Privacy
Privacy Policy
1. Who we are
Maxxer is a productivity tracker for macOS, operated by I'm Right, Inc., a Delaware corporation ("we", "us", "our"). This Privacy Policy explains what we collect, how we use it, and the choices you have. If you have questions, reach us at privacy@maxxer.io.
2. What we collect
a) Account information
When you create an account you sign in with your email address or a Google account through our authentication provider, Clerk. We store your email and an account identifier — not a password. If you subscribe, payments are handled by Paddle, our Merchant of Record, which collects your billing details. We never receive or store your full card number.
b) On-device activity
Maxxer records keystroke and mouse-click counts, the active application (and, for browsers, the domain of the active tab), idle/away state, and focus-session metadata — all locally. If you turn on the optional Webcam Attention or eye-tracking features, your camera is analyzed on your Mac to sense whether you're at your desk; those camera frames are processed entirely on-device and are never stored or transmitted. This data stays on your device by default and is used only to render your dashboard, streaks, and goals. We do not transmit the contents of what you type — only aggregate counts.
c) Cloud sync and leaderboards
Ranking on the leaderboard and cross-device backup are core features of Maxxer, so your account syncs aggregate metrics (APM per minute, focus-time totals, session start/end timestamps) to power them. We never sync the contents of what you type — only these aggregate numbers. This processing is part of providing the service you signed up for. If you don't want it, you can delete your account and we erase your cloud data (see Section 8).
d) Diagnostic telemetry
When Maxxer crashes we may send a minimal report including OS version, app version, and a stack trace, identified only by an anonymous install identifier. These reports carry no personal content: no keystrokes, no file paths, no email address, no device name, and no IP address. You can disable crash reporting in Settings → Privacy.
Separately, when your app talks to our API (sign-in, sync, leaderboards, billing), our servers record the originating IP address of the request, as any web server does, and we retain it on server-side error reports to diagnose regional outages and to detect abuse. This applies only to requests your app makes to us — never to the crash reports described above, and never to on-device activity.
3. What we don't collect
- Keystroke contents, clipboard, or screen contents.
- Browsing history beyond the domain of the application or tab in focus.
- Location data — we never request or use your device’s location. (Our servers can infer an approximate region from the IP address of an API request, as described in Section 2d; that is not device location and is not collected by the app.)
- Microphone input or audio recordings.
- Camera images or video — the optional Webcam Attention feature analyzes your camera only on your Mac and never uploads or stores it (see Section 2b).
4. How we use your data
- Operate your account and deliver the app you're paying for.
- Send occasional service email (billing receipts, security notices, major updates). We do not sell your data or use it for advertising.
- Diagnose and fix bugs.
- Aggregate anonymized statistics to improve the product (e.g., which features are used, at a cohort level).
5. Sharing
We share data only with the vendors we depend on to run the service: Paddle (payments and Merchant of Record), Clerk (account sign-in), Cloudflare (hosting and database), Resend (transactional email), and Sentry (crash and error diagnostics; on by default, and you can turn it off in Settings → Privacy). Each is bound by data-processing terms. We disclose data to law enforcement only when compelled by a valid legal request.
6. Retention
We keep account data for as long as your account is active, plus up to 12 months after cancellation for accounting and dispute purposes. You can request earlier deletion at any time — see Section 8.
7. Security
Data in transit is encrypted with TLS. Data at rest in our databases is encrypted with industry-standard algorithms. Local on-device data is protected by macOS's user-account isolation. No system is perfectly secure; we make our best commercially reasonable effort.
8. Your rights
Depending on where you live (GDPR, CCPA, and similar laws), you have the right to access, correct, delete, or export your personal data, and to object to certain processing. Email privacy@maxxer.io from the address on your account and we'll respond within 30 days.
9. Children
Maxxer is not directed at children under 13, and we do not knowingly collect data from them.
10. Changes
If we make material changes to this policy we'll notify you by email and update the "Last updated" date above.