Privacy
Last updated · August 2026
1. Who is responsible
The controller is the operator listed in the imprint (Dustin Deunert – deunert.io). This policy explains how we process personal data worldwide. Where the GDPR or UK GDPR applies, it is intended to satisfy those requirements.
2. This website
The site is served by Cloudflare, Inc. (USA), which processes standard access/connection data (browser, operating system, referrer, IP address, timestamp) in order to deliver and cache the site’s content, to protect it against DDoS attacks and other abuse, and to maintain its security and availability. Legal basis: Art. 6(1)(f) GDPR; US transfer on the EU Standard Contractual Clauses and the EU–U.S. Data Privacy Framework. The domain is registered through Hostinger, which does not serve visitor traffic.
- Analytics — Umami: no cookies are set and we send no cross-site identifiers. Besides page views we record interaction events — which buttons are clicked, how far down the page visitors scroll, which FAQ entries are opened — so we can tell which parts of the page are useful. The only details attached to an event are the language, the section or button involved and, on the buy link, the currency shown; none of them describe you, and none is taken from the address you arrived on.
- What happens to your IP address: we never see one — no IP address appears anywhere in our analytics dashboard. Umami documents that it does not store raw IP addresses either: it hashes the address in memory together with a salt that rotates, then discards it. That hash is what makes counting unique visitors possible at all, so visits from the same device can be grouped together for as long as that salt lasts. Once the salt rotates the link is gone and cannot be recomputed. Nothing follows you to another website and no lasting profile is built. Legal basis: legitimate interests (Art. 6(1)(f) GDPR), which is why we do not ask for consent.
- Fonts are self-hosted — no third-party font requests.
- Email — Google (Gmail): if you email us, Google processes the message as our email provider. We process the correspondence on the basis of our legitimate interest in answering enquiries and staying in touch with users (Art. 6(1)(f) GDPR); where it concerns preparing or performing a contract, Art. 6(1)(b) GDPR may apply as well.
3. Purchases
Checkout runs through Polar as merchant of record. You provide your payment and billing details directly to Polar, which processes them under its own privacy policy to complete the sale, issue an invoice and handle VAT.
From Polar we then receive, and can see in their merchant dashboard: your name and email address, your billing address, the order and invoice number, the product bought, the amount and tax, the date, the payment status and the type of payment method, your license key, and how many times that key has been validated. We use it to issue and support your license, to answer you if you write to us, and to keep the records tax law requires.
Your card details never reach us. They go to Polar and its payment providers, and we have no access to them at any point.
4. The app
Rungeist reads your own running processes (via lsof and ps) and, when Docker Desktop is running, your local Docker containers (via the docker CLI) — never file contents, environment variables or arguments — and writes a single local snapshot file shared with its widget. None of that leaves your Mac. The app makes only two kinds of network connection:
- License activation with Polar to activate and periodically re-validate your key. This sends your license key, an activation identifier and a non-identifying activation label so you can tell your own machines apart — your Mac’s model identifier plus a random suffix (for example “MacBookPro18,3 · 7f3a”). Your computer name is never sent. Legal basis: Art. 6(1)(b) GDPR (performance of the license contract).
- Update checks via the Sparkle framework, an open-source component of the Sparkle Project. Sparkle requests the update feed from
dl.p0rt.app, hosted on Cloudflare, and transmits your IP address and, in the User-Agent header, the Rungeist and Sparkle version numbers; update packages are downloaded from the same host. Neither your macOS version nor a system profile is sent. Legal basis: Art. 6(1)(f) GDPR (keeping the Software secure and up to date).
5. How long we keep data
- Website access data: we keep no server access logs of our own. Cloudflare processes connection data as described above and deletes it according to its own retention policy.
- Analytics: Umami stores analytics data without a persistent identifier or a raw IP address. The rotating hash described in section 2 groups visits only for as long as that salt lasts; once it rotates, nothing remains that could be traced back to you, so there is no visitor-level record left to retain or delete.
- Email: messages are kept as long as needed to handle your enquiry and deleted afterwards, unless statutory retention periods require otherwise — in particular §§ 257 HGB, 147 AO, which can require commercially or fiscally relevant correspondence to be kept for up to 10 years.
- License data — Polar: Polar keeps the purchase and transaction records under its own retention obligations and privacy policy. That is Polar’s decision, not ours.
- License data — us: we keep the order and license information described in section 3 for as long as we need it to administer your license and support you, and after that only where the law requires it — in particular the tax retention periods in §§ 257 HGB, 147 AO.
6. Who else sees your data
Depending on what you do, your data may be processed by:
- Polar Software, Inc. and its payment providers — purchase, invoicing, VAT and license issuing.
- Cloudflare — website hosting, CDN, the download host and security.
- Google — email hosting, if you write to us.
- Umami — website analytics.
We do not sell your data or use it for advertising. Personal data may also be disclosed where required by law or where necessary to our service providers acting on our behalf.
7. Your rights & contact
You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interests. For any request, write to info@rungeist.com.
You may also lodge a complaint with a supervisory authority — ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin.