Privacy Policy

MIDItoAppleScript keeps profiles on your Mac and contacts Gumroad to check a licence only after you enter a key.

Last updated 18 September 2026

The developer and data controller

Soundeschön
The trading name of Thomas Lawton
Developer of MIDItoAppleScript
Sole trader in the United Kingdom

Postal and service address:
49 Station Road
Polegate
East Sussex
BN26 6EA
United Kingdom

Email: hello@miditoapplescript.com

The developer is the controller of the personal data he handles.

The app

The app does not use analytics, crash reporting or telemetry. Neither version uses error reporting.

MIDItoAppleScript does not upload your MIDI activity, profiles or scripts. Scripts you run can send data according to their own instructions.

Only after you enter a licence key, version 2 posts three fields to https://api.gumroad.com/v2/licenses/verify: product_id, license_key and increment_uses_count. On activation, increment_uses_count is true, asking Gumroad to add one to the activation count for your key. For every other check, the field is false and the count does not increase. Repeated activations on the same Mac count separately. The developer sees the count in Gumroad and uses it only to spot a key shared beyond the licence. Gumroad also sees the requesting IP address. Trial use never contacts Gumroad.

Version 2 checks at launch if 24 hours have passed since the last successful licence check. While open, version 2 checks hourly whether that daily check is due. 'Activate' and 'Check Now' also request a check.

Version 2 reads only whether Gumroad recognised the key, whether Gumroad has disabled it and whether the purchase was refunded or charged back. Nothing else in Gumroad's reply is read, stored or logged, including the purchase email address. The check is part of the licence contract.

A failed request leaves the licence state unchanged. Script running continues offline for 90 days from the last successful check, then stops until a check succeeds.

Version 2 fetches https://www.miditoapplescript.com/version2.json at launch if at least 24 hours have passed since the last successful fetch, including during the trial. It also fetches this file when you choose 'Check for Updates…'. Version 1 fetches https://www.miditoapplescript.com/version.json at launch under the same 24-hour rule, with no manual check. Neither version checks again automatically while left open. These update requests carry no identifier. Cloudflare, the website host, sees an IP address and user agent.

Version 2 stores plain JSON in ~/Library/Application Support/MIDItoAppleScript/state.json: the active profile identifier, launch profile setting, last update-check time, version 1 import status, names of MIDI devices seen by the Mac, whether that device list has been seeded, and trial start time. After activation, the file also holds the licence key in plain text, the last successful licence-check time and any reported refund or chargeback status. The key is not stored in the Keychain.

Version 1 stores its mappings and its last update-check time in ~/.midi_app_profile.json. Neither file is ever uploaded, and the version 2 state file stays outside exported profiles. The state file contains no email address, name, order number or machine identifier.

The website

Cloudflare hosts the website. The website uses no analytics, crash reporting, telemetry or error reporting.

Downloads are counted as a running total per download route, with version 2 downloads also counted per calendar day. That counter records no address, no IP and nothing that identifies who downloaded. The counter stores whole numbers only, with no cookies or user agents. Downloads count when the whole file has been sent, including repeats by the same person; partial requests, HEAD requests, self-declared crawlers, link previews and transfers cut off early do not count.

The contact form sends your name, email, subject and message through Resend to the developer's inbox. Optional macOS version, app version and MIDI device fields are included if supplied; 'Report a Bug…' in the menu bar menu or app, and 'Request a Feature…', open the contact page with your macOS version, app version and MIDI device in the page address. These values prefill the form and reach Cloudflare when the page loads, before you send a message. Messages are kept to continue the conversation and deleted on request. Answering messages is the developer's legitimate interest.

Gumroad, Resend and Cloudflare are US companies. For transfers to the United States, Gumroad relies on standard contractual clauses, Resend is certified under the EU-US Data Privacy Framework and its UK Extension, and Cloudflare is certified under the UK Extension and includes the UK International Data Transfer Addendum in its terms. Copies of these safeguards are available from each company's terms, including Gumroad's privacy policy.

Buying through Gumroad

Gumroad handles card and billing details, email addresses and country information for tax as merchant of record. See Gumroad's privacy policy.

The developer sees your purchase email address, date, amount, refund state and activation count, for administering the purchase and licence contract. Purchase records are kept for as long as UK tax record rules require.

Your rights

Contact hello@miditoapplescript.com to request access, correction or deletion of your personal data, or to object to its use. These rights depend on the circumstances. Tax records may need to be kept. You can complain to the Information Commissioner's Office.

Changes to this policy

The date above changes when this policy is updated.