Privacy
Last updated 9 October 2026
The short version
- The app sends us nothing about what you block, when, or how you use it. No analytics, no crash reports, no telemetry.
- The website counts page views with Cloudflare Web Analytics, which sets no cookies and leaves out visitors in the EU, the EEA, Switzerland and the UK. It has no advertising and no tracking across sites, and no cookies at all until you click Buy, or open a payment link for an order, and Paddle's checkout opens (section 3).
- When you buy, Paddle handles the payment. We never receive your card number, and we keep none of your payment details.
- We keep your email address, your licence, and a one-way hash and the model name of each Mac you activate — what a licence needs to work and to cover the right number of Macs.
- We never sell personal data, share it for advertising, or profile anyone.
1. Who is responsible
The controller of your personal data is Vitalii Kizlov, who makes Cloister: a sole trader registered in Poland, ul. Jana III Sobieskiego 112/14, 00-764 Warszawa, Poland, NIP 6751773289. For anything about your data, write to support@getcloister.app.
2. The app
What stays on your Mac. Your blocklists, schedules, session history and settings are stored on your Mac and never uploaded. Cloister's network content filter looks at connections on your Mac to decide whether they go to a blocked domain. That happens on the Mac; nothing about your traffic is recorded or sent anywhere. When Cloister blocks a site, nothing loads from us — the site simply fails to load on your Mac, so we never learn what you tried to open.
Cloister contacts a server of ours only when you activate, unlink, renew or refresh a licence, and when it checks for updates.
Activation, once per Mac. Cloister sends your licence key, a one-way hash of the Mac's hardware identifier, and the Mac's model name, such as “MacBook Air”. The hash is computed on your Mac and cannot be turned back into the identifier, which never leaves it. Our server returns a licence file signed for that Mac, and from then on Cloister checks it offline. Like any server, ours sees your IP address while answering; we do not store it with your licence.
Unlinking, renewing and refreshing. Unlinking a Mac sends your licence key and that Mac's hash, so the server can free the seat. Renewing sends your licence key, so the server can open the renewal's checkout. Refreshing a licence sends the same three things as activation, so the server can sign it again. Each of these requests, and activation, carries a user agent naming Cloister and its version.
Update checks. Cloister checks for new versions by downloading a small file that lists them, and downloads an update when you accept it. These requests carry what any download does — your IP address, the languages your Mac prefers, and a user agent naming Cloister, the update framework and their versions — and are logged by our host like any web request (section 3). They are not linked to your licence. The legal basis is our contract with you or, during a trial, our legitimate interest in keeping Cloister working (Art. 6(1)(b) and (f) GDPR).
Support details, only if you send them. Under General, Cloister's settings show one line about its background component — its version, its build and the user it runs as — with a Copy button, so you can paste it into an email to us. It holds nothing from your lists or schedules, and nothing is sent unless you send it.
When you first open Cloister, macOS itself checks its notarization with Apple. That is between your Mac and Apple, under Apple's privacy policy.
3. The website
Hosting. getcloister.app, our downloads and our licence server run on Cloudflare. Cloudflare processes each request — your IP address, the page asked for, the time and your browser's user agent — to deliver it and protect the service, and keeps logs under its own retention. We add no tracking to them and do not use them to profile anyone. We do look at Cloudflare's traffic statistics built from these logs — counts by page, country and browser, not individual requests. The legal basis is our legitimate interest in running and securing the site (Art. 6(1)(f) GDPR).
Analytics. Cloudflare Web Analytics counts page views on getcloister.app: which page, the site you came from, your country, your browser and device type, and how quickly the page loaded. It sets no cookies and stores nothing in your browser; Cloudflare discards your IP address at the nearest data centre instead of storing it, and says it does not follow individual visitors. We chose the setting that leaves Europe out: Cloudflare adds Web Analytics only to pages served from its data centres outside the EU, the EEA, Switzerland and the UK. Visitors in those countries are normally served from data centres there, so their visits are not counted. We look only at the totals, to see whether real people read the site. The legal basis is our legitimate interest in knowing how the site is used (Art. 6(1)(f) GDPR).
Currency. To show prices in your currency, the pricing section asks Cloudflare which country your connection comes from. The answer is used on the page and not stored.
Cookies and local storage. The site sets no cookies. If you pick light or dark mode, the choice is saved in your browser's local storage so it survives a reload. It never leaves your device.
Checkout. Nothing from Paddle loads until you click Buy, or open a payment link for an order (a getcloister.app/checkout/ address). Then Paddle's checkout opens on the page. It is run by Paddle, under Paddle's privacy notice, and brings the services a payment needs: Paddle's own servers, its payment processors and their fraud prevention, a Google payment frame that the payment processor loads, error monitoring and translation. Some of them set cookies of their own — a short-lived security cookie from Paddle's network, a fraud-prevention cookie from the payment processor, and a Google cookie from that payment frame, though Google Pay itself is not offered. They belong to Paddle and its providers, not to us, and we never see them.
4. Buying
Paddle is the seller of Cloister — Paddle.com Market Limited, or Paddle.com Inc. in the United States and Paddle.com (Canada) Ltd. in Canada — and processes your order as a controller in its own right. Your card, billing address, tax details and invoice are Paddle's to hold.
Paddle shares order data with us under its Data Sharing Addendum, as one independent controller to another. When you buy, Paddle's notice to our licence server gives the transaction number, what you bought, a Paddle customer number, and partial payment details: the card type, its last four digits, its expiry date and the name on it, or your PayPal email address. Our server discards the payment details without storing or logging them, then asks Paddle for your email address. We keep only that email, the transaction number and the Paddle customer number (section 5).
Paddle's dashboard also shows us your name, your email address, your country, any postcode, company name or VAT number you entered, the card type and its last four digits, and your purchase history. That is Paddle's record, held by Paddle. We look there only to handle a refund or a support request, and copy nothing from it anywhere else.
5. Your licence
We keep your email address, licence key, what your licence covers, the Paddle transaction number of each purchase or renewal, your Paddle customer number, and for each Mac you activate, its hash, its model name and the date. We use them to issue your licence, email you the key, activate and unlink Macs, keep to the number of Macs your licence covers, and handle refunds. The legal basis is performing our contract with you (Art. 6(1)(b) GDPR). Without an email address we cannot issue a licence, though once issued it can carry on without one (section 10).
We email you your licence key and, when needed, messages about your licence. We send no newsletters or marketing.
Mailjet sends these emails for us (section 7), as plain text: no images, no tracked links, and no record of when you open them. Mailjet adds a header that lets your mail app offer to unsubscribe you. We send no newsletters, so there is nothing to unsubscribe from, and pressing it can stop our later emails about your licence, such as your key sent again, from reaching you. If that happens, write to us.
6. Support
When you write to us, we use what you tell us to help you. The legal basis is our contract with you or, where there is none, our legitimate interest in answering you (Art. 6(1)(b) and (f) GDPR).
7. Who else handles your data
A few companies help us run Cloister:
| Company | For | Where |
|---|---|---|
| Cloudflare, Inc. | This website and downloads, counting page views, and the licence server and its database | Global network; US company |
| Mailjet (Sinch group) | Sending licence keys, as plain text with no tracking (section 5) | Servers in Germany and Belgium; Swedish parent company |
| Google Ireland Limited (Google Workspace) | Our mailbox: the mail you send to support@, security@ or licence@, and our replies | Google's servers worldwide; US parent company |
Cloudflare, Mailjet and Google act only on our instructions, under their data processing agreements, except that Mailjet also handles the emails it carries as a controller in its own right, to prevent spam and fraud, keep its network secure and meet its legal duties. Paddle is not on this list because it is not acting for us: it is the seller, and a controller in its own right (section 4). We disclose data to public authorities only when the law requires it.
8. Transfers outside the EEA
Some of these companies are based in, or use servers in, the United States. Transfers to Cloudflare rely on the EU–US Data Privacy Framework, under which Cloudflare is certified, and on the European Commission's standard contractual clauses in its data processing agreement. Google stores mail on servers worldwide, including in the US; its US parent, Google LLC, is certified under the same framework, and Google also relies on standard contractual clauses. Mailjet stores its data on servers in the EU; for any transfer to the US, such as to its support tools, its group's data processing agreement relies on the same framework and on standard contractual clauses.
9. How long we keep it
| Data | Kept |
|---|---|
| Licence | As long as the licence exists. Licences are perpetual, so until you ask us to delete it (section 10) |
| As long as the licence exists, or until you ask us to forget it (section 10) | |
| A Mac's activation | Until that Mac is unlinked, or the licence is deleted |
| A refunded or revoked licence | Three years after the refund, with your email kept only as a one-way keyed hash, so that repeated buying and refunding can be recognised — on our legitimate interest in preventing refund abuse (Art. 6(1)(f) GDPR), which you can object to (section 10) |
| Support emails | Three years after our last exchange |
| Mailjet's records of the emails it sends for us | Mailjet publishes no fixed period: its agreement promises a retention policy, and deletion within 90 days of our account closing |
| Hosting logs | As long as Cloudflare needs them to deliver and secure the site — Cloudflare publishes no fixed period; we keep no copies |
| Page-view counts | Full detail for 7 days, then a sample viewable for six months; we see totals only |
| Backups of the licence database | At most 30 days, so anything deleted is gone from them by then |
| Theme choice | In your browser, until you clear it |
10. Your rights
You have the right to see the data we hold about you, to have it corrected or deleted, to restrict how we use it, to receive it in a portable format, and to object to processing based on our legitimate interest. Write to support@getcloister.app from the address on your licence — or quoting your licence key, if we no longer hold your email; we reply within a month.
Deleting your data. Your licence is a contract we are still keeping — it lets you activate and unlink Macs, move the licence and receive security fixes — so we keep what it needs for as long as it exists. When you ask us to delete your data, you choose one of two things:
- Forget my email, keep my licence. We delete your email address and our link to your Paddle customer record. Your licence keeps working and can still activate Macs with its key, but we can no longer send you the key again, so keep the key somewhere safe.
- Delete everything, including my licence record. We delete the licence record, its orders, its Macs and our support emails with you. Cloister keeps working on Macs already activated, because they check the licence offline, but no new Mac can be activated, and we cannot undo it.
Either way, deleted data is gone from our licence database's backups within 30 days. Mailjet's records of the emails we sent you leave its systems on its own schedule, and mail we delete leaves Google's systems within 180 days at most, as Google's data processing agreement provides.
Paddle keeps its own copy of your order, as a separate controller, and answers for it separately. To ask Paddle to delete its data, use Paddle's deletion form; Paddle keeps some transaction records for five years.
You can also complain to the Polish data protection authority — Prezes Urzędu Ochrony Danych Osobowych (PUODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl — or to the authority where you live or work.
11. What we never do
We do not sell or share personal data for advertising, we do not profile anyone, and we make no automated decisions that affect you. Cloister is not directed at children under 16.
12. Security
Connections to our servers are encrypted. We collect only what a licence needs, never store the raw hardware identifier, keep the licence database behind two-factor authentication, and hold the key that signs licences as a secret on our server.
13. Changes
When this policy changes, the date at the top changes. If a new version of Cloister changes what it sends us, its release notes will say so.