Effective 8 September 2026. Replaces the version of 4 September 2026.
DeskSay is a menu bar app that names your desktops. It does not need to know anything about you to do that, so it collects almost nothing. This page lists everything, rather than describing it in general terms.
Your voice never leaves your Mac. Speech recognition uses the on device engine built into macOS, the same one dictation uses, and the app refuses to run recognition any other way. Nothing is recorded, nothing is uploaded, and voice works with the network switched off. There is no account, and the app itself has no analytics.
The website is a separate thing, and it does use analytics. Section 6 says exactly what that means.
Lumiere Media, Inc., which makes DeskSay, is the controller of the data described here. You can reach us at support at desksay.com.
Everything DeskSay makes for you is a file in your own user folder, under Library/Application Support/DeskSay. Your desktop names and colours are one JSON file, each note is a rich text file with a small metadata file beside it, and time records are one SQLite database. None of them is ever transmitted, and deleting the folder removes them.
The Board can show a small picture of the windows on each desktop. That needs macOS Screen Recording permission, which the app asks for once and only when you turn the pictures on. The pictures are taken from the window server when the Board opens, are held in memory while the app runs, and are never written to disk or sent anywhere. Without the permission the Board shows app icons instead.
The licence token the app keeps in its preferences records the email address the key was bought with, so Settings can show you which purchase this Mac is on. It stays on the Mac.
The app talks to two hosts of ours and nothing else: the licence server, and desksay.com for updates.
| When | What is sent | Why |
|---|---|---|
| First run | A one way hash identifying the Mac, and the app version | To start and time your 14 day trial, and to stop one machine restarting the trial by reinstalling |
| Redeeming a voucher | The voucher code and the same hash | To extend the trial once per code per Mac |
| Activating a licence | The hash, your licence key, and your Mac's name as set in System Settings | To check the key is valid and to count this Mac against the number of Macs on your subscription |
| About once a week while licensed | The hash, the key, and the activation id the server gave this Mac | To confirm the subscription is still paid, and to let a cancelled or refunded key stop working |
| Deactivating this Mac | The key and the activation id | To free the seat for another Mac |
| Once a day | A request for desksay.com/appcast.xml, carrying the app name and version as any web request does | To find out whether a newer version exists |
The machine identifier is a SHA-256 hash of the Mac's hardware UUID, not the UUID or a serial number. It cannot be turned back into anything about you or your hardware, and it is the same after a reinstall, which is what stops the trial being restarted. After starting a trial or checking a licence the app also asks the server for the time, with nothing attached, so a Mac with a wrong clock is not locked out.
The update check uses Sparkle, the same framework most Mac apps outside the App Store use. System profiling, the option that would report your macOS version and hardware, is not turned on, so what reaches desksay.com is the request itself and the app version. Both update checking and automatic installing can be switched off in Settings.
Nothing else in the app talks to our servers. Your desktop names, notes, time records and automations stay on your Mac and are never transmitted.
Payment is handled entirely by Stripe, on Stripe's own checkout page. We never see or store your card details. From a purchase Stripe tells us your email address and its own identifiers for the checkout, the payment, the subscription and the customer record, plus which plan and how many Macs you chose. We generate your licence key and keep it alongside those. As Macs are activated we keep, for each one, the hashed machine identifier, an activation id we make up, the Mac's name, and when it was activated and last checked in.
Your key is shown on the thank you page, which asks our licence server for it using the checkout id in Stripe's redirect link. When our email sending is configured, the same key is also emailed to you through Resend from hello at desksay.com. The email address is used for that, and to answer you if you write to us. It is not used for marketing.
Changing the number of Macs, updating a card or cancelling happens through Stripe's customer portal, linked from desksay.com/manage. Anything you enter there goes to Stripe, not to us; we learn of the result through Stripe's notifications.
The same page can list the Macs your key is active on and remove one. To prove the key is yours it emails a link to the address you bought with (through Resend, as above); the link is signed, works for one hour, and is not stored. Asking for a link with an address that bought nothing sends nothing and is not recorded. An AppSumo buyer gets the same link from the AppSumo activation page instead, since AppSumo has just confirmed who they are.
A Product Hunt promotion code is a Stripe coupon applied on Stripe's checkout page. Using one collects nothing beyond what an ordinary purchase does.
Bought on AppSumo. AppSumo is the seller and handles payment and refunds; we never see your card or, unless you write to us, your email address. AppSumo gives your purchase a licence id, tells our licence server about it as it is bought, activated, upgraded or refunded, and sends you to desksay.com/appsumo with a single-use code. That page exchanges the code with AppSumo, which confirms the licence id, and our server issues a DeskSay key tied to it. We keep the AppSumo licence id, the tier, the key we issued and its status. Each notification AppSumo sends is kept in full as a ledger for support, so a disputed activation or refund can be traced; the entries hold the licence id, the event and its time, and no name or address. We keep them for as long as the licence record, and delete them with it.
Settings and the welcome guide have a switch called "Send anonymous crash reports". It is off unless you turn it on, and in the current version nothing reads it: there is no crash reporting code in the app, so no crash report is collected or sent today, whichever way the switch is set. The switch is there so that if reporting is added, it will be opt in from the start. If that happens, a report will contain the crash itself, the app version and the macOS version, and this page will change with it.
desksay.com uses Google Analytics 4 on every page, including this one. We use it for one thing: to see which pages people find useful and which ones they leave, so we know what to rewrite. It is measurement ID G-FJYKJEYCWN.
Google sets its own cookies in your browser to do that. They are named _ga and _ga_ followed by a property code, they live in your browser rather than on our server, and their job is to let Google tell a returning browser from a new one. An earlier version of this page said no cookie was set, which was written before Google Analytics was added and is no longer true.
What Google receives on a visit is the page you looked at, the link that sent you, an approximate location worked out from your IP address, and general facts about your browser, device and screen. Google's enhanced measurement is on, so it also records scrolls, clicks on links that leave the site, and file downloads. We see all of it as counts and averages in Google's reports. We do not use it for advertising, we do not sell it, and we never try to work out who an individual visitor is.
Vercel's own Web Analytics also runs on the home page and the thank you page. It is how we counted visits before Google Analytics was added, and it reports page views without naming anyone.
There is no cookie banner on this site, and the analytics script loads without asking you first. If you would rather not be counted, any browser or extension that blocks Google Analytics stops the script loading, and Google publishes its own opt out add on. We do not act on the Do Not Track header, because we do not read it.
Separately from analytics, we keep a record of each download. That record is a timestamp, a short label for where the visitor came from such as producthunt, a two letter country code that Cloudflare works out from the request, and whether the browser said it was on a Mac. The download record holds no IP address, no browser fingerprint and no advertising identifier, and it is not joined to anything in Google Analytics. Known crawlers are not counted.
The live Board on the home page and the voice card next to it are animations that run in your browser. They send nothing anywhere, and the voice card does not use your microphone. The Contact button opens a small panel that shows our address and copies it to your clipboard when you ask, and that is all it does. Three pages call our licence server: the thank you page after a Stripe purchase, to fetch your key; the AppSumo activation page, to exchange AppSumo's code for a key; and the manage page, to list and remove the Macs on a key.
The site, the download file and the launch videos are static files served by Vercel. Each page also loads its fonts from Google Fonts, which shows Google your IP address in the course of serving the font.
| Service | What it handles |
|---|---|
| Stripe | Payments, card details and the customer portal linked from desksay.com/manage; we never receive card details |
| AppSumo | Sells the lifetime licence, takes payment and handles refunds; issues the licence id and reports its status to our server |
| Cloudflare | Runs the licence server (Workers) and its database (D1): trials, licences, activations, the AppSumo notification ledger and download counts |
| Resend | Sends your licence key email, and the manage link when you ask for one |
| Vercel | Serves the website, the download and the videos, and counts visits on two pages |
| Google Analytics on the website, and the web fonts the pages load |
We do not sell your data and we do not share it for advertising. There are no third party trackers in the app. On the website there are: Google Analytics on every page, Vercel's visit counter on two of them, and the Google Fonts stylesheet each page loads.
Licence records are kept for as long as the licence exists, because that is what makes the key work on a new Mac years from now, and for as long as our accounting obligations require afterwards. An activation record is deleted when you deactivate that Mac or remove it from the manage page, and every activation on a key is deleted when the key is refunded, disputed or its subscription ends. The AppSumo notification ledger is kept as long as the licence record it concerns. Trial records are kept so a trial cannot be restarted indefinitely. Download counts are aggregate and contain nothing personal. Google Analytics data sits with Google and is deleted on the retention period set on the property; the cookies Google sets expire on Google's own schedule, and clearing your browser's cookies removes them at once.
You can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted. Email support at desksay.com and we will answer within 30 days. Deleting your licence record means your key will stop activating on new machines, so we will confirm that with you before doing it.
If you are in the UK or the EU, our lawful basis is performance of the contract for the licence and activation data, and our legitimate interest in preventing abuse for the hashed machine identifier and the trial record.
DeskSay is not directed at children and we do not knowingly collect data from anyone under 13.
If this policy changes, the effective date at the top changes with it, and the current version is always at desksay.com/privacy. This version adds AppSumo purchases and the ledger of AppSumo's notifications, the manage page and its emailed link, and lists every page that calls the licence server.