Privacy Policy
Last updated: October 3, 2026 · Effective date: October 3, 2026
This Privacy Policy (“Policy”) describes how Heylel Labs, a sole proprietorship operated by Martin Pacheco (“DockDuck”, “we”, “us”, or “our”), collects, uses, discloses, and protects personal data in connection with the DockDuck desktop application for macOS (the “App”), the website at https://dockduck.app and its subdomains (the “Sites”), DockDuck Share (“Share”), and related services (together, the “Services”).
We are the data controller for the personal data described in this Policy, except where the data is processed by our Merchant of Record (see Section 5), which acts as a separate controller and/or processor for payment and tax purposes, and except for personal data inside files that a sender transmits with Share, for which the sender is the controller and we act as a processor (see Section 6).
By using the Services, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Services.
1. Privacy-by-design summary
DockDuck is engineered to operate locally on your device.
The App does not upload, transmit, scan off-device, index in the cloud, or otherwise send the contents, names, paths, or metadata of your files and folders to us or any third party, with one exception that you control: a file you choose to send as a link with DockDuck Share. All other file management occurs locally on your Mac.
Share is the only feature that sends a file off your Mac, and only when you ask it to. The App encrypts the file on your Mac before it uploads it, so we store it without being able to read it. Section 6 explains exactly what we can and cannot see.
When you connect to a server (SFTP, SMB, FTP, or WebDAV), your login is stored only in the macOS Keychain on your device and is sent directly to that server; we never receive it. DockDuck also never asks for or stores your third-party cloud account sign-ins (such as Google Drive, OneDrive, or Box): those services are reached only through the folders their own official apps create on your Mac, so your cloud login stays entirely with that app.
You can try the App without an account. The free trial is tied to your Mac through an anonymous device identifier, described in Section 4.
The limited personal data we do process is described in detail below.
2. Definitions
- “Personal data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on personal data (e.g. collection, storage, use, disclosure, deletion).
- “Controller”, “Processor”, “Data Subject”, “Sub-processor” have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the UK GDPR.
- “Merchant of Record” or “MoR” means the entity that sells the App to you as reseller and is responsible for billing and tax (see Section 5).
3. Personal data we do not collect
- The contents, file names, directory paths, thumbnails, or metadata of the files and folders on your Mac. The only files that reach us are the ones you send with Share, and those arrive encrypted (Section 6).
- Keystrokes, screen contents, or in-App navigation history.
- Location data, contacts, photos, or any other on-device personal content.
- Special categories of data under GDPR Art. 9 (we neither seek nor want it).
- Your third-party cloud logins or your server credentials. Server logins (SFTP, SMB, FTP, WebDAV) are stored only in your Mac’s Keychain and sent straight to the server you connect to; we never receive them. We never ask for or store your Google, Microsoft/OneDrive, Box, or other cloud-account sign-ins.
- Your hardware identifier. The device identifier we receive is derived from it with a one-way function and cannot be turned back into it.
4. Categories of personal data we process
| Category | Examples | Source | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|---|---|
| Trial data | Anonymous device identifier (a one-way hash), trial start date, date the App last contacted us, extension days | The App, when you start the free trial and when it later checks the trial | Run the free trial without an account; stop a trial from being restarted by reinstalling | Art. 6(1)(b) contract; 6(1)(f) legitimate interest (abuse prevention) | While we offer the trial, because deleting it would restart the trial. Deleted on request |
| Terms acceptance record | Version of the Terms you agreed to and when; for an account, also the App version, language, browser or App identifier, and a keyed hash of the IP address | The App, when you start the trial or accept the Terms | Keep evidence that the Terms were accepted | Art. 6(1)(f) legitimate interest (establishing and defending legal claims) | Life of the trial record or account, plus the applicable limitation period |
| Account data | Name, email, password hash (if you set one), preferred language, email-verification status, how the account was created | You, when you buy a license or register your email | Create and secure your account; deliver your license | Art. 6(1)(b) contract | Until you delete the account (Section 11) |
| Trial-extension email | Email address and a single-use verification link | You, if you choose to register your email for 7 more days | Verify the address and add the days; this creates an account | Art. 6(1)(b) contract | As account data; the link expires within hours |
| Order & identity data | Name, email, country, license key, order ID | Our MoR at purchase | Deliver, validate & support your license | Art. 6(1)(b) contract | Duration of license + statutory tax period |
| License-validation data | License key, anonymous device identifier, activation count | The App, at activation/validation | Verify license validity, manage device activations, prevent abuse | Art. 6(1)(b) contract; 6(1)(f) legitimate interest (anti-piracy) | Until license deactivation + short log window |
| Sessions & devices | The Macs and browsers signed in to your account: device name (for example “Anna’s MacBook Pro”), device identifier, IP address, browser or App identifier, last use | The App and the Sites, when you sign in | Keep you signed in; show and limit the Macs using a license; detect stolen sessions | Art. 6(1)(b) contract; 6(1)(f) legitimate interest (security) | Until the session ends or is revoked, plus a short period |
| App version data | App version, macOS version, CPU architecture | The App, when signed in | Support; know which versions are in use | Art. 6(1)(f) legitimate interest | With the account |
| Share data | See Section 6 | The App and the Share download page | Run Share, prevent abuse | See Section 6 | See Section 6 |
| Download data | IP address, browser type, App version requested, language, referring channel, time | The Sites, when the App is downloaded | Count downloads; tell real downloads from automated ones | Art. 6(1)(f) legitimate interest | IP address and browser type: 30 days. Counts: kept in aggregate |
| Update / connection data | IP address, App version, macOS version, CPU architecture, request timestamp | Automatic update checks (Sparkle to our CDN) | Serve the correct update; security; abuse prevention | Art. 6(1)(f) legitimate interest | Short-lived server logs (≤ 30 days) |
| Optional diagnostics | Crash reports, anonymized/aggregated feature-usage events | The App, only if you opt in (“Share Technical Data”) | Diagnose crashes; improve the App | Art. 6(1)(a) consent | Aggregated; raw reports ≤ 90 days |
| Support data | Email address, ticket and message contents, attachments and system info you provide | You, when you contact us or open a ticket | Provide support, respond to requests | Art. 6(1)(b)/(f) | Up to 24 months after resolution |
| Email preferences | Whether you unsubscribed from news and offers, and when | You | Respect your choice | Art. 6(1)(c) legal obligation | With the account |
| Content you post | Comments and reactions on release notes, shown with your account name | You | Run the public changelog discussion | Art. 6(1)(b) contract | Until you delete them or your account |
| Site & cookie data | IP, browser/device type, pages viewed, referrer | The Sites / analytics | Operate, secure, and measure the Sites | Art. 6(1)(f); 6(1)(a) for non-essential cookies | Per Section 11 |
Where we rely on consent, you may withdraw it at any time (e.g. by disabling diagnostics in Settings) without affecting prior processing.
5. Payments and the Merchant of Record
Purchases of DockDuck are sold and processed by our reseller and Merchant of Record, Sold through Link, LLC, formerly known as Lemon Squeezy LLC, 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA (“Lemon Squeezy”).
When you buy a license, Lemon Squeezy collects and processes your name, email, billing address/country, and payment-method details as a controller and/or processor for payment, fraud-prevention, invoicing, and tax purposes, and provides us with limited order data (name, email, country, order ID, license key). We never receive or store your full payment-card number.
Lemon Squeezy’s terms govern the payment relationship:
- Privacy Policy: https://www.lemonsqueezy.com/privacy
- Buyer Terms & Conditions: https://www.lemonsqueezy.com/buyer-terms
- Data Processing Agreement: https://www.lemonsqueezy.com/dpa
6. DockDuck Share
Share lets a license holder send a file as a link. It is the only feature that sends a file off your Mac. Part B of our Terms governs it; this section describes the data involved.
What we cannot see. Every link is end-to-end encrypted, with no option to turn that off. The App encrypts the file’s contents, its name, the note, and the preview image on your Mac before upload. The key is the part of the link after the ”#” sign, which browsers never send to a server. We store the encrypted file but cannot open, read, or scan it, and cannot recover a lost link. If someone gives us the full link, for example in a report, we can open that one file.
What we can see, and keep.
| Data | Why | Retention |
|---|---|---|
| The encrypted file and encrypted preview | Deliver it to the people you give the link to | Deleted when the link is revoked or removed, and in every case no later than 7 days after upload. We keep no backups of shared files |
| Link details: size, general kind of file (such as image or document), number of files, expiry, whether a password is set, download count, your account, and your account name if you choose to show it | Run the link, apply monthly allowances, prevent abuse | 60 days after the link expires |
| Password, if you set one | Access control | Stored only as a secure hash, with the link details |
| The sender’s IP address at the time of sending | Share is not offered in some countries; we work out the country on our own server with an offline database | Not stored for this purpose and not sent to any third party |
| Recipients’ IP addresses | Limit password guesses and repeated downloads | Kept only as keyed hashes in short-lived memory, for minutes to hours |
| Reports: the reason, any details, the reporter’s name and email if given, a keyed hash of the reporter’s IP address, and the link’s key if the reporter chooses to give it | Review reports and act on abuse | With the link details, or longer where the law requires us to preserve them |
| Enforcement records: strikes or a suspension on a sender’s account | Stop repeated abuse | With the account |
People who receive a link do not need an account. For them we process only what the table lists for recipients and reports. Recipients never see the sender’s email address.
Legal basis. Art. 6(1)(b) contract for senders; Art. 6(1)(f) legitimate interest (security and abuse prevention) for recipients and reports; Art. 6(1)(c) legal obligation where the law requires us to preserve or report.
Personal data inside the files you send. You decide what goes into a file and who receives it. For that data you are the controller and we act only as a processor that stores and transmits it on your instructions. Because the file is encrypted, we have no access to its contents. If you send personal data on behalf of an organization that needs a data-processing agreement, contact us first.
Legal requests. We disclose data about Share only as Part B of the Terms describes. We cannot disclose contents we cannot read.
7. Cookies and similar technologies (Sites)
The Sites use strictly necessary cookies required to operate and secure them, such as the one that keeps you signed in to your account. To measure traffic we use a cookieless, privacy-respecting analytics service that does not track you across sites. We do not use cross-site advertising trackers. You can control cookies via your browser settings and any cookie banner presented on the Sites.
8. How we use personal data
We process personal data to: (a) run the free trial and deliver, activate, and validate your license; (b) create and secure your account; (c) operate Share and keep it free of abuse; (d) provide updates and security fixes; (e) provide customer support; (f) diagnose crashes and improve the App (with consent); (g) operate, secure, and measure the Sites; (h) send service messages, and news about DockDuck where the law allows (see below); (i) keep evidence that our Terms were accepted; (j) comply with legal, tax, and accounting obligations; and (k) detect, prevent, and address fraud, abuse, and security incidents. We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.
Emails we send. Service messages about your account, purchases, security, and important changes are part of the Services. News about DockDuck, such as release announcements and offers, is sent to account holders where the law allows, on the basis of our legitimate interest or your consent where consent is required. Every such email has an unsubscribe link, and you can turn them off in your account settings.
9. Disclosure of personal data and sub-processors
We do not sell or rent personal data. We disclose limited data only to:
- Service providers / sub-processors acting on our behalf under
appropriate contractual safeguards:
- Sold through Link, LLC (Lemon Squeezy): payments, tax, invoicing (Merchant of Record).
- Amazon Web Services, Inc.: our database, and hosting of the update feed (S3 / CloudFront).
- Railway Corporation: hosting of our application servers.
- Vercel Inc.: hosting of the Sites, the account portal, and the Share download page; cookieless analytics.
- Cloudflare, Inc.: storage of the encrypted files sent with Share.
- Resend, Inc.: delivery of email.
- Functional Software, Inc. (Sentry): error monitoring of our servers and account portal, configured not to collect personal data by default.
- Legal / safety: where required by law, court order, or to protect our rights, users, or the public, including the cases Part B of the Terms describes for Share.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to this Policy.
A current list of sub-processors is available on request at the contact in Section 17.
10. International data transfers
We operate worldwide and our providers (listed in Section 9) are located in the United States and other countries. Where personal data of EEA, UK, or Swiss data subjects is transferred outside those areas, the transfer is protected by an appropriate safeguard under GDPR Chapter V, such as the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, and/or transfers to providers certified under the EU-U.S. Data Privacy Framework, where applicable.
11. Data retention and deleting your account
We retain personal data only as long as necessary for the purposes set out in Sections 4 and 6, after which it is deleted or anonymized. Order and tax records are retained for the period required by applicable tax and accounting law (commonly up to 7–10 years).
Deleting your account. You can delete your account from the account portal. Deletion is scheduled for 14 days later, so you can cancel it if it was a mistake; after that the account and the data tied to it are erased, except what the law requires us to keep, such as order and tax records. Links you sent stop working when the account is deleted.
The trial record. It holds no name or email. You can ask us to delete it at the contact in Section 17.
You may request earlier deletion of any data subject to our legal obligations (see Section 12).
12. Your rights (EEA / UK / Switzerland: GDPR)
Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing (including processing based on legitimate interests); data portability; and to withdraw consent at any time where processing is based on consent.
To exercise any right, email martin@dockduck.app. We will respond within one month (extendable by two months for complex requests, with notice). We may need to verify your identity. You also have the right to lodge a complaint with your local supervisory authority (e.g. your national Data Protection Authority).
For order/payment data held by Lemon Squeezy, you may also contact Lemon Squeezy directly.
13. Your rights (California: CCPA/CPRA)
In the last 12 months, we may have collected the categories of personal information described in Sections 4 and 6 (identifiers, commercial information, internet/network activity, and limited geolocation inferred from IP), collected from the sources and for the business purposes described above.
We do not “sell” and do not “share” personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, as amended (“CCPA/CPRA”). We do not process sensitive personal information for purposes requiring a right to limit.
California residents have the right to: know/access the categories and specific pieces of personal information collected; delete personal information; correct inaccurate information; and not be discriminated against for exercising these rights. You may exercise these rights, or use an authorized agent, by emailing martin@dockduck.app.
14. Other U.S. state privacy rights
Residents of states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas, and others) may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising or profiling. We honor these rights and do not engage in targeted advertising. Contact us at martin@dockduck.app.
15. Security
We implement reasonable technical and organizational measures appropriate to the risk, including transport encryption (HTTPS/TLS), end-to-end encryption of files sent with Share, storage of passwords and sign-in tokens only as hashes, keyed hashing of IP addresses where we keep them for abuse prevention, least-privilege access, and minimization of the data we collect. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your license key, your device, and the links you send secure: anyone with a full Share link can open it.
16. Children
The Services are intended for users 16 years and older and are not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will delete it.
17. Changes and contact
We may update this Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date and, where required, with additional notice. Your continued use of the Services after changes take effect constitutes acceptance.
Controller: Heylel Labs, Martin Pacheco Email: martin@dockduck.app