Effective date: July 31, 2026
This policy explains what MFSoft LLC ("MFSoft," "we," "us") collects, why, and what we do with it — across the MFCommander application, the mfsoft.dev website, and the api.mfsoft.dev licensing service.
MFSoft LLC is the data controller for the processing described here. Contact: [email protected].
MFCommander never sends us your files. Not their contents, not their names, not their paths, not directory listings, not the contents of any remote server, bucket, container, or cluster you browse. Not your credentials. Not ever. There is no analytics SDK and no usage telemetry in the application.
The application does talk to us in two narrow, disclosable cases, both described in full below:
Both can be understood completely from Sections 3 and 4. Neither carries any information about what you use MFCommander to do.
These never leave your Mac and are never transmitted to us:
Activation is offline. Your license key is a signed token verified on your Mac against a public key built into the application. Activating requires no account, no sign-up, and no network connection. We do not create an account for you.
Validation is periodic and online. Once a license is active, MFCommander contacts api.mfsoft.dev/license/validate on a schedule so that licenses which were refunded, charged back, or revoked for fraud stop granting paid features.
| What is sent | Your license ID, and a SHA-256 fingerprint of your license key. Your IP address is visible to our server, as it is to any server you connect to. |
| What is not sent | File names, contents, or paths · directory listings · connection, host, bucket, or cluster details · credentials · device identifiers, serial numbers, or hardware fingerprints · usage, feature, or telemetry data · your name or email address |
| How often | At most once a day for the first 30 days after your license is issued; at most once a month thereafter |
| When | Opportunistically on launch or resume, when a check is due. Never blocking, never a dialog |
| Purpose | Enforcing the licence — detecting refunded, charged-back, or revoked entitlements (legitimate interests, GDPR Art. 6(1)(f); performance of contract, Art. 6(1)(b)) |
| Response | A signed statement of your license's status, cached locally so the answer survives being offline |
We do not use this to count devices, track installs, or profile you. The key fingerprint is a one-way hash; we send it instead of the key itself so a check never puts your key back on the wire. Our server records only the timestamp of the most recent successful check against your license record.
It fails open. If you are offline, the request times out, our server is down, or the response does not verify, nothing changes about your edition. MFCommander is fully usable offline indefinitely.
Turning it off: validation is part of how a paid license works and cannot be disabled separately. The Community edition never contacts the validation endpoint at all.
If update checks are enabled, MFCommander asks our update host whether a newer version exists. The request carries the application version and platform only.
It does not send your license key, license ID, entitlement status, email, device identifier, file names, connector metadata, or any application data. Disable it any time in Settings.
Purchases are processed by Polar Software Inc., our Merchant of Record. Polar takes your payment details directly — MFSoft never sees or stores your card number. Polar acts as an independent controller for its own tax and payment compliance; see Polar's privacy policy.
Polar passes us what we need to issue and support your license, which we store in our licensing service (Amazon DynamoDB, AWS us-east-1):
| Data | Why |
|---|---|
| Name and email address | Issue the license, email you the key, handle support and recovery requests |
| Order ID and edition purchased | Match the order to the license, prevent duplicate issuance |
| License ID, issue date, updates-window end date | The entitlement itself |
| License status (active / refunded / charged back / revoked) and revocation date | Answer validation checks |
| Timestamp of the last validation check | Support and abuse investigation |
Your license key is emailed to you through Amazon SES from sendmail.mfsoft.dev. We send transactional mail about your license and purchase. We do not add you to a marketing list because you bought something.
Waitlist and early-access signups. If you submit the signup form on mfsoft.dev we store your email address, the page or campaign you came from, the consent version shown to you, and the time. For abuse prevention, rate limiting, and knowing which countries to prioritize, we also store the IP address the request came from, a coarse location derived from it (country, region, city), and your browser user-agent string.
License recovery. If you use the recovery form, your email address is sent to our licensing service to look up and re-send your keys. We do not store a separate record of the request on the website.
Server logs. Our web servers keep standard request logs, including IP addresses, for security and troubleshooting.
No third-party analytics or advertising. As of the effective date above, mfsoft.dev runs no third-party analytics, advertising, or session-recording scripts, and sets no advertising or tracking cookies. If that changes, we will update this policy and the effective date before the change goes live.
Our licensing service runs on Amazon Web Services in the US East (N. Virginia) region. Our website runs on infrastructure we operate. Payments run through Polar. Transactional email runs through Amazon SES.
If you are in the European Economic Area, the United Kingdom, or Switzerland, your data is transferred to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and the equivalent UK and Swiss mechanisms, incorporated into our agreements with those providers.
We share personal data only with these service providers, under contracts that require them to protect it — or where we are legally compelled to, or must to establish or defend a legal claim. We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.
| Purchase and license records | For the life of the license, plus the period tax and accounting law requires us to keep transaction records (generally 7 years) |
| Waitlist signups | Until you unsubscribe or ask us to delete them |
| Web server logs | Up to 90 days |
| Support correspondence | Up to 3 years after the matter is closed |
Wherever you live, you can email [email protected] to access, correct, delete, or receive a copy of your personal data, or to object to or restrict how we use it.
If you are in the EEA, UK, or Switzerland, you have those rights under the GDPR or UK GDPR, plus the right to withdraw consent at any time and the right to lodge a complaint with your national supervisory authority.
If you are in California, you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal data, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
We respond within 30 days. We may need to verify your identity first — usually by confirming you control the email address on the account.
License keys are Ed25519-signed and verified locally. Traffic to api.mfsoft.dev and mfsoft.dev is encrypted in transit with TLS. Our signing keys are held in AWS Secrets Manager. Credentials for the servers you connect to stay on your Mac in the macOS Keychain, and we could not retrieve them if we wanted to.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.
MFCommander is developer tooling and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
We may update this policy. Material changes will be announced by an updated effective date at the top and, where the change affects what the application transmits, in the release notes for the version that introduces it. We will not begin collecting a new category of data from the application without publishing the change first.
MFSoft LLC — [email protected] — https://mfsoft.dev