Privacy policy
Last updated 31 August 2026
Floodtide is made by an independent developer trading as Bhop Studio ("we"). Bhop Studio is a trading name, not a registered company. This policy covers the Floodtide app for macOS and this website. The short version: the app works without an account, everything it sends home is either anonymous or something you typed and chose to send, and we never sell or share data for advertising.
Questions or requests: raf@bhopstudio.com. The request-by-request technical breakdown lives on the docs page.
What the app sends, and when
Nothing, until you choose. Floodtide scans your Mac locally. The list of your installed apps stays on your Mac.
- Checking for updates. To find out what is current, the app fetches public sources directly: Homebrew's catalogue (formulae.brew.sh), app vendors' own update feeds, GitHub's API, Microsoft's update manifests and Apple's App Store lookup. Those servers see your IP address the way any website you visit does. Floodtide adds no account, identifier or app inventory to those requests.
- Anonymous usage line (optional, off until you say yes). If you agree on the consent screen, the app sends at most one line a day: a random install ID, whether the copy is in trial, licensed or lapsed, the Floodtide version, and broad update outcomes (source, installed, failed or skipped, and for a failure the step it stopped at, one word from a fixed list). It never includes your email, licence key, Mac identity, app names or error text. You can read the exact payload and turn this off in Settings, Privacy.
- Coverage sharing (optional, separate switch). "Share coverage data" sends a daily list of app name, bundle identifier, version and whether Floodtide covers it, so we can see what to support next. It carries no identity and is off by default.
- Coverage requests (only when you click). Requesting coverage for an app sends that app's name, bundle identifier and version, nothing else, after a dialog that shows you exactly what will be sent.
- Bug reports (only when you send one). A report contains what you wrote, the app version, and, if you attach it, the failure diagnostic the row shows you. Adding your email is optional; if you add it, we use it only to reply and to tell you when the fix ships.
- Floodtide's own updates. The app checks our server for new Floodtide versions using Sparkle. No system profile is attached.
- Licences. Activating a licence sends your key and an anonymised device identifier so the three-Mac limit works. Deactivating a Mac frees the seat. A signed receipt is kept in your Mac's Keychain so the app works offline.
What the website collects
- Anonymous visit counts. Page views, downloads and checkout starts are recorded against a hash of your IP address that changes every day, with the page, the referring site and your country. We cannot turn the hash back into you, and these rows delete themselves after 13 months. There are no third-party analytics or advertising scripts.
- Purchases. Stripe processes payment. Your card details never touch our servers. We keep your email address, the amount, and Stripe's transaction identifiers, because we have to: they are how licences are recovered, refunds are honoured and accounts are kept. Your licence key is emailed to you via Resend.
- Account sign-in. Signing in to the account page uses a one-time code emailed to you, then a session cookie so you stay signed in.
- Cookies. Two, both first-party: the session cookie above, and a 90-day referral cookie
(
ft_ref) set only if you arrive through someone's referral link, so their credit lands when you buy. No tracking cookies, no ad cookies.
What we never collect
Your installed app list without the coverage switch on. File paths. Screen contents. Contacts. Your location beyond country. Anything from Full Disk Access, Accessibility or screen recording, because the app never asks for those permissions.
Who processes data for us
Stripe (payments), Vercel (website hosting), Supabase (database), Resend (transactional email). Each receives only what its job needs.
How long we keep things
Website and download events: 13 months, deleted automatically. Purchase records: as long as accounting law requires. Licences and activations: while the licence exists. Bug reports: until resolved and a reasonable period after. The anonymous usage lines and coverage counts are not linked to you and are kept in aggregate.
Your rights
If you are in the UK or EU, you can ask for a copy of the personal data we hold about you (in practice: your purchase, licence and any bug reports you sent with your email), have it corrected or deleted, or object to processing. Email raf@bhopstudio.com and a person will read it. Deleting purchase records is limited by accounting law; everything else we can honour. You can also complain to the ICO (ico.org.uk).
Changes
If this policy changes in a way that matters, the change is dated here and noted in the release notes. We will not quietly widen what is collected.