and is never used for tracking.

On that page you can also:

  • change the name a license is for, the name Dirnex shows. The license then gets a new key with the new name; the old key keeps working. We keep only the new name.
  • delete your data (Delete My Data). It deletes, at once, your email address, your name, your licenses, your sign-in links and sessions, and the bug reports that gave your email address, and our encrypted backups keep them at most 12 months longer (see “Backups” below). Orders stay in our records without your name, email address or company, as described under “How long” above. We get an email saying that it happened and for which address, so that we can also delete any emails you wrote to us. Paddle keeps its own records of your purchases, under its own privacy policy.

Backups

Every night we copy our database, encrypted, to backup storage of our own. Without a key that only we hold, the copies can’t be read. We keep the copies of the last 30 days and one of each of the last 12 months, and delete older ones, so data deleted from the database stays in the copies for at most 12 more months. Sign-in links and sessions are never copied. We use the copies only to bring the database back after a failure, and once a week we check, inside the backup storage, that the newest one can be restored.

Email

When you write to support@dirnex.app, we receive your email address and your message. Cloudflare receives the mail for dirnex.app and forwards it to a Gmail mailbox, so Cloudflare and Google handle it too. Our answers are sent from that mailbox through Resend, so Resend handles them too. We keep the conversation for as long as we need it to help you.

Who else handles your data

We use these services to run Dirnex and the store. Each one handles data only for the purpose described above:

  • Vercel: hosting the website and our server, and counting visits and downloads;
  • GitHub: hosting the app’s files and its list of releases;
  • Neon: our database, in Frankfurt, Germany;
  • Paddle: selling licenses, as described above;
  • Resend: sending license and sign-in emails, and our answers to your emails;
  • Cloudflare: receiving email for dirnex.app and forwarding it to our support mailbox;
  • Google (Gmail): our support mailbox;
  • Telegram: notifications to us about new bug reports, without their contents, and about problems on our server, without any personal data.

We don’t sell or rent personal data, and we don’t share it with anyone else unless the law requires us to.

Where your data is processed

We work from outside the European Union. Our database and our server code run in the European Union, in Frankfurt. The encrypted backups of our database are kept on our own storage, outside the European Union. Some of the services above are based in the United States or the United Kingdom, so your data may be processed there. These companies protect it with the safeguards the law requires, such as the European Union’s standard contractual clauses.

Why we may use it

If you are in the European Union or the United Kingdom, these are the legal reasons for each use:

  • A contract with you: creating, sending and renewing your license, and your licenses page.
  • A legal obligation: keeping records of orders for tax law.
  • Your request: a bug report you send, and an email you write to us.
  • Our legitimate interest: running the website securely, counting visits and downloads, update checks, and answering your questions.

Your rights

You can ask us to show you the data we have about you, to correct it, to delete it, to limit how we use it, or to send it to you in a common file format. You can also object to how we use it. Write to support@dirnex.app; we answer within 30 days. On Your licenses, you can see your licenses, change the name on them and delete your data yourself, at any time.

You also have the right to complain to the data protection authority of the country you live in.

Children

Dirnex and dirnex.app are not meant for children under 16, and we don’t knowingly collect their data.

Changes to this policy

When the way we handle data changes, we update this policy and the date at the top.