Privacy
Last updated August 2026
This is the whole list. It is short because the app was built to need very little, and because a privacy notice that enumerates everything is only worth writing if the list is actually complete.
Flash Media Solutions, Inc. is the data controller. Use the contact form about anything on this page.
What the app sends
- A one-way fingerprint of your Mac. A salted SHA-256 hash of a hardware identifier. It is sent so a 14-day trial is 14 days rather than 14 days per reinstall, and so we can count how many Macs a license is used on. It cannot be reversed into your hardware identifier, your name, or anything else about you. We never receive the identifier itself.
- Your Mac’s name — only once you sign in or buy. It is display text so you can tell your machines apart when releasing one. It is encrypted at rest.
- Your email address and name — only if you buy or sign in. Stripe collects them at checkout and passes them to us. Both are encrypted at rest.
- A check for a new version. The app asks your permission before the first one. Declining does not affect anything else.
What the app never sends
- Anything you play, listen to, or type.
- Any keystroke. The app acts on volume up, volume down and mute, and reads nothing else.
- Your speakers’ names, your network, or anything discovered on it.
- Analytics, telemetry, crash pings, or any third-party tracker. There are none in the app and none on this website.
What this website stores
- Your license record: name, email, seat count, order reference and the license itself. Name, email and license are encrypted at rest; the email is additionally indexed by a keyed hash so we can find your record without storing a searchable address.
- Your activations: the machine fingerprint above, your Mac’s name, and when it was last seen.
- Trial records: a machine fingerprint and a start date. No email, no name.
- Sign-in codes: a hash of the six-digit code and an expiry. They are deleted as they are used and expire in ten minutes.
- Payment references, but never payment details. Alongside your license we keep the Stripe reference for each payment: the original purchase, any extra Macs you add later (with the seat count and amount), and — briefly — a note when a refund or dispute arrives before the payment it belongs to has finished processing, so the two cannot pass each other. These are references INTO Stripe; card numbers and bank details never reach this site at all.
- A count of page views, attached to nobody. The web server records which page was requested, when, and which language it was shown in. Your IP address, your browser’s identity and the page you came from are all discarded before the line is written — not stored and then ignored, but never written down. The result cannot be tied to you, joined back into a visit, or turned into a profile. It answers “how many people read the setup guide” and nothing else.
- Support conversations, briefly. A message you send us — through the contact form, by email, or with “Report a Problem” in the app — is kept, encrypted, together with our replies so the conversation holds together. Once it is answered we delete the whole thread 30 days after its last message; while it is still waiting on a reply from us we keep it until we have replied, and in no case longer than 7 years. A report sent from the app also carries what it shows you on screen before you send it: the app and macOS versions, your Mac’s model identifier, whether the app has the permissions it needs, the name of your audio output and of your speaker, whether you are on a trial or a license, and the app’s recent log. It never carries your license key, your password, anything you typed elsewhere, or anything about what you were listening to. Replies are written by a person; an AI tool running on the same infrastructure that already carries the mail may translate the message and suggest a first draft, and nothing you write is used to train anything. The one exception to the deletion schedule: a conversation tied to a dispute, a chargeback or abuse may be kept until the matter is closed.
- A web session while you browse these pages. Visiting this site creates a short-lived session row holding your IP address, a browser identifier and a timestamp. It exists so the contact form and the checkout can be protected against cross-site request forgery. There is no way to run those safely without it, and it is deleted automatically after two hours of inactivity.
We do read one report from Google: Search Console tells us which phrases showed this site in search results, and how often each was clicked. That is Google reporting on its own search results, not this site watching you — it needs no code on the page, sets nothing in your browser, and cannot see anyone who did not arrive from a Google search. The figures are counts of phrases, never of people, and Google withholds rare searches entirely so that no query can be traced back to one person. It is the only reason we can answer “what were people looking for”, because Google has removed that from the referrer since 2011.
Cookies
Three, and you can check that number yourself in your browser’s developer tools.
optically-session— the browsing session described above. Expires after two hours.XSRF-TOKEN— the anti-forgery token that makes the contact form and checkout safe to submit. Expires with the session.locale— the language you picked, so the site does not forget it on the next page. Nothing but a language code, kept for a year.
There is no analytics cookie, no advertising cookie, and no third-party cookie of any kind, so there is nothing here to ask your consent for and no banner to click past. The first two are strictly necessary to run the site; the third only remembers a choice you made on purpose.
The API the Mac app calls is separate and stateless: it sets no cookie, creates no session, and never records your IP address next to your machine fingerprint. This website sets no analytics or advertising cookies of any kind, and there is no tracker on any page. That is not only a promise: the site sends a Content-Security-Policy that tells your browser to refuse any script, image, font or connection from anywhere but this domain, so nothing here can load a third-party tracker even by mistake.
Who else is involved
- Stripe processes payments and holds your card details. We never see them. Stripe’s own privacy policy governs what it does with your data.
- Our email provider delivers your receipt, your license and any sign-in codes.
That is the complete list of third parties. There is no analytics provider, no CDN tracking you, and no advertising network.
Why we are allowed to hold it
For license and purchase records: because we need them to give you what you bought and to keep the tax records the law requires of us. For trial records: our legitimate interest in offering a trial that can only be taken once. We do not rely on consent for anything except the update check, which the app asks for separately and which you can refuse.
How long we keep it
License and purchase records for as long as your license is valid and then for as long as tax law requires us to keep sale records. Trial records for two years after the trial ends. Sign-in codes are deleted within an hour of being issued, used or expired. Web sessions expire after two hours. The last three are done by a scheduled job that runs daily — not by hand, and not only when someone remembers.
Your rights
You can ask us for a copy of what we hold about you, to correct it, or to delete it. Ask through the contact form, using the address you bought with, and we will action it within 30 days, free of charge.
One honest caveat about deletion: your license is a signed file on your own Mac and keeps working whatever we delete at our end. Deleting your record removes your name, address and seat list from our database — it does not and cannot switch off software you already own.
The second caveat is the law’s, not ours: we have to keep a record of the sale itself. So erasing you removes your name, your address, the license file, your Macs’ names and their fingerprints, and leaves behind an order reference, an amount and a date that no longer point at a person. Tax rules require that much, and Stripe keeps its own copy of the payment regardless of what we do. What stops afterwards is our ability to recognize you: no signing in, no managing your Macs, and no re-sending your license, so keep a copy of the email first.
If you are in the UK or EU you may also complain to your data protection authority.
Children
Optically is not directed at children, and we do not knowingly collect anything about anyone under 16.
Changes
If this notice changes materially we will date it at the top. We will not quietly widen what the app sends: if that list ever grows, the app itself will say so before it does.