Privacy

Your layouts stay home.

Your window layouts never leave your Mac. Here is the short, honest list of what does leave, exactly what it contains, and the first-party analytics the website uses. No cookies, no third-party trackers, no accounts.

The app
Your layouts stay on your Mac

Putback asks for one macOS permission, Accessibility, and uses it only to read the position and size of your windows and to move them. Your layouts (window frames, app identifiers, and display configurations) live in a local file that never leaves your Mac. You can inspect or delete it anytime at ~/Library/Application Support/Putback.

What does leave your Mac

A few small things travel to our servers so licensing, the trial, and stability can work. Here is every one of them, with its exact contents. There are no user accounts.

License activation

When you activate a paid license, Putback sends your license key, the device identifier described below, and the device name (so you can recognise your Macs when managing the license). Because a paid license carries your email, that identifier is linked to you until you deactivate the Mac. Nothing else.

Trial check-ins

During the 7 day trial, Putback checks in with a device identifier, the app version, and the macOS version. That is all it needs to count the trial days. No name, no email, no window contents. The identifier is a one-way hash of your Mac's hardware ID, so it does not carry your name, but it is deliberately stable: it survives deleting the app and reinstalling, which is what stops one Mac restarting the trial forever. The hardware ID itself never leaves your Mac.

Crash reports

If Putback crashes, the next launch sends a report with no name or email on it: the app version, the macOS version, the hardware model, and the crash stack. When macOS itself raised the error, the report also carries the text macOS wrote, which can name a window or another app that was involved. Home folder paths are stripped out on arrival, because those carry your account name. Never your layouts, and never anything you typed.

Update checks

Putback checks for new versions through Sparkle, the standard macOS update framework. That is a request to our update feed so the app can tell you an update exists.

The website
Analytics, without the tracking

The site uses first-party analytics only. No cookies, no advertising, no third-party trackers. Each page view records the page path, the referrer, an optional campaign tag from the link you followed, and your country (read from Cloudflare's edge, never stored alongside anything that identifies you).

It also records a visitor number that is a one-way hash of your connection details (IP address and browser) mixed with the current date. Because the date is part of the hash, the number rotates every day, so it cannot follow you from one day to the next. The IP address itself is never stored.

When you finish a purchase, the thank-you page sends one more first-party beacon that ties that sale to the same session-level source above (the link or referrer that brought you), so we can tell which channels actually pay off. It carries no new identifier, no amount, and no email. We also keep a short-lived tally of how many people are on the site right now. It reuses that same daily-rotating visitor number, counts only the last five minutes, and the rows are cleared out within the hour, so it is a live count, never a history.

Roadmap voting

Voting and commenting on the public roadmap use a random token saved in your browser's localStorage, so a vote counts once without an account. Clear the site's data and the token is gone.

Checking your monitor

If you use the monitor checker, what you submit is added to a running count: the display model, the verdict, and the settings it saw. It is stored as totals only, with no visitor number and no IP attached, so a submission cannot be traced back to you.

When we store your email

Only when you explicitly hand it over: signing up for the newsletter, sending a support ticket, asking to be told when a roadmap idea ships, or buying a license. If you never do any of those, we never have your email.

We also keep a log of the transactional email we send you, so we can tell whether your license key actually arrived. It records the address, the subject, whether it was delivered, and the license key it related to. It never records the body of a message.

Who helps us run it
The services we rely on

A handful of processors help run Putback. We keep the list short and name them plainly.

Stripe

Handles payments. Your card details go straight to Stripe and never touch our servers.

Resend

Sends transactional email: license keys, receipts, support replies, and the confirmations you ask for.

Amazon Web Services (SES)

Configured as an alternate email sender we can switch to if we ever need it.

Cloudflare

Hosts the website, stores the database, and routes inbound email to us.

Your data, your call
How long we keep it

Licenses, and the support tickets and email log attached to them, are kept for as long as the license is valid, because that is what lets us answer you and re-send a key years later. Crash reports and trial check-ins are kept while they are still useful for fixing bugs.

Website analytics rows are not deleted on a schedule, and we want to be straight about why rather than quietly leave it out: the visitor number in them rotates every day, so once a day has passed those rows cannot be tied to a person even by us. What is left is a count of page views. If you would rather we deleted anything at all that relates to you, ask, and we will.

Ask, or ask us to delete

To ask what we hold about you, or to have it deleted, either open a support ticket or email Peter directly at hi@petersindex.com. Either reaches the same person. Our data lives on Cloudflare infrastructure.

Last updated: August 25, 2026. Audited this page against what the servers actually store, and corrected it where the two disagreed. The trial identifier is described as what it is, a stable hash of your Mac's hardware ID rather than an anonymous one. Crash reports now say that a macOS error can name a window or another app, and home folder paths are stripped on arrival. The live-visitor tally is cleared within the hour, not within minutes. Added the monitor checker, the transactional email log, and how long we keep things.

July 7, 2026. Rewrote this page around the honest split between what stays on your Mac and what leaves, named every processor, and noted the purchase-confirmation beacon and the live-visitor count.