Summary
- Activity records, statistics, categories, and reminder rules stay on your Mac unless you manually back up or enable automatic backup; immutable snapshots go to your selected iCloud storage or folder, not a Hikage backup server. Current backups may deduplicate content-addressed objects, but that integrity mechanism is not encryption. Enabled calendar actions may create Hikage-managed events and update their managed titles and markers while preserving other fields.
- Input activity keeps only throttled timestamps and a coarse keyboard or mouse-button category. Hikage does not save typed text, mouse coordinates, input-device brands, models, or unique identifiers, window titles, page content, complete URLs, or media titles and playback details.
- The app connects to external services only for specific features such as licensing, software updates, and website icons, without uploading your activity data. Complete activation codes are retained encrypted for delivery and support; administrative reveal requires dedicated permission and is audited.
- Checkout may use the Merchant of Record shown during purchase. Support actions only open an editable email draft, which is sent only if you choose to send it.
This summary does not replace the full policy below.
Last updated and effective: August 16, 2026
Hikage is a macOS activity recording and review app. Its core design principle is to process activity data on your device wherever possible and to transmit only the information necessary to provide online features that you enable, request, or continue to use.
This Privacy Policy explains what data Hikage processes, why it is processed, how it is stored, which third parties may receive it, and how you can manage or delete it. Please read this Policy before using Hikage.
1. Scope and Contact
This Policy applies to:
- the Hikage macOS app;
- the official Hikage website at
hikage.app; - software downloads, installation, update checks, free trials, purchases, license activation, and related support services.
In this Policy, “we,” “us,” and “our” refer to the operator of Hikage. The contact channel for matters concerning the data processing described in this Policy is:
- Email: support@hikage.app
This Policy does not apply to third-party websites you access through Hikage, calendar providers you choose to connect, or other third-party services you use independently. Those services are governed by their own privacy policies. When you purchase through a Merchant of Record, that party also processes relevant transaction data independently under the privacy policy shown during checkout.
2. Our Privacy Principles
Hikage follows these principles:
- Local first. Activity records, statistics, reminder rules, and calendar candidates are generally stored on your Mac rather than uploaded to Hikage servers. Hikage writes immutable user-data copies to your selected iCloud storage or folder only after you back up manually or expressly enable automatic backup.
- Data minimization. Hikage processes only the data needed to provide the relevant feature. Hikage does not record typed content, media titles, authors, playback progress, window titles, or clipboard data. Hikage does not save full URLs, paths, query parameters, page titles, or page contents.
- Permission on demand. macOS permissions involving browsers, Accessibility, or Apple Calendar are requested only when you actively enable the relevant capability.
- Purpose limitation. Hikage does not use activity records for advertising profiles or cross-site behavioral advertising, and it does not sell such data.
- User control. You can stop recording, disable features, revoke system permissions, delete local data, or—where applicable law provides—request access to, correction of, or deletion of relevant server-side information that we control.
3. Data Processed Only on Your Device
3.1 Frontmost Apps and Device State
To produce usage time, daily statistics, monthly statistics, per-app statistics, and graph view, Hikage may record the following on your device:
- the frontmost app’s bundle identifier, display name, process identifier, and transition time;
- system sleep and wake times;
- display sleep and wake times;
- local timestamps, randomly generated recording-session identifiers, and event identifiers needed to preserve event order and calculate duration.
By default, this data is written to a local SQLite database under your user directory.
3.2 Content-Free Input-Activity Timestamps
To determine whether you are still using the computer, Hikage may query how much time has passed since the most recent keyboard press or mouse-button press and may store the throttled activity timestamp locally together with the coarse source category “keyboard” or “mouse button.” Both categories share the same 15-second throttle, so distinguishing the source does not add event rows.
Hikage does not record specific keys, keyboard shortcuts, typed text, mouse coordinates, pointer movement, clicked objects, the target app, input-device brands, models, unique identifiers, or clipboard content. This feature does not create a global keyboard event monitor and does not require the macOS Input Monitoring permission.
3.3 Playback Activity Detection
While frontmost-app recording is running, Hikage automatically checks whether the frontmost app matches the system media session currently elected by macOS. Hikage uses only the session’s source hierarchy and playback rate for this in-memory match. It does not send an Apple Event to the target app or request Automation or another macOS privacy permission.
When the frontmost app clearly matches a playing system media session, Hikage records playback start, one continued-playback confirmation every 30 seconds, playback end, and their timestamps in the raw activity database for away detection. Each playback fact contains only its phase and timestamp; the app identity comes from the frontmost-app facts already recorded for the same period. Each start or confirmation allows derived playback activity to continue for at most 30 seconds. A pause, source mismatch, frontmost-app switch, system or display sleep, stopping recording, or unavailable detection capability ends the current playback state.
Hikage does not extract, transmit, or save media titles, authors, progress, page titles, full URLs, or page contents. System-media-session identifiers, source hierarchy, and playback rate are not written to the raw database or sent over the network; the source hierarchy and playback rate are used only for the current in-memory match.
3.4 Web Addresses in Browsers
After you actively enable browser web address recording for a supported browser, Hikage temporarily reads the current web address and immediately normalizes it in memory for statistics.
- For public websites, Hikage generally stores only the hostname, such as
www.example.com; it does not store the scheme, path, query parameters, or fragment. - For local or LAN services, Hikage may retain a non-default port to distinguish different services on the same host.
- Hikage also stores the browser identity, event time, and—where it can be determined—the standard or private-browsing context.
- A full URL exists only briefly in memory during a single read and normalization operation and is not written to the raw database.
For browsers whose private windows can be identified reliably, Hikage skips private windows by default unless you expressly allow them to be recorded. System interfaces for browsers such as Safari and Firefox may not reliably distinguish standard windows from private windows. In those cases, the context is marked as “unknown,” and the current settings let you choose whether all unknown contexts should be skipped.
3.5 Statistics, Categories, Exclusions, and Reminders
Hikage stores or derives the following locally:
- daily statistics, monthly statistics, per-app statistics, category summaries, and graph view;
- app and website categories, colors, custom and system exclusion lists, away thresholds, and away exceptions;
- preferences such as module order, language, appearance, menu bar behavior, and launch at login;
- scheduled-reminder rules, reminder status, recent reminder records, pause state, and the pending-delivery queue.
This information is used only for Hikage’s local features and is not uploaded as part of license activation, purchase confirmation, or software-update requests.
3.6 Calendar Integration
The presence of a calendar feature in the interface does not mean Hikage has obtained access to your calendars. Hikage requests the relevant permission only when you actively connect Apple Calendar, add or delete a calendar item, or choose to delete both a rule and its managed items. Preview, prefetch, and background checks do not initiate a permission request on their own.
When you enable calendar preview, the page displays only non-all-day events from the calendars you select in the current preview range. For display, identification, deduplication, update, or deletion, Hikage reads the required event and calendar metadata, including event titles and times, event and calendar identifiers, calendar and source names, colors, and Hikage management markers. Hikage does not read event notes, attendees, locations, or alerts, and it does not keep those fields or arbitrary event URL content in its local preview cache; it uses Event URLs only to recognize Hikage’s own management markers.
To improve display speed, Hikage may keep a limited, rebuildable cache of recent preview intervals in its local calendar-integration database. This cache may contain the metadata described above from calendars you selected previously and is pruned automatically to a capacity limit.
“Automatically add recently completed items” is off by default. After you expressly enable it, and only while Hikage already has full Calendar access, Hikage may check recently completed candidates in the background. For each candidate, Hikage reads the target calendar and the time interval needed for duplicate detection. To prevent duplicate creation and recover an unfinished Hikage write, it may also recognize Hikage’s own management marker within a limited interval around the candidate. Background processing does not request permission on its own or read an unlimited calendar history unrelated to processing that candidate; an eligible, non-duplicate candidate may be written to the target calendar according to your setting.
When you enable the relevant rule or action, Hikage may create Apple Calendar events managed by Hikage and write the activity name, start and end times, the number of actual active minutes if you choose to include it, and notes summarizing the activity and any periods of interruption. When a rule name or title-suffix setting changes, Hikage may update the title and Hikage management marker of those managed events while preserving other calendar fields you changed. By default, Hikage does not write raw browser web address events, input activity, bundle identifiers, attendees, locations, or alerts.
Unless you expressly perform a deletion or another action, Hikage does not modify calendar events unrelated to Hikage.
When you delete an external calendar event from Hikage, that action directly deletes the corresponding Apple Calendar event. If the target calendar is provided by iCloud, Google, Microsoft Exchange, or another service, the event may be synchronized to that provider’s servers according to the settings between you and the provider.
3.7 Website Language Suggestions
On the home, pricing, and changelog pages, the Hikage website may compare the current page language with the browser’s local navigator.languages preference list, falling back to navigator.language when the list is empty. This comparison occurs entirely in your browser. The language-suggestion feature does not make an additional network request to send or analyze the language list, current path, or suggested language, and it never changes the page language automatically.
Accepting a suggestion only opens the same page in the suggested supported language and does not save a preference. Closing the suggestion with its close button or the Escape key also does not save a preference. Only when you expressly choose to continue with the current language and stop future suggestions does the website store localStorage["hikage.languageSuggestion.declined.v1"] = "1". This value is only a Boolean refusal preference; it does not contain your language list, path, or suggested language. Clearing the site data for hikage.app removes the preference and allows eligible language suggestions to appear again.
4. Data Transmitted over the Network or Stored on Servers
Hikage does not upload its activity database or statistics merely because you use one of the network features below. Network requests ordinarily expose the requester’s IP address, request time, network protocol, and necessary request headers to the recipient.
4.1 Free Trials, License Activation, and Device Management
When you actively start a free trial, enter an activation code, refresh a license, view activated devices, or deactivate a device, Hikage sends the data needed to complete that operation to the licensing service. This data may include:
- a locally generated random installation ID;
- the device public key and a device hash derived from the installation ID and public key;
- proof signed by the device;
- the Hikage version, macOS version, and hardware model;
- a device label used in the device list, usually based on the Mac’s local name;
- the grant identifier for the current trial or activation and the activation-record identifier of a device to be deactivated;
- the activation code you actively enter.
Hikage does not read or transmit the hardware serial number, hardware UUID, or another unique hardware serial identifier. An activation code is used only for the individual activation request, and the client does not retain the complete code in plaintext.
The licensing service may store license records, activated-device records, trial records, last-seen times, app and system versions, hardware models, device labels, public keys, device hashes, and license events needed for security auditing and abuse prevention. For each current or invalidated historical code generation, the service stores the complete activation code in an AES-256-GCM encrypted envelope, together with an irreversible keyed digest and a small number of trailing characters. The license database and its backups contain ciphertext rather than the plaintext code; the encryption keyring is managed separately. The complete code is decrypted only for purchase delivery, re-delivery of the current code, purchase or license support, and a single-generation administrative reveal. Administrative reveal requires a dedicated permission, and both successful and failed reveal attempts are audited. License events may include a keyed-hash representation of the IP address, the User-Agent, and necessary event information.
The licensing service may also store the association between an order and a license, together with order or transaction identifiers, the purchase email address, the supported Hikage website language in use when the purchase was completed, payment and refund status, and necessary notes received from a Merchant of Record. The recorded website language is one page locale, such as en or fr; it is not the browser’s language-preference list. This information is used to deliver or recover a license, send the complete purchase email first in English and then restate it in the purchaser’s website language, handle refunds or payment disputes, and prevent abuse.
4.2 Software Updates
Hikage uses Sparkle to check for and install software updates. When automatic checking is enabled, Hikage periodically accesses a public update feed. You can also choose “Check for Updates” manually.
An update request may include the installed Hikage version, update channel, interface language, and the IP address and request headers naturally generated by the network request. Hikage currently does not enable Sparkle’s system-profiling feature. Update requests do not send activity records, web address records, statistics, calendar data, reminder rules, activation codes, order information, or the device list.
4.3 Website Icon Retrieval
When Hikage prepares an icon for a website that you have saved for separate website statistics, it first accesses the public icon catalog at hikage.app over HTTPS. Every enabled website uses the same manifest URL, and this request does not include the current hostname, your browsing history, or a list of websites you have enabled. Hikage matches the normalized hostname locally on your Mac. If it finds a match, it may request the catalog’s content-addressed light and/or dark icon files.
The infrastructure hosting hikage.app may therefore receive your IP address, request time, the Hikage/1.0 User-Agent, and the requested manifest or icon path. Because the catalog’s icon IDs and hostname mappings are public, a request for a matched icon file may reveal which catalog entry—and therefore which associated website—was matched. The catalog does not receive your activity database, statistics, full URLs, or list of recorded websites.
If the catalog has no matching entry or is unavailable, Hikage may then access the target website or an allowed same-site subdomain to retrieve a favicon or another icon declared by the page. This fallback may run during background icon preparation, including after app launch, but it is limited to websites already saved for separate website statistics. Hikage does not derive fallback requests from raw browsing history, the current browser tab, or websites that you have not enabled. Hikage may also directly prepare the target website’s favicon when you explicitly open its “Change Icon” selector. A usable catalog match does not trigger the background fallback; the default YouTube entry contacts YouTube only if this fallback is needed.
The target website or its CDN may therefore receive your IP address, the request time, the requested icon path, and the Hikage/1.0 User-Agent. Any homepage HTML read while locating an icon is processed only in memory, and webpage content is not stored. Hikage limits redirect scope and response-body size.
Catalog requests and redirects are restricted to same-origin HTTPS, and downloaded catalog icons are checked against their published SHA-256 digest and image limits. The licensing and update services also use HTTPS. The protocol used for a direct target-website icon request depends on the protocol offered by that website; the current version may try HTTP if HTTPS retrieval fails. HTTP does not provide the same confidentiality in transit as HTTPS.
4.4 Visits to the Website and Checkout Components
The Hikage website is hosted by infrastructure providers. We currently do not intentionally deploy advertising SDKs, cross-site tracking, or third-party behavioral analytics. Hosting providers may nevertheless process IP addresses, request times, User-Agent strings, requested paths, response statuses, and similar technical logs to deliver webpages, prevent abuse, diagnose faults, and maintain security.
When a purchase page loads a checkout script, component, or hosted page supplied by a Merchant of Record, that party and its content-delivery, security, and payment partners may receive an IP address, request time, User-Agent string, device and browser information, language, referring page, and other technical information needed to provide checkout and prevent fraud. Checkout may use cookies or similar technologies necessary to complete the transaction, perform security checks, and prevent fraud. If non-essential analytics, marketing, or abandoned-checkout recovery features are enabled in the future, we will provide any additional notice and obtain consent where applicable law requires.
After a verified purchase is fulfilled, the Hikage purchase-completion page may use a short-lived receipt to retrieve and display the initial activation code, while the same code is also delivered by email. The page removes the receipt from the address bar immediately and may keep only the receipt and its expiration time in the current tab’s session storage. It does not place the activation code in URL parameters or browser storage; the code remains only in page memory and the displayed page, and is cleared when the page is hidden, the receipt expires, or the flow moves to support.
The website does not sell or share personal information for advertising purposes. Essential cookies or similar technologies set by infrastructure providers or a Merchant of Record depend on the specific service configuration and the provider’s own policies.
4.5 Purchases and the Merchant of Record
Paid Hikage products may be sold to you by the third-party Merchant of Record identified on the checkout page or order receipt. That party may act as the seller, payee, or authorized reseller for the transaction. The specific Merchant of Record, legal entity, and applicable policies will be identified during checkout, on the order receipt, or in the transaction confirmation.
During checkout, you ordinarily provide the Merchant of Record with, or allow it to process, information such as the following, depending on the checkout configuration and payment method:
- your name, purchase email address, country or region, postal code, and billing address;
- company name, tax identifier, or tax-exemption information where applicable;
- the product, price, quantity, discount, currency, tax, and transaction time;
- payment method, cardholder or payment-account information, payment credentials, and payment status;
- IP address, device, browser, language, and security, authentication, and anti-fraud information;
- refund, payment-reversal, chargeback, dispute, and transaction-related communications.
In a standard checkout hosted directly by the Merchant of Record, Hikage generally does not receive or store a complete payment-card number, card security code, complete payment-account credentials, or an online-banking password unless the checkout page clearly states otherwise. Enter payment credentials only in the secure checkout interface supplied by the Merchant of Record.
To deliver and maintain a license, recover a purchase, provide support, handle a refund or payment dispute, prevent fraud, and comply with legal obligations, the Merchant of Record may provide us with necessary transaction data through a dashboard, API, webhook, order notice, or support communication. This data may include:
- customer, order, transaction, adjustment, refund, or dispute identifiers;
- the purchaser’s name, email address, and necessary billing or tax information;
- product, price, quantity, discount, amount, currency, and tax;
- payment, delivery, refund, payment-reversal, chargeback, and dispute status;
- order-creation, payment, completion, refund, and dispute timestamps;
- information needed to associate the order with a Hikage license, activation code, or license record.
We use only the data actually received and necessary for these purposes. Purchasing Hikage does not cause us to receive or upload your local activity records.
To the extent that the Merchant of Record acts as the transaction seller, payee, tax processor, payment-risk decision-maker, or entity required by law to retain records, it ordinarily processes data independently for its own purposes and legal obligations under its own privacy policy. Hikage independently determines the processing needed to associate orders with licenses, deliver software, activate licenses, provide product support, and handle its own disputes. A privacy request made to us does not automatically delete or alter payment, tax, or compliance records independently controlled by the Merchant of Record, and the reverse is also true.
4.6 Support and Privacy Communications
The Hikage app and feedback page do not collect, upload, or store feedback. Choosing a feedback entry asks your operating system or browser to open its configured email handler with support@hikage.app and a category subject. A problem report also includes an editable body template. Hikage does not automatically read or attach screenshots, logs, activity records, license data, or other user content.
Only if you choose to send the draft through your email service do we receive the sender address, message content, attachments, and other information you choose to provide. We use this information as necessary to reply, handle a purchase, license, refund, technical-support or privacy request, and improve the product. The email provider you use processes the message under its own terms and privacy policy.
4.7 Backups and Viewing Data from Other Macs
Backups use a “separate recording on each Mac, immutable snapshots published to a shared location” model. They do not create a shared writable database, real-time cloud sync, or a Hikage account. Automatic backup is off by default. You may back up manually at any time or expressly enable automatic backup. Once enabled, Hikage attempts to publish only when non-rebuildable user data has changed and at least six hours have passed since the last successful backup, when the runtime becomes ready or the app becomes active again.
Each logical snapshot covers the raw activity records, local calendar ledger, reminder history, and historical app icons included in the existing .hikagedata user-data archive. It also includes the logical-day start, away rules, exclusions, separate website statistics, merges, classifications, time zone, and calendar parameters needed to view statistics using the contemporaneous rules. A snapshot does not contain activation codes, licensing or Keychain material, system permissions, Apple Calendar events, the complete set of user settings, local aliases that the current Mac assigns to other data sources, or runtime state outside the user-data archive.
The current repository format stores immutable content-addressed objects, including a raw-database checkpoint and append-only event segments, the local calendar ledger, reminder history, statistics profile, and historical app icons, together with a logical snapshot descriptor. It is the only backup-repository format this version recognizes. Identical objects may be shared by multiple snapshots from the same data source. Restore, export, and remote viewing reconstruct the same standard .hikagedata format after validating the required object set. Content addressing and integrity digests are not encryption and do not change the categories of data included in a backup.
The default backup location is an iCloud container managed by Hikage. Apple processes that data under your iCloud account, service settings, and its own privacy rules. You may instead choose a local folder, external disk, network volume, or third-party synchronization folder. The corresponding device, administrator, or synchronization provider may then read, copy, or process the files across borders according to your configuration. Hikage does not operate a backup server and does not send backups to its licensing, update, website, purchase, or support services.
The shared repository stores random repository, data-source, snapshot, and raw-lineage UUIDs; the Mac’s published name; publication time; app version; logical and newly stored sizes; raw-event sequence boundaries; event count and range; integrity digests; publication cursors; deletion markers; and the contemporaneous statistics profile. Each Mac also stores the backup-location bookmark, its random data-source identity, local aliases, and current statistics-presentation selection in the app preferences domain managed by macOS. These machine-specific values are not included in a user-settings export or .hikagedata.
When you view another Mac, Hikage reads only that device’s latest completely published and validated snapshot. It validates and, when necessary, reconstructs a standard archive before opening the remote raw database read-only, and fixes “now” and the derivation rules to the saved snapshot values. Recording, calendars, reminders, settings, and permissions on the current Mac do not switch. A successfully materialized remote snapshot and its rebuildable derived projection may be cached at Caches/Hikage/RemoteSources, allowing the last validated data to remain viewable while the shared location is temporarily offline.
Disabling automatic backup only stops future automatic publication; it does not delete existing snapshots. Changing the backup location does not move, merge, or delete the old location, and an unavailable location does not silently fall back to another one. Clearing Hikage/RemoteSources deletes only the current Mac’s remote-presentation cache, not the shared original. Deleting a shared backup requires selecting a specific snapshot in Backup History. In the current content-addressed format, a deletion marker hides that snapshot first; objects still referenced by another snapshot remain, and newly unreferenced objects are removed only after a seven-day grace period. Uninstalling the app generally does not delete snapshots from iCloud or a custom folder. A restore first creates a pre-restore snapshot of this Mac’s current data and then uses the user-data import process for whole replacement and rollback; it does not replace this Mac’s backup identity, settings, license, or system permissions.
5. Information Hikage Expressly Does Not Record or Upload
Hikage does not record the following in the raw activity database:
- specific keys, keyboard shortcuts, or typed text;
- mouse coordinates, pointer movement, or clicked objects;
- input-device brands, models, or unique identifiers;
- media titles, authors, playback progress, system-media-session identifiers, source hierarchy, or playback rate;
- window titles;
- full URLs, paths, query parameters, page titles, or page contents;
- clipboard content;
- screen images or camera or microphone content.
Hikage does not send frontmost-app activity, playback activity, browser web address records, input-activity timestamps, statistics, calendar candidates, Apple Calendar events, or reminder rules to the licensing service, a Merchant of Record, or the software-update service.
We do not sell or share your activity records for cross-site behavioral advertising, and we do not use those records to create advertising profiles.
6. System Permissions and Controls
Hikage may use the following macOS capabilities:
- Automation permission: used to read the current web address from browsers such as Safari, Google Chrome, Chromium, and Microsoft Edge; each browser is enabled separately.
- Accessibility permission: used only when you enable Firefox web address recording, to read address information exposed through the system Accessibility interface for the frontmost Firefox window.
- Full Apple Calendar access: used to read the calendars you select, create Hikage-managed events, update the titles and Hikage management markers of those managed events, and delete events when you expressly perform the relevant action. Unless you expressly perform a deletion or another action, Hikage does not modify events unrelated to Hikage.
Identifying the frontmost app, determining system or display sleep state, detecting content-free input activity, and matching the frontmost app to the system media session for playback detection do not require the sensitive permissions listed above. Playback detection does not send Apple Events to the target app. Scheduled reminders use Hikage’s own menu bar popover. They do not use the macOS Notifications permission, and Hikage does not request that permission.
You can disable the relevant recording feature in Hikage settings, and you can revoke Automation, Accessibility, or Calendar access in System Settings > Privacy & Security. Disabling a feature or revoking permission stops future processing through that feature, but it does not automatically delete historical records, caches, calendar preview caches, or settings already stored on your device.
A macOS system authorization is not necessarily the same as consent for legal purposes. Where applicable law requires separate consent, we will provide the necessary information and choice before the relevant processing begins.
7. Purposes and Legal Bases for Processing
We process data only for the following purposes:
- to provide activity recording, statistics, categorization, reminders, and calendar integration on your device;
- to create, store, read, retain, delete, or restore immutable per-Mac backups at your direction and to present snapshots from other Macs read-only;
- to provide free trials, verify licenses, manage device seats, and prevent duplicate trials or license abuse;
- to confirm purchases, deliver or recover licenses, and associate orders with license records;
- to handle refunds, duplicate charges, delivery failures, payment reversals, chargebacks, and payment disputes;
- to check, download, and verify software updates;
- to retrieve icons for websites with separate website statistics enabled;
- to provide technical support, order support, and privacy-request handling;
- to protect the website and services, diagnose faults, comply with tax, accounting, consumer-protection, or other legal obligations, and establish, exercise, or defend legal claims.
Depending on the law that applies in your region, we may rely on one or more of the following legal bases: performing a software-license or service contract with you; taking steps at your request before entering into a contract; obtaining your consent; complying with a legal obligation; and pursuing legitimate interests in service security, fraud prevention, fault diagnosis, order performance, protection of licensing rights, and dispute resolution. You may withdraw your consent at any time, but withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
The Merchant of Record may rely on its transaction contract with you, legal obligations, legitimate interests in fraud prevention and payment security, or another applicable legal basis when acting as the transaction seller, payee, tax processor, or payment-risk decision-maker. See the Merchant of Record’s privacy policy shown during checkout for its specific explanation.
8. Recipients and Third-Party Services
To the minimum extent necessary, the following recipients may process relevant data:
- Infrastructure providers. These currently include Cloudflare, which is used for website hosting, the public icon catalog, and the licensing service. It may process website and icon-catalog requests, license requests, database records, and operational logs according to our configuration and instructions.
- Software-update infrastructure. This infrastructure provides the public appcast, release notes, and update packages. Sparkle performs update checks and verification on your Mac.
- Target websites and their CDNs. They may receive a request when you explicitly open that website’s “Change Icon” selector, or when the icon catalog has no usable match during background preparation for a website already saved for separate statistics.
- Your chosen calendar provider. A provider receives an event when you write it to a calendar hosted by iCloud, Google, Microsoft Exchange, or another service.
- Apple iCloud or your chosen storage service. When you back up manually or enable automatic backup, Apple may process snapshots in Hikage’s iCloud container. Administrators of a custom folder, NAS, network volume, or third-party synchronization service may process the corresponding files according to your configuration.
- The Merchant of Record and its payment, tax, security, and checkout partners. They may sell Hikage, provide checkout, process payment and transaction taxes, issue receipts, perform security and anti-fraud checks, and handle refunds and payment disputes. The specific party and applicable policies are disclosed during checkout or on the order receipt.
- Email providers. They are used for purchase, licensing, support, refund, and privacy communications.
- Courts, regulators, or law-enforcement authorities. We provide data only when required by law or when necessary to protect users or the public, preserve lawful rights, or address fraud or abuse.
- A business successor. In a merger, reorganization, financing, or transfer of assets or business, relevant data may be transferred to a successor to the Hikage business to the extent permitted by law and subject to appropriate safeguards.
We require service providers that process data on our behalf to use security and confidentiality measures proportionate to the processing risk. Where a third party acts as an independent controller, its own privacy policy applies, and we do not control its legally independent processing.
9. Storage Locations and Retention
9.1 Local Data
Hikage’s raw activity database, calendar-integration database, user-selected app or website icons, cached website icons, and signed license Access Record are stored by default in the Hikage directory under your user Application Support directory. The LicenseV2 directory contains only one atomically replaced, current-user-only signed-access-record.json; it does not contain a complete activation code or device private key. Cached website icons may include Hikage catalog artwork and icons retrieved directly from target websites.
The rebuildable logical-day derived-projection database is stored by default at Caches/Hikage/DerivedProjection/Derived.sqlite. It can be regenerated from raw activity events and the current derivation settings and is not included in user-data exports.
Reminder history is stored in UserState.sqlite in the same directory as the current raw database. Reminder rules and some short-lived reminder runtime state remain in Hikage’s app preferences domain managed by macOS (UserDefaults). A user-data export includes reminder history, but not the full preferences domain; the separate user-settings export likewise includes only an explicit allowlist of portable settings.
The backup-location bookmark, this Mac’s random data-source identity, local data-source aliases, and current statistics-presentation selection are also stored in that app preferences domain, but are not included in a user-settings export. Fully validated snapshots from other Macs and their rebuildable derived projections may be stored at Caches/Hikage/RemoteSources; clearing it does not delete shared backups.
Shared backups are not Hikage server-side data. By default they are stored in Hikage’s container under your iCloud account, or they may be stored in a folder you select. Snapshots remain until removed by a manual deletion or the automatic retention rules. In the content-addressed format, shared objects remain while any snapshot or pending publication references them; after the last reference is removed, deletion is delayed by a seven-day grace period. Disabling automatic backup, changing locations, deleting the local Hikage directory, or uninstalling the app generally does not delete shared snapshots from an old location.
The random installation ID (together with a key-creation completion marker), device-signing key, and rollback anchors for at most eight grants are stored in the macOS Data Protection Keychain. Supported Macs use a Secure Enclave key; when the hardware is expressly unsupported, Hikage uses a sensitive, non-synchronizing software SecKey that cannot be exported through the public Security APIs. Hikage no longer writes a device private key to Application Support and does not silently create a second device identity when a committed key is missing or an existing credential is temporarily unreadable.
Local activity data remains until you delete it or it is removed because of system behavior, disk failure, backup restoration, or a similar event. The system or you may clear derived caches; clearing a cache does not delete the raw activity database. Uninstalling the app alone generally does not remove data from Application Support, Caches, or Keychain.
Separately, the website’s Boolean preference not to show future language suggestions remains in browser local storage until you clear the site data for hikage.app. The purchase-completion page may temporarily store a short-lived receipt and its expiration time in the current tab’s session storage and clears it under the conditions described in Section 4; a complete activation code is not placed in browser storage.
9.2 Server-Side Data
Server-side data is retained only for as long as needed for the relevant purpose. When determining a retention period, we consider whether a license or trial remains valid, whether device-seat management or security auditing remains necessary, applicable tax, accounting, or consumer-protection obligations, refund and dispute periods, fraud and abuse risks, and whether deletion or de-identification is technically feasible.
| Data category | Retention period or criteria |
|---|---|
| Perpetual-license records, order associations, and license status | Retained while the license is valid and as needed to provide licensing services. After termination, retained only as necessary to comply with law, handle refunds or disputes, prevent fraud, or establish, exercise, or defend legal claims. |
| Encrypted current and historical activation-code generations | Retained with the associated license record, including generations invalidated by reset, revocation, refund, or administrative rotation, so that authorized delivery, support, and audit functions remain consistent. Deleted or restricted when the associated record no longer needs to be retained, subject to legal, fraud-prevention, dispute, and backup-rotation requirements. Database backups contain ciphertext; the separately managed keyring is not part of the database backup. |
| Merchant-of-Record customer, order, transaction, adjustment, refund, and dispute associations | Retained as needed to deliver or recover a license, verify transaction status, handle refunds and payment disputes, and comply with tax, accounting, and consumer-protection obligations; deleted, de-identified, or restricted when no longer needed. Records independently controlled by the Merchant of Record follow its own retention rules. |
| Activated or deactivated device information | Retained as needed to manage device seats, restore licenses, and perform security audits; deleted or de-identified when no longer needed. |
| Trial device hashes and trial status | Retained as needed to enforce the one-time-trial rule and prevent duplicate trials; deleted or de-identified after the relevant trial program or anti-abuse purpose ends. |
| License security events, IP hashes, and User-Agent strings | Retained for the shortest period needed to investigate security events, prevent abuse, and handle legal disputes; deleted or de-identified after the relevant purpose ends. |
| Website, checkout-integration, and infrastructure operational logs | Retained for the shortest period needed to protect service security, prevent abuse, verify checkout integration, and diagnose faults, then rotated or deleted according to infrastructure configuration. |
| Purchase, support, refund, and privacy emails | Retained as needed to handle the request, perform the transaction, comply with legal obligations, and resolve disputes; deleted or archived with restricted processing when no longer needed. |
As a general rule, we extract from Merchant-of-Record notices or webhooks only the fields needed to perform the transaction and maintain the license. If a more complete raw event is temporarily retained for idempotency, fault diagnosis, a security investigation, or dispute evidence, access and retention are limited; it is not treated as an indefinite business record.
When the purpose for retention no longer applies, the retention period expires, or a valid deletion request must be honored, we delete, anonymize, or otherwise stop processing relevant data that we control unless the law requires continued retention or the data remains necessary to establish, exercise, or defend legal claims. If relevant data remains in server backups, deletion takes effect progressively according to applicable backup-rotation and isolation procedures. Backup data is not used for ordinary business processing except for disaster recovery, security investigations, or legal requirements.
10. Children and Minors
Hikage is not designed specifically for children, does not actively create profiles of child users, and does not require users to create a Hikage account or provide their age.
Users must have reached the age at which they can independently consent to the relevant processing and enter into a software-license contract where they live. A user below that age may use Hikage only if a parent, guardian, or other legally authorized person reads and agrees to the relevant documents and is responsible for purchasing and enabling network-connected features. The guardian should help the user understand browser, Accessibility, and Apple Calendar permissions and enable only the features actually needed.
We do not use children’s activity records for advertising, cross-site tracking, or behavioral profiling. If we confirm that a server received a child’s personal information without valid parental or guardian consent where such consent is legally required, we will stop the relevant processing and, after verification, delete or de-identify the information or take another action required by applicable law. The user or their guardian may use the email address in this Policy to request access, correction, deletion, or cessation of processing. A request concerning transaction data independently controlled by a Merchant of Record should be directed separately to that party.
11. Your Choices and Rights
To the extent provided by applicable law, you may request:
- confirmation of whether we process your personal information and a copy of that information;
- correction or completion of inaccurate or incomplete information;
- deletion of personal information;
- withdrawal of consent;
- restriction of or objection to particular processing;
- data in a structured and commonly used format, or transfer of data where technically feasible;
- basic information about automated decision-making; Hikage currently does not use automated decision-making that produces legal or similarly significant effects for you;
- the ability to lodge a complaint with a competent privacy or data-protection authority.
Because activity records generally exist only on your Mac, we ordinarily cannot view, export, or delete that local data from a server. You must complete the relevant steps on your device:
- Stop recording and disable the relevant features in Hikage settings.
- Quit Hikage.
- Delete the
Hikagedirectory from Application Support. - Delete Hikage caches under Caches separately if needed.
- If you need to completely re-establish the device’s licensing identity, separately delete Hikage’s installation-ID, device-signing-key, and access-anchor items from macOS Keychain.
- Revoke Automation, Accessibility, and Calendar permissions in System Settings.
- To delete backups, separately delete specific snapshots in Hikage’s Backup History or manage the old location through the relevant storage service. Merely disabling automatic backup, changing locations, or clearing the remote cache does not delete the shared original.
Deleting local files does not automatically delete activation, trial, order-association, or security records held by the licensing service, and it does not delete events already written to a third-party calendar. You may contact support@hikage.app to request access to, correction of, or deletion of relevant server-side information that we control, or to request help identifying the Keychain item that should be removed.
We cannot act in place of a Merchant of Record concerning payment credentials, tax records, anti-fraud records, or statutory books that it independently controls. For those records, use the contact channel provided during checkout, on the order receipt, or in the Merchant of Record’s privacy policy. Where lawful and necessary, we may help identify the transaction or forward the request, but doing so does not transfer the Merchant of Record’s independent legal obligations to us.
To prevent impersonation, we may ask for information sufficient to verify the requester’s relationship to the relevant license, device, order, or email address. We will respond within the period required by applicable law. If we cannot fulfill a request, we will explain why and describe any available appeal or complaint process.
12. Cross-Border Processing
The Hikage website, licensing service, and purchase process use global infrastructure that may operate in multiple countries or regions. Technical information related to website or licensing-service use, activation information, order-association information, or support emails may therefore be processed outside your country or region. A Merchant of Record and its payment, tax, security, or checkout partners may also conduct cross-border processing through their global infrastructure. After you back up manually or enable automatic backup, Apple iCloud, a network-storage administrator, or a third-party synchronization service used by a custom folder may also process backup files across borders through its infrastructure.
We will use contractual, technical, and organizational measures required by applicable law. Where the law requires notice of an international transfer, separate consent, standard contractual clauses, a security assessment, or another procedure, we will complete the applicable requirement before the relevant transfer begins. Data processed only on your device and not uploaded is not transferred internationally by Hikage itself. However, a Merchant of Record, iCloud, Google, Microsoft Exchange, target websites, or other third-party services you use may conduct their own cross-border processing.
13. Data Security
We use measures proportionate to the processing risk, including:
- protecting local files through macOS user-directory permissions;
- storing the installation ID, non-exportable device-signing key, and minimal rollback anchor in the non-synchronizing Data Protection Keychain bound to the current device;
- using HTTPS, device-signed proof, and server-signed Access Records for license requests;
- verifying server-side notices received from a purchase system and applying appropriate idempotency and access controls to order and license-status changes;
- not storing activation codes in plaintext on the server, and using keyed digests for activation codes and IP identifiers in security events;
- restricting catalog redirects to same-origin HTTPS, checking content digests, and limiting redirect scope, response size, and image dimensions for website-icon requests;
- limiting staff and service-provider access to data.
The raw activity database currently has no additional Hikage application-layer encryption. Its protection depends on your macOS user account, file-system permissions, and any disk encryption you enable. We recommend enabling FileVault, using a strong login password, and protecting your device and backups.
Backup content likewise has no additional Hikage application-layer encryption, whether an older snapshot is stored as a complete .hikagedata archive or a current snapshot is stored as content-addressed objects. Its access controls and protection at rest and in transit depend on the iCloud account, file system, disk, network volume, or third-party synchronization service you select. Hikage uses digests and strict validation to detect incomplete or corrupted snapshots, but integrity validation is not encryption. Choose only a location that you trust and whose access permissions are appropriate.
No storage or transmission method can guarantee absolute security. If a data-security incident is likely to create a high risk to your rights or interests, we will take remedial action and provide legally required notices.
14. Changes to This Policy
We may update this Policy because of changes to features, data-processing practices, third-party services, purchase processes, or legal requirements. We will communicate material changes through the website, an in-app notice, release notes, a purchase contact email, or another appropriate channel and will state the new update and effective dates.
We will not use a policy change alone to retroactively apply previously collected data to a new purpose incompatible with the original purpose. Where applicable law requires consent, we will obtain it before the new processing begins.
The Merchant of Record used for a transaction, its policies, and the checkout data flow may change with the sales channel. We will identify the party actually used in the relevant checkout. This Policy does not designate an undisclosed platform as a permanent or exclusive provider.
15. Contact Us
For questions about this Policy, Hikage’s data-processing practices, or your personal-information rights, contact:
- Email: support@hikage.app
To help us process your request, use “Privacy Request” in the subject line and describe the type of request and its relationship to the relevant license, device, order, or email address.