Privacy policy
Effective date: July 12, 2026. Last updated: July 12, 2026.
This privacy policy explains what data Superset Files ("the app") and its publisher collect, why, and the limited circumstances in which the app communicates over the network. It is written to be read alongside the End-User License Agreement (the purchase/use terms) and does not replace it. Where the two documents overlap, each governs its own subject matter.
The publisher and data controller for Superset Files is Elena Maher, sole proprietor ("we", "us", "the Licensor"). For any privacy question, request, or concern, contact privacy@supersetfiles.com.
The short version
Superset Files is a local-first Mac desktop app. It opens folders you choose on your own Mac and lets you view and edit their contents. By design and by default:
- The app does not run analytics or telemetry.
- The app does not upload your files, index them on a remote server, or read files outside the folders you explicitly open.
- The app does not phone home to profile you or track your usage.
The app contacts the network in only three situations, each described below: (1) checking for updates, (2) crash reporting — which is off by default and only runs if you turn it on, and (3) purchase and license activation, which is handled by our payment provider. Remote images referenced inside your own Markdown will also load over the network if a document you open contains them, because that is your content, not something the app adds.
This posture is deliberate. Keeping file access local and telemetry off by default is a feature of the product, not an oversight.
Data controller and scope
This policy applies to the Superset Files desktop application distributed as a direct download for macOS, to this website (supersetfiles.com), and to the purchase and licensing flow associated with it. It does not apply to third-party websites, services, or content you may reach through documents you open, nor to the internal terms of the third-party processors named below, which are governed by their own privacy policies.
What we collect, and what we do not
Data the app does not collect
Unless you take an explicit action described in this policy, Superset Files does not collect, transmit, sell, or share:
- The contents of your files or documents.
- The names or paths of your files or folders.
- Your keystrokes, edits, search queries, or in-app activity.
- Behavioral analytics, usage metrics, session recordings, or advertising identifiers.
- Your location.
Your documents stay on your Mac. All file reading and writing is local and scoped to the folders you explicitly grant the app access to. The app does not scan your disk, does not index your files on any server, and does not access files outside the folders you open.
Data associated with a purchase
When you buy a license, purchase and license-key data (such as your email address, the license key issued to you, and billing details necessary to complete the sale) is processed by our payment provider acting as merchant of record. See "Third-party processors" below. We receive from that provider the limited order and license records needed to fulfil the sale, provide a support path, and manage your license entitlement. We do not receive or store your full payment-card details.
Data involved in license activation
When you activate your license in the app, the app sends your license key (and a minimal machine identifier used to count activations against your license) to the payment provider's licensing service to validate the key and record the activation. This exchange happens at purchase, activation, and validation time. It exists to confirm a valid license and to enforce the per-license activation limit; it is not used to profile you or track your usage of the app.
Diagnostic data (crash reporting) — opt-in, off by default
Superset Files includes an optional crash-reporting feature that is disabled by default. It is never enabled unless you deliberately turn it on in the app's settings.
When — and only when — you enable it, the app may send anonymous crash and diagnostic data (such as error type, stack traces from the app's own code, app version, and operating-system version) to our crash-reporting processor to help us find and fix defects. This feature is redacted so that it cannot transmit the contents of your files or your local file paths. It carries anonymous technical crash information only.
You can turn crash reporting off again at any time in the app's settings, which returns the app to its default, no-diagnostics state.
Update checks
To tell you when a new version is available, the app periodically checks an update feed for the latest release information. This is a version check: the app requests release metadata and, if a newer version exists, downloads the update in the background and applies it when you next restart the app. The update check does not send us your files, your file paths, or your identity.
Remote content inside your own documents
If a document you open references remote resources — for example an image included by URL inside a Markdown file — the app will load that resource over HTTPS so the document renders as written. This is a request to the third-party host of that content, made because your document asks for it. It is your content, not telemetry added by the app, and we do not receive or log it.
Why we process data, and our legal basis
We limit processing to what is necessary to:
- Sell you a license and issue a receipt (performance of the contract with you, handled by our merchant of record).
- Activate and validate your license and enforce activation limits (performance of the contract and our legitimate interest in preventing license misuse).
- Deliver software updates (legitimate interest in the security and correctness of the software you run).
- Diagnose and fix crashes, only where you have enabled crash reporting (your consent, which you may withdraw at any time).
We do not process your data for advertising, profiling, or resale, and we do not sell personal data.
Third-party processors
We keep our processor footprint small. The processors below act on our instructions or as an independent controller/merchant of record for the parts of the service they operate. Each has its own privacy policy that governs its handling of data, and you should review those policies for full details.
| Processor | Role | Data involved | When it applies |
|---|---|---|---|
| Freemius | Merchant of record; payment and license-key provider | Order and billing data, email, license-key and activation records | At purchase, and at license activation/validation |
| Crash-reporting provider (Sentry) | Diagnostic/crash processor | Anonymous crash and diagnostic data (no file contents, no file paths) | Only if you enable crash reporting; off by default |
| Update feed host | Distributes update metadata and build downloads | Standard connection metadata for a version check and download | When the app checks for or downloads an update |
| Netlify | Hosts this website; stores form submissions | The email address you submit to the release-notes form, and standard web-server connection logs | Only if you submit the release-notes form on the download page |
| GoatCounter | Website analytics (privacy-friendly, cookieless) | Aggregate pageview counts, plus the page visited, the referring page, and the browser, operating system, screen size, and country derived from your request. No cookies are set, no cross-site identifier is used, and your IP address is not stored. | When you visit pages on this website |
Our merchant of record. Our merchant of record is the seller of record for your purchase and is responsible for collecting and remitting any applicable sales tax or VAT and for issuing your receipt. For the direct-download launch, that merchant of record is Freemius. Purchase records, receipts, and any buyer-protection terms are governed by the merchant of record's own terms and privacy policy. Requests that concern the transaction itself — such as a receipt or an order lookup — route through the merchant of record.
Crash reporting. The crash-reporting processor only receives data if you have turned crash reporting on. The data is redacted to exclude file contents and local file paths, as described above.
Website analytics. This website — not the app — uses GoatCounter, an open-source, privacy-friendly analytics service, to understand aggregate traffic, such as which pages are visited and roughly where visitors come from. It sets no cookies, does not track you across other sites, and does not store your IP address or build a profile of you. The app itself runs no analytics or telemetry, as described in "The short version" above.
International transfers
We operate as a small independent publisher, and the processors above may process data in countries other than the one in which you live. Where your data is transferred internationally, it is transferred through these processors under the safeguards described in their respective privacy policies. Because the app itself keeps your files local, the only data that may cross a border is the limited purchase, license, and (if you enable it) anonymous crash data described in this policy.
Data retention
We retain the limited records we hold only as long as needed for the purpose we collected them, or as required to meet legal, tax, and accounting obligations:
- Purchase and license records are retained for as long as your license is active and for the period our merchant of record and applicable tax and accounting rules require after that. These records are held primarily by the merchant of record.
- Crash and diagnostic data, if you enabled crash reporting, is retained by the crash-reporting processor under its own retention schedule and is used only to diagnose and fix defects.
- Update-check connection metadata is transient and is not compiled by us into a profile of you.
We do not retain copies of your files, because we never receive them.
Your controls and choices
- Crash reporting is your choice. It is off by default. You can turn it on or off at any time in the app's settings. Off is the default state.
- Your files stay yours. You control which folders the app can access, and you can revoke that access at any time within the app. Removing a folder stops the app from reading it.
- Update behavior. Updates keep the app current and secure. If you do not want the app to run at all, you can quit or uninstall it.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of personal data we hold about you, to object to certain processing, to data portability, and to withdraw consent (for example, by turning off crash reporting) without affecting processing that already took place. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, contact privacy@supersetfiles.com. We will respond within the time required by applicable law. Because much of the data associated with your purchase is held by our merchant of record, some requests may need to be directed to, or coordinated with, that provider, and we will help you route the request appropriately. We may need to verify your identity before acting on a request, and we may decline or limit a request where an exception or obligation under applicable law applies.
Children
Superset Files is a productivity tool intended for general and professional use. It is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided personal data in connection with the app, contact privacy@supersetfiles.com and we will take appropriate steps.
Security
The app is built with a conservative security posture: context isolation is on, Node integration is off, the app runs sandboxed, and it applies a strict content security policy. All file access is local and limited to the folders you choose. The app has undergone two adversarial security reviews. No software can be guaranteed to be completely secure, and we provide the app without any warranty as to security except as required by law and as stated in the End-User License Agreement. You are responsible for keeping backups of your own files.
No warranty; limitation of this policy
This policy describes our data practices; it is not a warranty or a service-level commitment. We do not promise uninterrupted availability, support response times, or any guarantee regarding the update feed, the crash-reporting service, or the payment provider, each of which is operated on its own terms. To the maximum extent permitted by applicable law, the app and its associated services are provided "as is," and our liability is limited as set out in the End-User License Agreement. Nothing in this policy limits any right you have that cannot be limited or waived under applicable law.
Changes to this policy
We may update this policy from time to time — for example, if we change a processor or add a feature. When we do, we will revise the "Last updated" date above and, where a change is material, take reasonable steps to make the change noticeable. Where the law requires your consent for a change, we will obtain it before that change applies to you. Material changes are posted here with an updated date; we do not treat your silence or continued use of the app as acceptance of a revised policy.
Contact
Privacy and data requests: privacy@supersetfiles.com
Security reports: security@supersetfiles.com
General support: support@supersetfiles.com
Publisher and data controller: Elena Maher, sole proprietor.