Privacy

Short version: the app analyses files on your machine and sends the licence server nothing but your licence.

What Thyme sends

When the licence server is reachable, Thyme posts your licence text to it to confirm it is still valid, and records the answer locally so it can work offline afterwards. The request contains the licence text. It does not contain file names, file contents, hashes of either, or any usage statistics.

The app also reports a hardware fingerprint during activation. That value is derived from a machine identifier — on macOS the host UUID, on Linux the systemd machine id, on Windows the registry MachineGuid — hashed with BLAKE2b. It is used to count how many machines a licence is running on, and no part of it can be reversed back to the original identifier.

What this website collects

When you buy, Stripe processes the payment and gives us your email address and country so the licence can be delivered and support can find your order. We store the email, the order, and the issued licence. Card details never reach this server.

The site sets one cookie of its own, and only to protect the checkout form against cross-site request forgery. It also loads Google Analytics (gtag.js, which sets its own cookies) to count visits — but that script is left off the checkout and licence pages, whose URLs carry a one-time token, so those are never reported to it. Other than Analytics there is no third-party request: no advertising pixel, and fonts are served from this host rather than a CDN.

Retention

Orders and issued licences are kept so that a lost licence can be re-sent. Request log lines are kept for a short period for abuse control and then discarded. Lookup links are single-use and expire in 30 minutes.

Contact

Any question about this, or a request to delete an order record: neocanable@gmail.com.