Effective date: September 15, 2026
This policy explains what MFSoft LLC ("MFSoft," "we," "us") collects, why, and what we do with it — across the MFCommander application, the mfsoft.dev website, and our licensing service.
MFSoft LLC is the data controller for the processing described here. Contact: [email protected].
MFCommander never sends us your files. Not their contents, not their names, not their paths, not directory listings, not the contents of any remote server, bucket, container, or cluster you browse. Not your credentials. Not ever. There is no third-party analytics SDK. The application sends privacy-minimized usage statistics that are on by default and can be switched off in Settings.
The application does talk to us in three narrow, disclosable cases, all described in full below:
All three can be understood completely from Sections 3, 4, and 5. None carries files, file metadata, connection details, or credentials.
The services you connect to are a separate matter, and we are not in the middle of them. When you connect MFCommander to a server or a cloud account — including Google Drive — your Mac talks to that service directly. Section 6 describes that in full.
These never leave your Mac and are never transmitted to us:
Operation history stays on your Mac for the period you choose — 30 days by default — and is excluded from Time Machine backups. You can clear it, or limit it to the current session, in Settings › General. It is never sent to MFSoft or counted in usage statistics.
Activation is offline. Your license key is a signed token verified on your Mac against a public key built into the application. Activating requires no account, no sign-up, and no network connection. We do not create an account for you.
Validation is periodic and online. Once a license is active, MFCommander checks in with our licensing service from time to time, so that licenses which were refunded, charged back, or revoked for fraud stop granting paid features.
| What is sent | Your license ID, and a one-way SHA-256 fingerprint of your license key. Your IP address is visible to our server, as it is to any server you connect to. |
| What is not sent | File names, contents, or paths · directory listings · connection, host, bucket, or cluster details · credentials · device identifiers, serial numbers, or hardware fingerprints · usage, feature, or telemetry data · your name or email address |
| How often | Periodically, in the background. Never blocking, never a dialog |
| Purpose | Enforcing the licence — detecting refunded, charged-back, or revoked entitlements (legitimate interests, GDPR Art. 6(1)(f); performance of contract, Art. 6(1)(b)) |
| Response | A signed statement of your license's status, cached locally so the answer survives being offline |
We do not use this to count devices, track installs, or profile you. The fingerprint is a one-way hash; we send it instead of the key itself so a check never puts your key back on the wire. Our server records only the timestamp of the most recent successful check against your license record.
It never interrupts your work. Validation runs in the background, and MFCommander remains usable offline. How licensing itself behaves is governed by the EULA; this policy covers what the check transmits.
Turning it off: validation is part of how a paid license works and cannot be disabled separately. The Community edition does not use license validation at all.
Usage statistics are collected and stored separately, as described in Section 4. Nothing in that section changes what a validation check sends.
These are on by default, and you can switch them off. MFCommander sends a small daily summary of how the application is used, so we can tell which features earn their place and whether people keep using the app after installing it. It is the only way we learn anything about the Community edition, which never contacts our licensing service.
Turning it off: Settings › Privacy › Send privacy-minimized usage statistics. Switching it off stops collection immediately and discards anything not yet sent. Switching it back on generates a new identifier, unconnected to the old one.
Seeing exactly what is sent: Settings › Privacy › Show exactly what is sent displays the literal contents of the next report before it leaves your Mac.
| What is sent | A random installation identifier · report-format and policy-version numbers · the week usage statistics were first initialized on your Mac · your application version, macOS major version, and processor architecture · your edition (Community, trial, Pro, or Infrastructure) and, during a trial, which day of it · the number of days the app was active in the reporting period · counts of features used, rounded into ranges rather than exact numbers. Your IP address is visible to our server, as it is to any server you connect to; we do not store it. |
| What is not sent | File names, contents, extensions, or paths · directory listings · anything you searched for · connection, host, bucket, cluster, container, or share names · credentials · your license key, license ID, name, or email · device identifiers, serial numbers, MAC addresses, or hardware fingerprints · window titles · free-form text of any kind · any timestamp more precise than the day |
| How often | At most once a day, as a single summary. Never per action |
| Purpose | Understanding which features are used and whether people keep using the application, so development effort goes where it helps (legitimate interests, GDPR Art. 6(1)(f)) |
| Retention | Raw reports are kept for 90 days and then deleted automatically. Monthly aggregate totals that identify no installation are kept indefinitely |
The identifier is random and connects to no customer record. It is generated on your Mac, is not derived from your license, your hardware, or anything about you, and is never stored alongside your name, email, order, or license. The telemetry system has no field that joins a report to a customer.
Counts are ranges, not exact figures. A report says you opened between six and twenty files, not that you opened eleven. Exact numbers are more identifying than they look, and nothing we are trying to learn needs them.
Your right to object. Because we rely on legitimate interests rather than consent, you have the right under GDPR Article 21 to object to this processing at any time. The switch in Settings is how you exercise it, and it takes effect immediately — you do not need to contact us first. You can also email us to have reports already collected deleted.
If update checks are enabled, MFCommander asks our update host whether a newer version exists. The request carries the application version and platform only.
It does not send your license key, license ID, entitlement status, email, device identifier, file names, connector metadata, or any application data. Disable it any time in Settings.
MFCommander is a file manager, so most of what it does is talk to somewhere your files already live — a local disk, an SMB or SFTP server, an FTP or NFS share, an S3 bucket, a Kubernetes cluster, a Docker host, OneDrive, iCloud Drive, or Google Drive.
Every one of those connections runs directly between your Mac and that service. MFSoft operates no proxy, relay, gateway, mirror, cache, or backup in any of these paths, and receives nothing from them. We could not read what you browse there even if we wanted to, because it never reaches us.
Connecting Google Drive signs you in through Google's own consent screen, using OAuth. MFCommander never sees or stores your Google password. You can review or revoke MFCommander's access at any time at myaccount.google.com/permissions, which takes effect immediately and independently of anything in this application.
MFCommander requests the https://www.googleapis.com/auth/drive scope. A file manager's job is to show you the files you already have and act on the ones you choose, so it needs to see the Drive you are browsing — the same access Finder has to your disk. Google displays this request to you before you approve it.
| How your Drive data is accessed | Directly between your Mac and Google's servers over TLS, using the access token Google issued to your Mac. No MFSoft server is in this path |
| How it is used | Only to carry out what you asked for in the interface in front of you — listing a folder, viewing a file, searching within an open file, creating a folder, and the copy, move, and delete operations you invoke. Nothing else |
| How it is stored | Folder listings and viewed file content are held in memory for as long as you are looking at them, and the large-file viewer fetches only the portion on screen rather than downloading the file. Two exceptions put a copy on your Mac's disk, both of them things you asked for: previewing a document in the preview pane writes a temporary copy to your Mac's temporary folder — readable only by your account, deleted when you close the preview, and cleaned up at the next launch if the app was force-quit — and copying a file to a local pane writes it exactly where you chose. Neither leaves your Mac. MFCommander's operation history also stays on your Mac: it records the names and locations involved in file operations, never file contents, for the period you choose (30 days by default), and is excluded from Time Machine backups. You can clear it or limit it to the current session in Settings › General |
| How it is shared | It is not. Not with MFSoft, not with any third party. It is never sold, never used for advertising or any form of profiling, and never transferred anywhere except to the destination you pick for a file operation |
| Whether a human reads it | No one at MFSoft can. Your Drive content never reaches our systems, so there is nothing for a person here to read, and no support process that would involve looking at it |
| What MFSoft receives | Nothing. No file names, contents, metadata, or folder structure · no Drive or Google account address · no access or refresh token · no record that you connected Drive at all |
Your Google sign-in stays on your Mac. The access and refresh tokens Google issues are held in the same encrypted store as your other saved connection secrets, described in Section 2, protected by a key that lives in your login Keychain. Removing the connection in Settings › Connections deletes those tokens from your Mac.
Limited Use. MFCommander's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The same principles apply to every other connector. Hosts, share names, bucket names, cluster and container names, paths, and the credentials for all of them stay on your Mac as described in Section 2. Application usage statistics (Section 4) never include any of them: they record that a connection type was used, never which server, account, or file.
Purchases are processed by Polar Software Inc., our Merchant of Record. Polar takes your payment details directly — MFSoft never sees or stores your card number. Polar acts as an independent controller for its own tax and payment compliance; see Polar's privacy policy.
Polar passes us what we need to issue and support your license, which we store in our licensing service:
| Data | Why |
|---|---|
| Name and email address | Issue the license, email you the key, handle support and recovery requests |
| Order ID and edition purchased | Match the order to the license, prevent duplicate issuance |
| License ID, issue date, updates-window end date | The entitlement itself |
| License status (active / refunded / charged back / revoked) and revocation date | Answer validation checks |
| Timestamp of the last validation check | Support and abuse investigation |
Your license key is emailed to you through our transactional email provider. We send mail about your license and purchase. We do not add you to a marketing list because you bought something.
There is no signup form. mfsoft.dev does not have a waitlist, a newsletter, or a mailing-list signup, and no page asks for your email address. The only place you give us an email address is license recovery, below.
License recovery. If you use the recovery form, your email address is sent to our licensing service to look up and re-send your keys. We do not store a separate record of the request on the website.
Server logs. Our web servers keep standard request logs, including IP addresses, for security and troubleshooting.
Website analytics. We measure page visits, download intent, checkout starts, and where visitors came from, using analytics software we run ourselves on our own servers. It records the page you viewed, the referrer and any campaign parameters, your browser, operating system, device type and screen size, a coarse location derived from your IP address, a pseudonymous visitor identifier that is re-salted daily, and the named actions you take. It sets no cookies. Session replay is off, and your raw IP address is not retained in the analytics record. These records are deleted after 90 days.
We do not run third-party analytics, advertising, or session-recording scripts, and we set no advertising or tracking cookies. Because we host our analytics ourselves, no analytics company receives your visit at all.
Our licensing service and usage-statistics endpoint run on cloud hosting infrastructure in the United States. Our website and its analytics run on servers we operate ourselves. Payments run through Polar. Transactional email runs through an email provider in the United States. All of them are engaged under data processing agreements.
If you are in the European Economic Area, the United Kingdom, or Switzerland, your data is transferred to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and the equivalent UK and Swiss mechanisms, incorporated into our agreements with those providers.
We share personal data only with these service providers, under contracts that require them to protect it — or where we are legally compelled to, or must to establish or defend a legal claim. We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.
| Purchase and license records | For the life of the license, plus the period tax and accounting law requires us to keep transaction records (generally 7 years) |
| Raw application usage reports | 90 days |
| Monthly application-usage aggregates | Indefinitely; these contain no installation identifier |
| Raw mfsoft.dev website analytics records | 90 days |
| Web server logs | Up to 90 days |
| Support correspondence | Up to 3 years after the matter is closed |
Wherever you live, you can email [email protected] to access, correct, delete, or receive a copy of your personal data, or to object to or restrict how we use it.
If you are in the EEA, UK, or Switzerland, you have those rights under the GDPR or UK GDPR, plus the right to withdraw consent where a purpose relies on consent and the right to lodge a complaint with your national supervisory authority. For application usage statistics, which rely on legitimate interests rather than consent, you have the right to object under GDPR Article 21; switching off Send privacy-minimized usage statistics exercises that right immediately.
If you are in California, you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal data, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
We respond within 30 days. We may need to verify your identity first — usually by confirming you control the email address on the account.
License keys are cryptographically signed and verified on your own Mac. Traffic between MFCommander and our services is encrypted in transit with TLS. Our signing keys are held in a managed secrets store, separate from the systems that serve requests. Credentials for the servers you connect to stay on your Mac in the macOS Keychain, and we could not retrieve them if we wanted to.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.
MFCommander is developer tooling and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
We may update this policy. Material changes will be announced by an updated effective date at the top. Where a change affects what the application transmits, the release notes for the version that introduces it are our primary disclosure channel, not an optional courtesy. We will not begin collecting a new category of data from the application without publishing the policy change and those release notes first.
MFSoft LLC — [email protected] — https://mfsoft.dev