Privacy Policy

Last updated and effective: August 16, 2026

Hikage is a macOS activity recording and review app. Its core design principle is to process activity data on your device wherever possible and to transmit only the information necessary to provide online features that you enable, request, or continue to use.

This Privacy Policy explains what data Hikage processes, why it is processed, how it is stored, which third parties may receive it, and how you can manage or delete it. Please read this Policy before using Hikage.

1. Scope and Contact

This Policy applies to:

In this Policy, “we,” “us,” and “our” refer to the operator of Hikage. The contact channel for matters concerning the data processing described in this Policy is:

This Policy does not apply to third-party websites you access through Hikage, calendar providers you choose to connect, or other third-party services you use independently. Those services are governed by their own privacy policies. When you purchase through a Merchant of Record, that party also processes relevant transaction data independently under the privacy policy shown during checkout.

2. Our Privacy Principles

Hikage follows these principles:

  1. Local first. Activity records, statistics, reminder rules, and calendar candidates are generally stored on your Mac rather than uploaded to Hikage servers. Hikage writes immutable user-data copies to your selected iCloud storage or folder only after you back up manually or expressly enable automatic backup.
  2. Data minimization. Hikage processes only the data needed to provide the relevant feature. Hikage does not record typed content, media titles, authors, playback progress, window titles, or clipboard data. Hikage does not save full URLs, paths, query parameters, page titles, or page contents.
  3. Permission on demand. macOS permissions involving browsers, Accessibility, or Apple Calendar are requested only when you actively enable the relevant capability.
  4. Purpose limitation. Hikage does not use activity records for advertising profiles or cross-site behavioral advertising, and it does not sell such data.
  5. User control. You can stop recording, disable features, revoke system permissions, delete local data, or—where applicable law provides—request access to, correction of, or deletion of relevant server-side information that we control.

3. Data Processed Only on Your Device

3.1 Frontmost Apps and Device State

To produce usage time, daily statistics, monthly statistics, per-app statistics, and graph view, Hikage may record the following on your device:

By default, this data is written to a local SQLite database under your user directory.

3.2 Content-Free Input-Activity Timestamps

To determine whether you are still using the computer, Hikage may query how much time has passed since the most recent keyboard press or mouse-button press and may store the throttled activity timestamp locally together with the coarse source category “keyboard” or “mouse button.” Both categories share the same 15-second throttle, so distinguishing the source does not add event rows.

Hikage does not record specific keys, keyboard shortcuts, typed text, mouse coordinates, pointer movement, clicked objects, the target app, input-device brands, models, unique identifiers, or clipboard content. This feature does not create a global keyboard event monitor and does not require the macOS Input Monitoring permission.

3.3 Playback Activity Detection

While frontmost-app recording is running, Hikage automatically checks whether the frontmost app matches the system media session currently elected by macOS. Hikage uses only the session’s source hierarchy and playback rate for this in-memory match. It does not send an Apple Event to the target app or request Automation or another macOS privacy permission.

When the frontmost app clearly matches a playing system media session, Hikage records playback start, one continued-playback confirmation every 30 seconds, playback end, and their timestamps in the raw activity database for away detection. Each playback fact contains only its phase and timestamp; the app identity comes from the frontmost-app facts already recorded for the same period. Each start or confirmation allows derived playback activity to continue for at most 30 seconds. A pause, source mismatch, frontmost-app switch, system or display sleep, stopping recording, or unavailable detection capability ends the current playback state.

Hikage does not extract, transmit, or save media titles, authors, progress, page titles, full URLs, or page contents. System-media-session identifiers, source hierarchy, and playback rate are not written to the raw database or sent over the network; the source hierarchy and playback rate are used only for the current in-memory match.

3.4 Web Addresses in Browsers

After you actively enable browser web address recording for a supported browser, Hikage temporarily reads the current web address and immediately normalizes it in memory for statistics.

For browsers whose private windows can be identified reliably, Hikage skips private windows by default unless you expressly allow them to be recorded. System interfaces for browsers such as Safari and Firefox may not reliably distinguish standard windows from private windows. In those cases, the context is marked as “unknown,” and the current settings let you choose whether all unknown contexts should be skipped.

3.5 Statistics, Categories, Exclusions, and Reminders

Hikage stores or derives the following locally:

This information is used only for Hikage’s local features and is not uploaded as part of license activation, purchase confirmation, or software-update requests.

3.6 Calendar Integration

The presence of a calendar feature in the interface does not mean Hikage has obtained access to your calendars. Hikage requests the relevant permission only when you actively connect Apple Calendar, add or delete a calendar item, or choose to delete both a rule and its managed items. Preview, prefetch, and background checks do not initiate a permission request on their own.

When you enable calendar preview, the page displays only non-all-day events from the calendars you select in the current preview range. For display, identification, deduplication, update, or deletion, Hikage reads the required event and calendar metadata, including event titles and times, event and calendar identifiers, calendar and source names, colors, and Hikage management markers. Hikage does not read event notes, attendees, locations, or alerts, and it does not keep those fields or arbitrary event URL content in its local preview cache; it uses Event URLs only to recognize Hikage’s own management markers.

To improve display speed, Hikage may keep a limited, rebuildable cache of recent preview intervals in its local calendar-integration database. This cache may contain the metadata described above from calendars you selected previously and is pruned automatically to a capacity limit.

“Automatically add recently completed items” is off by default. After you expressly enable it, and only while Hikage already has full Calendar access, Hikage may check recently completed candidates in the background. For each candidate, Hikage reads the target calendar and the time interval needed for duplicate detection. To prevent duplicate creation and recover an unfinished Hikage write, it may also recognize Hikage’s own management marker within a limited interval around the candidate. Background processing does not request permission on its own or read an unlimited calendar history unrelated to processing that candidate; an eligible, non-duplicate candidate may be written to the target calendar according to your setting.

When you enable the relevant rule or action, Hikage may create Apple Calendar events managed by Hikage and write the activity name, start and end times, the number of actual active minutes if you choose to include it, and notes summarizing the activity and any periods of interruption. When a rule name or title-suffix setting changes, Hikage may update the title and Hikage management marker of those managed events while preserving other calendar fields you changed. By default, Hikage does not write raw browser web address events, input activity, bundle identifiers, attendees, locations, or alerts.

Unless you expressly perform a deletion or another action, Hikage does not modify calendar events unrelated to Hikage.

When you delete an external calendar event from Hikage, that action directly deletes the corresponding Apple Calendar event. If the target calendar is provided by iCloud, Google, Microsoft Exchange, or another service, the event may be synchronized to that provider’s servers according to the settings between you and the provider.

3.7 Website Language Suggestions

On the home, pricing, and changelog pages, the Hikage website may compare the current page language with the browser’s local navigator.languages preference list, falling back to navigator.language when the list is empty. This comparison occurs entirely in your browser. The language-suggestion feature does not make an additional network request to send or analyze the language list, current path, or suggested language, and it never changes the page language automatically.

Accepting a suggestion only opens the same page in the suggested supported language and does not save a preference. Closing the suggestion with its close button or the Escape key also does not save a preference. Only when you expressly choose to continue with the current language and stop future suggestions does the website store localStorage["hikage.languageSuggestion.declined.v1"] = "1". This value is only a Boolean refusal preference; it does not contain your language list, path, or suggested language. Clearing the site data for hikage.app removes the preference and allows eligible language suggestions to appear again.

4. Data Transmitted over the Network or Stored on Servers

Hikage does not upload its activity database or statistics merely because you use one of the network features below. Network requests ordinarily expose the requester’s IP address, request time, network protocol, and necessary request headers to the recipient.

4.1 Free Trials, License Activation, and Device Management

When you actively start a free trial, enter an activation code, refresh a license, view activated devices, or deactivate a device, Hikage sends the data needed to complete that operation to the licensing service. This data may include:

Hikage does not read or transmit the hardware serial number, hardware UUID, or another unique hardware serial identifier. An activation code is used only for the individual activation request, and the client does not retain the complete code in plaintext.

The licensing service may store license records, activated-device records, trial records, last-seen times, app and system versions, hardware models, device labels, public keys, device hashes, and license events needed for security auditing and abuse prevention. For each current or invalidated historical code generation, the service stores the complete activation code in an AES-256-GCM encrypted envelope, together with an irreversible keyed digest and a small number of trailing characters. The license database and its backups contain ciphertext rather than the plaintext code; the encryption keyring is managed separately. The complete code is decrypted only for purchase delivery, re-delivery of the current code, purchase or license support, and a single-generation administrative reveal. Administrative reveal requires a dedicated permission, and both successful and failed reveal attempts are audited. License events may include a keyed-hash representation of the IP address, the User-Agent, and necessary event information.

The licensing service may also store the association between an order and a license, together with order or transaction identifiers, the purchase email address, the supported Hikage website language in use when the purchase was completed, payment and refund status, and necessary notes received from a Merchant of Record. The recorded website language is one page locale, such as en or fr; it is not the browser’s language-preference list. This information is used to deliver or recover a license, send the complete purchase email first in English and then restate it in the purchaser’s website language, handle refunds or payment disputes, and prevent abuse.

4.2 Software Updates

Hikage uses Sparkle to check for and install software updates. When automatic checking is enabled, Hikage periodically accesses a public update feed. You can also choose “Check for Updates” manually.

An update request may include the installed Hikage version, update channel, interface language, and the IP address and request headers naturally generated by the network request. Hikage currently does not enable Sparkle’s system-profiling feature. Update requests do not send activity records, web address records, statistics, calendar data, reminder rules, activation codes, order information, or the device list.

4.3 Website Icon Retrieval

When Hikage prepares an icon for a website that you have saved for separate website statistics, it first accesses the public icon catalog at hikage.app over HTTPS. Every enabled website uses the same manifest URL, and this request does not include the current hostname, your browsing history, or a list of websites you have enabled. Hikage matches the normalized hostname locally on your Mac. If it finds a match, it may request the catalog’s content-addressed light and/or dark icon files.

The infrastructure hosting hikage.app may therefore receive your IP address, request time, the Hikage/1.0 User-Agent, and the requested manifest or icon path. Because the catalog’s icon IDs and hostname mappings are public, a request for a matched icon file may reveal which catalog entry—and therefore which associated website—was matched. The catalog does not receive your activity database, statistics, full URLs, or list of recorded websites.

If the catalog has no matching entry or is unavailable, Hikage may then access the target website or an allowed same-site subdomain to retrieve a favicon or another icon declared by the page. This fallback may run during background icon preparation, including after app launch, but it is limited to websites already saved for separate website statistics. Hikage does not derive fallback requests from raw browsing history, the current browser tab, or websites that you have not enabled. Hikage may also directly prepare the target website’s favicon when you explicitly open its “Change Icon” selector. A usable catalog match does not trigger the background fallback; the default YouTube entry contacts YouTube only if this fallback is needed.

The target website or its CDN may therefore receive your IP address, the request time, the requested icon path, and the Hikage/1.0 User-Agent. Any homepage HTML read while locating an icon is processed only in memory, and webpage content is not stored. Hikage limits redirect scope and response-body size.

Catalog requests and redirects are restricted to same-origin HTTPS, and downloaded catalog icons are checked against their published SHA-256 digest and image limits. The licensing and update services also use HTTPS. The protocol used for a direct target-website icon request depends on the protocol offered by that website; the current version may try HTTP if HTTPS retrieval fails. HTTP does not provide the same confidentiality in transit as HTTPS.

4.4 Visits to the Website and Checkout Components

The Hikage website is hosted by infrastructure providers. We currently do not intentionally deploy advertising SDKs, cross-site tracking, or third-party behavioral analytics. Hosting providers may nevertheless process IP addresses, request times, User-Agent strings, requested paths, response statuses, and similar technical logs to deliver webpages, prevent abuse, diagnose faults, and maintain security.

When a purchase page loads a checkout script, component, or hosted page supplied by a Merchant of Record, that party and its content-delivery, security, and payment partners may receive an IP address, request time, User-Agent string, device and browser information, language, referring page, and other technical information needed to provide checkout and prevent fraud. Checkout may use cookies or similar technologies necessary to complete the transaction, perform security checks, and prevent fraud. If non-essential analytics, marketing, or abandoned-checkout recovery features are enabled in the future, we will provide any additional notice and obtain consent where applicable law requires.

After a verified purchase is fulfilled, the Hikage purchase-completion page may use a short-lived receipt to retrieve and display the initial activation code, while the same code is also delivered by email. The page removes the receipt from the address bar immediately and may keep only the receipt and its expiration time in the current tab’s session storage. It does not place the activation code in URL parameters or browser storage; the code remains only in page memory and the displayed page, and is cleared when the page is hidden, the receipt expires, or the flow moves to support.

The website does not sell or share personal information for advertising purposes. Essential cookies or similar technologies set by infrastructure providers or a Merchant of Record depend on the specific service configuration and the provider’s own policies.

4.5 Purchases and the Merchant of Record

Paid Hikage products may be sold to you by the third-party Merchant of Record identified on the checkout page or order receipt. That party may act as the seller, payee, or authorized reseller for the transaction. The specific Merchant of Record, legal entity, and applicable policies will be identified during checkout, on the order receipt, or in the transaction confirmation.

During checkout, you ordinarily provide the Merchant of Record with, or allow it to process, information such as the following, depending on the checkout configuration and payment method:

In a standard checkout hosted directly by the Merchant of Record, Hikage generally does not receive or store a complete payment-card number, card security code, complete payment-account credentials, or an online-banking password unless the checkout page clearly states otherwise. Enter payment credentials only in the secure checkout interface supplied by the Merchant of Record.

To deliver and maintain a license, recover a purchase, provide support, handle a refund or payment dispute, prevent fraud, and comply with legal obligations, the Merchant of Record may provide us with necessary transaction data through a dashboard, API, webhook, order notice, or support communication. This data may include:

We use only the data actually received and necessary for these purposes. Purchasing Hikage does not cause us to receive or upload your local activity records.

To the extent that the Merchant of Record acts as the transaction seller, payee, tax processor, payment-risk decision-maker, or entity required by law to retain records, it ordinarily processes data independently for its own purposes and legal obligations under its own privacy policy. Hikage independently determines the processing needed to associate orders with licenses, deliver software, activate licenses, provide product support, and handle its own disputes. A privacy request made to us does not automatically delete or alter payment, tax, or compliance records independently controlled by the Merchant of Record, and the reverse is also true.

4.6 Support and Privacy Communications

The Hikage app and feedback page do not collect, upload, or store feedback. Choosing a feedback entry asks your operating system or browser to open its configured email handler with support@hikage.app and a category subject. A problem report also includes an editable body template. Hikage does not automatically read or attach screenshots, logs, activity records, license data, or other user content.

Only if you choose to send the draft through your email service do we receive the sender address, message content, attachments, and other information you choose to provide. We use this information as necessary to reply, handle a purchase, license, refund, technical-support or privacy request, and improve the product. The email provider you use processes the message under its own terms and privacy policy.

4.7 Backups and Viewing Data from Other Macs

Backups use a “separate recording on each Mac, immutable snapshots published to a shared location” model. They do not create a shared writable database, real-time cloud sync, or a Hikage account. Automatic backup is off by default. You may back up manually at any time or expressly enable automatic backup. Once enabled, Hikage attempts to publish only when non-rebuildable user data has changed and at least six hours have passed since the last successful backup, when the runtime becomes ready or the app becomes active again.

Each logical snapshot covers the raw activity records, local calendar ledger, reminder history, and historical app icons included in the existing .hikagedata user-data archive. It also includes the logical-day start, away rules, exclusions, separate website statistics, merges, classifications, time zone, and calendar parameters needed to view statistics using the contemporaneous rules. A snapshot does not contain activation codes, licensing or Keychain material, system permissions, Apple Calendar events, the complete set of user settings, local aliases that the current Mac assigns to other data sources, or runtime state outside the user-data archive.

The current repository format stores immutable content-addressed objects, including a raw-database checkpoint and append-only event segments, the local calendar ledger, reminder history, statistics profile, and historical app icons, together with a logical snapshot descriptor. It is the only backup-repository format this version recognizes. Identical objects may be shared by multiple snapshots from the same data source. Restore, export, and remote viewing reconstruct the same standard .hikagedata format after validating the required object set. Content addressing and integrity digests are not encryption and do not change the categories of data included in a backup.

The default backup location is an iCloud container managed by Hikage. Apple processes that data under your iCloud account, service settings, and its own privacy rules. You may instead choose a local folder, external disk, network volume, or third-party synchronization folder. The corresponding device, administrator, or synchronization provider may then read, copy, or process the files across borders according to your configuration. Hikage does not operate a backup server and does not send backups to its licensing, update, website, purchase, or support services.

The shared repository stores random repository, data-source, snapshot, and raw-lineage UUIDs; the Mac’s published name; publication time; app version; logical and newly stored sizes; raw-event sequence boundaries; event count and range; integrity digests; publication cursors; deletion markers; and the contemporaneous statistics profile. Each Mac also stores the backup-location bookmark, its random data-source identity, local aliases, and current statistics-presentation selection in the app preferences domain managed by macOS. These machine-specific values are not included in a user-settings export or .hikagedata.

When you view another Mac, Hikage reads only that device’s latest completely published and validated snapshot. It validates and, when necessary, reconstructs a standard archive before opening the remote raw database read-only, and fixes “now” and the derivation rules to the saved snapshot values. Recording, calendars, reminders, settings, and permissions on the current Mac do not switch. A successfully materialized remote snapshot and its rebuildable derived projection may be cached at Caches/Hikage/RemoteSources, allowing the last validated data to remain viewable while the shared location is temporarily offline.

Disabling automatic backup only stops future automatic publication; it does not delete existing snapshots. Changing the backup location does not move, merge, or delete the old location, and an unavailable location does not silently fall back to another one. Clearing Hikage/RemoteSources deletes only the current Mac’s remote-presentation cache, not the shared original. Deleting a shared backup requires selecting a specific snapshot in Backup History. In the current content-addressed format, a deletion marker hides that snapshot first; objects still referenced by another snapshot remain, and newly unreferenced objects are removed only after a seven-day grace period. Uninstalling the app generally does not delete snapshots from iCloud or a custom folder. A restore first creates a pre-restore snapshot of this Mac’s current data and then uses the user-data import process for whole replacement and rollback; it does not replace this Mac’s backup identity, settings, license, or system permissions.

5. Information Hikage Expressly Does Not Record or Upload

Hikage does not record the following in the raw activity database:

Hikage does not send frontmost-app activity, playback activity, browser web address records, input-activity timestamps, statistics, calendar candidates, Apple Calendar events, or reminder rules to the licensing service, a Merchant of Record, or the software-update service.

We do not sell or share your activity records for cross-site behavioral advertising, and we do not use those records to create advertising profiles.

6. System Permissions and Controls

Hikage may use the following macOS capabilities:

Identifying the frontmost app, determining system or display sleep state, detecting content-free input activity, and matching the frontmost app to the system media session for playback detection do not require the sensitive permissions listed above. Playback detection does not send Apple Events to the target app. Scheduled reminders use Hikage’s own menu bar popover. They do not use the macOS Notifications permission, and Hikage does not request that permission.

You can disable the relevant recording feature in Hikage settings, and you can revoke Automation, Accessibility, or Calendar access in System Settings > Privacy & Security. Disabling a feature or revoking permission stops future processing through that feature, but it does not automatically delete historical records, caches, calendar preview caches, or settings already stored on your device.

A macOS system authorization is not necessarily the same as consent for legal purposes. Where applicable law requires separate consent, we will provide the necessary information and choice before the relevant processing begins.

We process data only for the following purposes:

Depending on the law that applies in your region, we may rely on one or more of the following legal bases: performing a software-license or service contract with you; taking steps at your request before entering into a contract; obtaining your consent; complying with a legal obligation; and pursuing legitimate interests in service security, fraud prevention, fault diagnosis, order performance, protection of licensing rights, and dispute resolution. You may withdraw your consent at any time, but withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

The Merchant of Record may rely on its transaction contract with you, legal obligations, legitimate interests in fraud prevention and payment security, or another applicable legal basis when acting as the transaction seller, payee, tax processor, or payment-risk decision-maker. See the Merchant of Record’s privacy policy shown during checkout for its specific explanation.

8. Recipients and Third-Party Services

To the minimum extent necessary, the following recipients may process relevant data:

  1. Infrastructure providers. These currently include Cloudflare, which is used for website hosting, the public icon catalog, and the licensing service. It may process website and icon-catalog requests, license requests, database records, and operational logs according to our configuration and instructions.
  2. Software-update infrastructure. This infrastructure provides the public appcast, release notes, and update packages. Sparkle performs update checks and verification on your Mac.
  3. Target websites and their CDNs. They may receive a request when you explicitly open that website’s “Change Icon” selector, or when the icon catalog has no usable match during background preparation for a website already saved for separate statistics.
  4. Your chosen calendar provider. A provider receives an event when you write it to a calendar hosted by iCloud, Google, Microsoft Exchange, or another service.
  5. Apple iCloud or your chosen storage service. When you back up manually or enable automatic backup, Apple may process snapshots in Hikage’s iCloud container. Administrators of a custom folder, NAS, network volume, or third-party synchronization service may process the corresponding files according to your configuration.
  6. The Merchant of Record and its payment, tax, security, and checkout partners. They may sell Hikage, provide checkout, process payment and transaction taxes, issue receipts, perform security and anti-fraud checks, and handle refunds and payment disputes. The specific party and applicable policies are disclosed during checkout or on the order receipt.
  7. Email providers. They are used for purchase, licensing, support, refund, and privacy communications.
  8. Courts, regulators, or law-enforcement authorities. We provide data only when required by law or when necessary to protect users or the public, preserve lawful rights, or address fraud or abuse.
  9. A business successor. In a merger, reorganization, financing, or transfer of assets or business, relevant data may be transferred to a successor to the Hikage business to the extent permitted by law and subject to appropriate safeguards.

We require service providers that process data on our behalf to use security and confidentiality measures proportionate to the processing risk. Where a third party acts as an independent controller, its own privacy policy applies, and we do not control its legally independent processing.

9. Storage Locations and Retention

9.1 Local Data

Hikage’s raw activity database, calendar-integration database, user-selected app or website icons, cached website icons, and signed license Access Record are stored by default in the Hikage directory under your user Application Support directory. The LicenseV2 directory contains only one atomically replaced, current-user-only signed-access-record.json; it does not contain a complete activation code or device private key. Cached website icons may include Hikage catalog artwork and icons retrieved directly from target websites.

The rebuildable logical-day derived-projection database is stored by default at Caches/Hikage/DerivedProjection/Derived.sqlite. It can be regenerated from raw activity events and the current derivation settings and is not included in user-data exports.

Reminder history is stored in UserState.sqlite in the same directory as the current raw database. Reminder rules and some short-lived reminder runtime state remain in Hikage’s app preferences domain managed by macOS (UserDefaults). A user-data export includes reminder history, but not the full preferences domain; the separate user-settings export likewise includes only an explicit allowlist of portable settings.

The backup-location bookmark, this Mac’s random data-source identity, local data-source aliases, and current statistics-presentation selection are also stored in that app preferences domain, but are not included in a user-settings export. Fully validated snapshots from other Macs and their rebuildable derived projections may be stored at Caches/Hikage/RemoteSources; clearing it does not delete shared backups.

Shared backups are not Hikage server-side data. By default they are stored in Hikage’s container under your iCloud account, or they may be stored in a folder you select. Snapshots remain until removed by a manual deletion or the automatic retention rules. In the content-addressed format, shared objects remain while any snapshot or pending publication references them; after the last reference is removed, deletion is delayed by a seven-day grace period. Disabling automatic backup, changing locations, deleting the local Hikage directory, or uninstalling the app generally does not delete shared snapshots from an old location.

The random installation ID (together with a key-creation completion marker), device-signing key, and rollback anchors for at most eight grants are stored in the macOS Data Protection Keychain. Supported Macs use a Secure Enclave key; when the hardware is expressly unsupported, Hikage uses a sensitive, non-synchronizing software SecKey that cannot be exported through the public Security APIs. Hikage no longer writes a device private key to Application Support and does not silently create a second device identity when a committed key is missing or an existing credential is temporarily unreadable.

Local activity data remains until you delete it or it is removed because of system behavior, disk failure, backup restoration, or a similar event. The system or you may clear derived caches; clearing a cache does not delete the raw activity database. Uninstalling the app alone generally does not remove data from Application Support, Caches, or Keychain.

Separately, the website’s Boolean preference not to show future language suggestions remains in browser local storage until you clear the site data for hikage.app. The purchase-completion page may temporarily store a short-lived receipt and its expiration time in the current tab’s session storage and clears it under the conditions described in Section 4; a complete activation code is not placed in browser storage.

9.2 Server-Side Data

Server-side data is retained only for as long as needed for the relevant purpose. When determining a retention period, we consider whether a license or trial remains valid, whether device-seat management or security auditing remains necessary, applicable tax, accounting, or consumer-protection obligations, refund and dispute periods, fraud and abuse risks, and whether deletion or de-identification is technically feasible.

Data category Retention period or criteria
Perpetual-license records, order associations, and license status Retained while the license is valid and as needed to provide licensing services. After termination, retained only as necessary to comply with law, handle refunds or disputes, prevent fraud, or establish, exercise, or defend legal claims.
Encrypted current and historical activation-code generations Retained with the associated license record, including generations invalidated by reset, revocation, refund, or administrative rotation, so that authorized delivery, support, and audit functions remain consistent. Deleted or restricted when the associated record no longer needs to be retained, subject to legal, fraud-prevention, dispute, and backup-rotation requirements. Database backups contain ciphertext; the separately managed keyring is not part of the database backup.
Merchant-of-Record customer, order, transaction, adjustment, refund, and dispute associations Retained as needed to deliver or recover a license, verify transaction status, handle refunds and payment disputes, and comply with tax, accounting, and consumer-protection obligations; deleted, de-identified, or restricted when no longer needed. Records independently controlled by the Merchant of Record follow its own retention rules.
Activated or deactivated device information Retained as needed to manage device seats, restore licenses, and perform security audits; deleted or de-identified when no longer needed.
Trial device hashes and trial status Retained as needed to enforce the one-time-trial rule and prevent duplicate trials; deleted or de-identified after the relevant trial program or anti-abuse purpose ends.
License security events, IP hashes, and User-Agent strings Retained for the shortest period needed to investigate security events, prevent abuse, and handle legal disputes; deleted or de-identified after the relevant purpose ends.
Website, checkout-integration, and infrastructure operational logs Retained for the shortest period needed to protect service security, prevent abuse, verify checkout integration, and diagnose faults, then rotated or deleted according to infrastructure configuration.
Purchase, support, refund, and privacy emails Retained as needed to handle the request, perform the transaction, comply with legal obligations, and resolve disputes; deleted or archived with restricted processing when no longer needed.

As a general rule, we extract from Merchant-of-Record notices or webhooks only the fields needed to perform the transaction and maintain the license. If a more complete raw event is temporarily retained for idempotency, fault diagnosis, a security investigation, or dispute evidence, access and retention are limited; it is not treated as an indefinite business record.

When the purpose for retention no longer applies, the retention period expires, or a valid deletion request must be honored, we delete, anonymize, or otherwise stop processing relevant data that we control unless the law requires continued retention or the data remains necessary to establish, exercise, or defend legal claims. If relevant data remains in server backups, deletion takes effect progressively according to applicable backup-rotation and isolation procedures. Backup data is not used for ordinary business processing except for disaster recovery, security investigations, or legal requirements.

10. Children and Minors

Hikage is not designed specifically for children, does not actively create profiles of child users, and does not require users to create a Hikage account or provide their age.

Users must have reached the age at which they can independently consent to the relevant processing and enter into a software-license contract where they live. A user below that age may use Hikage only if a parent, guardian, or other legally authorized person reads and agrees to the relevant documents and is responsible for purchasing and enabling network-connected features. The guardian should help the user understand browser, Accessibility, and Apple Calendar permissions and enable only the features actually needed.

We do not use children’s activity records for advertising, cross-site tracking, or behavioral profiling. If we confirm that a server received a child’s personal information without valid parental or guardian consent where such consent is legally required, we will stop the relevant processing and, after verification, delete or de-identify the information or take another action required by applicable law. The user or their guardian may use the email address in this Policy to request access, correction, deletion, or cessation of processing. A request concerning transaction data independently controlled by a Merchant of Record should be directed separately to that party.

11. Your Choices and Rights

To the extent provided by applicable law, you may request:

Because activity records generally exist only on your Mac, we ordinarily cannot view, export, or delete that local data from a server. You must complete the relevant steps on your device:

  1. Stop recording and disable the relevant features in Hikage settings.
  2. Quit Hikage.
  3. Delete the Hikage directory from Application Support.
  4. Delete Hikage caches under Caches separately if needed.
  5. If you need to completely re-establish the device’s licensing identity, separately delete Hikage’s installation-ID, device-signing-key, and access-anchor items from macOS Keychain.
  6. Revoke Automation, Accessibility, and Calendar permissions in System Settings.
  7. To delete backups, separately delete specific snapshots in Hikage’s Backup History or manage the old location through the relevant storage service. Merely disabling automatic backup, changing locations, or clearing the remote cache does not delete the shared original.

Deleting local files does not automatically delete activation, trial, order-association, or security records held by the licensing service, and it does not delete events already written to a third-party calendar. You may contact support@hikage.app to request access to, correction of, or deletion of relevant server-side information that we control, or to request help identifying the Keychain item that should be removed.

We cannot act in place of a Merchant of Record concerning payment credentials, tax records, anti-fraud records, or statutory books that it independently controls. For those records, use the contact channel provided during checkout, on the order receipt, or in the Merchant of Record’s privacy policy. Where lawful and necessary, we may help identify the transaction or forward the request, but doing so does not transfer the Merchant of Record’s independent legal obligations to us.

To prevent impersonation, we may ask for information sufficient to verify the requester’s relationship to the relevant license, device, order, or email address. We will respond within the period required by applicable law. If we cannot fulfill a request, we will explain why and describe any available appeal or complaint process.

12. Cross-Border Processing

The Hikage website, licensing service, and purchase process use global infrastructure that may operate in multiple countries or regions. Technical information related to website or licensing-service use, activation information, order-association information, or support emails may therefore be processed outside your country or region. A Merchant of Record and its payment, tax, security, or checkout partners may also conduct cross-border processing through their global infrastructure. After you back up manually or enable automatic backup, Apple iCloud, a network-storage administrator, or a third-party synchronization service used by a custom folder may also process backup files across borders through its infrastructure.

We will use contractual, technical, and organizational measures required by applicable law. Where the law requires notice of an international transfer, separate consent, standard contractual clauses, a security assessment, or another procedure, we will complete the applicable requirement before the relevant transfer begins. Data processed only on your device and not uploaded is not transferred internationally by Hikage itself. However, a Merchant of Record, iCloud, Google, Microsoft Exchange, target websites, or other third-party services you use may conduct their own cross-border processing.

13. Data Security

We use measures proportionate to the processing risk, including:

The raw activity database currently has no additional Hikage application-layer encryption. Its protection depends on your macOS user account, file-system permissions, and any disk encryption you enable. We recommend enabling FileVault, using a strong login password, and protecting your device and backups.

Backup content likewise has no additional Hikage application-layer encryption, whether an older snapshot is stored as a complete .hikagedata archive or a current snapshot is stored as content-addressed objects. Its access controls and protection at rest and in transit depend on the iCloud account, file system, disk, network volume, or third-party synchronization service you select. Hikage uses digests and strict validation to detect incomplete or corrupted snapshots, but integrity validation is not encryption. Choose only a location that you trust and whose access permissions are appropriate.

No storage or transmission method can guarantee absolute security. If a data-security incident is likely to create a high risk to your rights or interests, we will take remedial action and provide legally required notices.

14. Changes to This Policy

We may update this Policy because of changes to features, data-processing practices, third-party services, purchase processes, or legal requirements. We will communicate material changes through the website, an in-app notice, release notes, a purchase contact email, or another appropriate channel and will state the new update and effective dates.

We will not use a policy change alone to retroactively apply previously collected data to a new purpose incompatible with the original purpose. Where applicable law requires consent, we will obtain it before the new processing begins.

The Merchant of Record used for a transaction, its policies, and the checkout data flow may change with the sales channel. We will identify the party actually used in the relevant checkout. This Policy does not designate an undisclosed platform as a permanent or exclusive provider.

15. Contact Us

For questions about this Policy, Hikage’s data-processing practices, or your personal-information rights, contact:

To help us process your request, use “Privacy Request” in the subject line and describe the type of request and its relationship to the relevant license, device, order, or email address.