Legal
Privacy Notice
What we collect, why, and who else sees it. The short version: the website sets no cookies and runs no analytics, your logs never leave your machine, and the only thing localsink ever sends us is a commercial license key, with the version and platform it is running on.
Last updated
Who we are
localsink, LLC, trading as localsink, publishes localsink and operates localsink.io. We are the controller for the personal data we collect about users of our site and our product — that is, we decide what is collected and why.
For any privacy question, or to exercise a right described below, email privacy@localsink.io or write to the address above.
What the product sends us
Your logs never leave your machine. localsink writes them to a local database file next to the process, and does not transmit them to us or to anyone else. We could not read them if we wanted to. The Software contains no telemetry, no usage analytics and no crash reporting.
There is exactly one call the Software makes to us, and only on a commercial license: validating your license key. The free build never contacts us at all — there is no key to validate, no account to create, and no network call to us of any kind.
That single call is described in full below, along with everything our website and our business collect — buying a license, emailing us, reading localsink.io.
What we collect, and why
When you visit localsink.io
The site is a set of static pages. It sets no cookies, runs no analytics or tracking scripts, embeds no third-party fonts, pixels or widgets, and has no forms to submit. We do not build a profile of you and we cannot follow you to other sites.
Our hosting provider, Cloudflare, processes standard server request data on our behalf in order to serve the site and protect it from attack: your IP address, the page requested, timestamp, user agent and referrer. We use this only to deliver the site securely and to diagnose faults. Legal basis: legitimate interests — running a working, secure website.
When localsink validates a commercial license
If you hold a commercial license and enter your license key, the Software sends that license key to our licensing service to confirm it is valid and current. It does this when you first enter the key, and periodically afterward so that a license which has been canceled, refunded or expired stops being treated as active.
Because that is an ordinary network request, our licensing service also receives your IP address and your user agent string, and we record them alongside the validation. From the user agent, we derive and record the localsink version, operating system and processor architecture. Cloudflare also supplies request metadata that we record: your country, network's autonomous system number (ASN) and the Cloudflare data center that handled the request. The Software sends no additional fields and does not transmit your logs, file paths, project names, machine name or any identifier we have generated for your installation.
We use this to confirm entitlement, to keep the number of active seats in line with what was purchased, and to detect abuse of a key — for example the same key being used far more widely than the license allows. Legal basis: performance of a contract for validating entitlement, and legitimate interests for preventing license abuse.
A failed validation does not interrupt the Software. The first successful validation stores your license's expiration date locally, and localsink keeps running normally until that date whether or not it can reach us again — if you are offline, or our service is down, it simply retries in the background. There is no lockout, no short grace period and no nag. If the expiration date passes without a successful validation, it reverts to the Community Edition — the Software itself is unchanged and keeps working.
The Community Edition performs no validation and makes no call, so none of this applies to it.
When you buy a commercial license
Purchases are handled by Paddle, our merchant of record. Paddle collects your name, email address, billing address, country, tax identifiers and payment details directly from you at checkout, and is an independent controller of that data — its own privacy policy applies. We never see or store your card details.
Paddle passes us the record of the sale — your name, email address, country, the product bought and the amount — so that we can issue and support your license and meet our accounting and tax obligations. Legal basis: performance of a contract for issuing and supporting the license, and legal obligation for keeping financial records.
When you email us
If you contact us at any of our published addresses, we receive your email address, your name if you give it, and the content of your message, including anything you attach. We use it to answer you and to keep a record of the conversation. Legal basis: legitimate interests — responding to people who contact us — or performance of a contract where you are a customer.
Please do not send us log files, credentials or production data. If you need to share a log sample for support, redact it first.
Product updates, if you ask for them
If we offer a launch or release announcement list and you join it, we use your email address to send those messages and nothing else. Legal basis: consent. Every message carries an unsubscribe link, and you can withdraw consent at any time by using it or by emailing us. We do not sell or rent our list, and we do not send marketing to people who have not asked for it.
Who we share data with
We do not sell personal data. We share it only with:
- Paddle — our merchant of record, for the sale of licenses, subscription management and payments, and tax compliance and invoicing.
- Service providers acting for us — our website host and CDN (Cloudflare), the infrastructure our licensing service runs on, our email provider, and the tools we use to keep records. They process data on our instructions under contract and may not use it for their own purposes.
- Professional advisors — accountants, auditors and lawyers, where they need it to advise us.
- Authorities — where we are required to by law, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights or safety of any person.
- A successor — if we are involved in a merger, acquisition or sale of assets, in which case we will tell you before your data becomes subject to a different privacy notice.
International transfers
We are based in the United States and our providers store and process data on servers in the United States and elsewhere. If you are in the UK or the European Economic Area, this means your personal data may be transferred outside the UK/EEA. Where it is, the transfer is covered by an appropriate safeguard — typically the Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant) or an adequacy decision — and we contract with our providers on that basis.
How long we keep it
- Server request data — retained by our host for a short operational period, typically no more than 30 days, then deleted or aggregated.
- Purchase and license records — kept for the life of the license and then for as long as tax and accounting law requires us to, generally seven years from the end of the relevant financial year.
- License validation records — the license key, IP address and user agent from each validation; the localsink version, operating system and processor architecture derived from the user agent; and the country, network ASN and Cloudflare data center supplied in Cloudflare's request metadata. We keep these for as long as the license is active and for a reasonable period afterward, so that we can investigate license abuse, answer a billing or entitlement dispute, and show what a license was used for if we are ever asked to. When a record is no longer useful for any of those, we delete it. You can ask us to delete yours at any time, and we will unless we are required to keep it.
- Support and other correspondence — kept for up to three years after the conversation ends, so we have context if you come back to us.
- Announcement list — until you unsubscribe, plus a minimal record of the unsubscribe so we do not email you again by mistake.
When data is no longer needed for the purpose it was collected for, we delete it or anonymize it so it can no longer be linked to you.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data. We honor them for everyone who asks, wherever you are:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of data that is wrong or incomplete.
- Erasure — deletion, where we have no overriding obligation to keep it.
- Restriction — to have us pause processing while a dispute is resolved.
- Portability — your data in a structured, machine-readable format.
- Objection — to processing based on legitimate interests, including any direct marketing.
- Withdrawal of consent — at any time, without affecting processing already carried out.
- Non-discrimination — we will not give you a worse product or price for exercising a right.
Email privacy@localsink.io to exercise any of these. We respond within one month, and will tell you if we need longer where the law allows an extension. We may need to verify your identity first — usually by confirming you control the email address the request concerns.
For purchase and billing data, Paddle is the controller, so send those requests to Paddle. We will point you in the right direction if you ask us first.
If you are in the UK or EEA and think we have handled your data badly, you may complain to your local supervisory authority — in the UK, the Information Commissioner's Office. We would rather you told us first so we can put it right.
Security
We use appropriate technical and organizational measures to protect personal data, including encryption in transit (the whole site is served over HTTPS), encryption at rest with our providers, access controls and multi-factor authentication on the accounts that hold data, and keeping the number of people and systems with access as small as we can. No system is perfectly secure, but we minimize data collection and limit it to what we need to operate and protect the service.
Cookies
localsink.io sets no cookies. There are no analytics cookies, no advertising cookies and no third-party cookies, which is why you are not being asked to accept any. If we ever need a strictly necessary cookie, or decide to measure traffic, we will update this notice and — where consent is required — ask for it before anything is set.
Paddle's checkout, which opens when you buy, sets its own cookies necessary to process the payment. Those are governed by Paddle's privacy policy.
Children
localsink is a developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email privacy@localsink.io and we will delete it.
Changes to this notice
We update this notice when what we do with data changes — for example if we add analytics, an account system or a mailing list. The date at the top of this page shows the current version, and we will give notice on the site before a material change takes effect.
Contact
Privacy — privacy@localsink.io. General — hello@localsink.io. Postal contact is the registered address above. See also our Terms and Conditions and Refund Policy.