privacy
What We Keep, And Why.
Short version: an email address, which platform you bought, and the key we issued you. No account, no password, no analytics, no tracking, and nothing at all sent from the app itself.
If you bought through the App Store or the Microsoft Store, we hold nothing about you at all — the store never tells us who you are.
The long version is below, because "short version" is not what the law asks for.
Who is responsible
The data controller is RMR Solutions LLC, a limited liability company organised in New Mexico, United States, at 6255 San Antonio Dr NE, P.O. Box 91021, Albuquerque, NM 87199. Questions, requests, or complaints: privacy@rmrsolutions.us.
Which parts of this apply to you
We deal with you directly in two situations, and not at all in a third:
- You bought Pro on this site. Direct sales are for the United States only.
- You asked us for a free Linux key. That is open to everyone, everywhere — no app store carries Linux, so it comes from us.
- You bought through the App Store or the Microsoft Store. Then Apple or Microsoft is the seller, not us. We never see your name, address, email, or payment details, and this notice does not cover that purchase — the store's own privacy policy does. If you write to us for support afterwards, we hold whatever is in your message and nothing more.
If you are in the European Union or the United Kingdom, the second and third cases are the ones that apply to you. The GDPR sections below are written for the Linux key flow, because that is the only service we offer you directly.
What we collect
Only what is needed to sell you a licence key and give it to you again if you lose it.
| Data | Where it comes from | Why |
|---|---|---|
| Email address | You, at checkout or on the Linux key form | To send you the key, and to re-send it on request |
| Which platform you bought | Your purchase | Keys are locked to one platform; we have to know which |
| Your licence key and its serial | Generated by us | So we can re-issue it and so no two customers get the same one |
| Payment reference, amount, currency, billing country, and the dates the key was issued, sent, and refunded if it was | Stripe, and our own records | Accounting, tax, and matching a payment to a key if something goes wrong |
| Whether the key was bought or issued free | How you asked for it | Linux keys are free; we need to tell the two apart when reconciling accounts |
| IP address | Your browser, when you request a free Linux key or ask us to re-send a key | Rate limiting only, so the free-key endpoint cannot be scripted. Deleted within seven days and never linked to a purchase. |
Collected by Stripe, not by us
Checkout is hosted by Stripe. Your card details never touch our systems. Stripe also collects a billing address, because sales tax depends on where you are. We store the country from it — that is the record showing we sell direct only in the United States — and not the rest of the address.
What we deliberately do not do
- No cookies are set by this site.
- No analytics, no advertising, no third-party trackers, no fingerprinting.
- No profiling and no automated decision-making that has any effect on you.
- No newsletter, and no marketing email of any kind. The only mail you get from us is your key, or a reply to something you sent us.
- The app itself never phones home. Your key is validated on your own device with no network call, so we do not and cannot know whether, when, or how you use the software.
Our legal grounds
| Purpose | Ground under Article 6 GDPR |
|---|---|
| Issuing your key, delivering it, re-sending it | Performance of a contract with you — Art. 6(1)(b) |
| Keeping records of what was sold, and when | Legal obligation, principally tax law — Art. 6(1)(c) |
| Rate limiting by IP address to prevent abuse of the free-key endpoint | Our legitimate interest in not having keys farmed by scripts — Art. 6(1)(f) |
Who else sees it
Three service providers, each doing one job:
- Cloudflare — hosts this site and the service that issues keys, stores the records described above, and provides the anti-bot challenge on the Linux key form (which processes your IP address).
- Stripe — takes the payment and calculates tax. Stripe has its own privacy notice governing what it does as a payment provider.
- Resend — delivers the email containing your key.
We do not sell your data, share it for advertising, or give it to anyone else, ever.
Transfers outside the EU
All three providers are based in the United States, so your data is transferred there. Those transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, and on the European Commission's Standard Contractual Clauses otherwise.
How long we keep it
| Data | Kept for |
|---|---|
| IP addresses used for rate limiting | 7 days, then deleted automatically every night |
| Internal payment-notification references | 30 days, then deleted automatically |
| Your email address, platform and key | Kept for as long as we sell or support the product, so that we can give you your key again. There is no account to lose access to, and this is what makes that promise possible. |
| Records of the sale itself | For the period tax law requires us to keep them, which is longer than the above and outside our discretion |
Your rights
Whoever and wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email privacy@rmrsolutions.us from the address you used and we will act within one month. We do not charge for this and we will not make you create an account to do it.
If you are in the EU, EEA or UK
The GDPR (and UK GDPR) gives you the rights above plus the right to restrict what we do with your data, to receive it in a portable form, and to object to processing we base on legitimate interests — which here means only the IP-based rate limiting.
In practice this concerns the free Linux key, since that is the only thing we sell or issue to you directly; Windows and macOS go through Apple and Microsoft, who answer for their own processing. You can complain to the data protection authority in the country where you live or work.
If you are in California
You may ask what personal information we have collected about you, ask us to delete it, and not be discriminated against for asking. We do not sell or share your personal information, for cross-context behavioural advertising or anything else, and we never have. We do not collect anything from anyone under 16 knowingly.
This site does not track you across other sites, so there is nothing for a Do Not Track signal to switch off. We honour it by having nothing to honour.
What deletion actually means here
If you ask us to erase your data, we remove your email address from our records. Two consequences worth knowing before you ask:
- Your key keeps working. It is validated by the app on your own machine, so there is nothing for us to switch off. Deleting your data does not take away the software you paid for.
- We can no longer re-send it. With no email address on file there is nothing to look you up by, so please keep your key somewhere safe first.
We keep the record of the sale itself — the amount, the date and the payment reference — because tax law requires it. Article 17(3)(b) GDPR permits this, and it no longer identifies you once your email address is gone.
Complaints
If you think we have handled your data badly, please tell us first — it is usually a mistake we can fix. If that does not resolve it, you can complain to your national data protection authority (in the EU, EEA or UK) or your state Attorney General (in the US).
Changes
If this notice changes materially we will update the date at the top. We do not have your address for anything other than sending your key, so we will not email you about it.