Privacy Policy
Privacy Policy
How RunShelf handles website visits, local app data, purchases, and support communication.
Effective: July 26, 2026
Controller and Contact
The controller for RunShelf is Burlis Management GmbH, Philippstraße 27, 52349 Düren, Germany.
Contact: [email protected]
Website Delivery
Cloudflare and the origin hosting provider may process your IP address, requested URL, timestamp, user agent, response or error data, and security or network diagnostics to deliver and protect this site.
The RunShelf application code does not add analytics cookies, marketing cookies, tracking pixels, browser analytics storage, or advertising tags.
Local App Data
RunShelf processes or stores detected process names, ports, process identifiers, runtime type, HTTP status, project paths, saved launch commands, preferences, trial dates, and validation dates locally on your Mac.
RunShelf 1.0.0 does not send raw project paths, commands, ports, process identifiers, server names, or local log contents from your Mac.
Local Logs
Launched-process stdout and stderr are stored unredacted in ~/Library/Logs/RunShelf with private directory and file permissions. When a new log session is created, inactive logs at least seven days old are deleted and only the newest twenty inactive logs older than one day are retained.
Active logs, and logs on a Mac where no new session is created, can remain longer. You can delete these local files.
Purchases and Licensing
Polar is the merchant of record and authorized reseller for checkout. Polar processes checkout, billing, payment, tax, invoice, fraud-prevention, and transaction information under its own policy. RunShelf does not receive payment-card details.
For activation, validation, and deactivation, the app sends the license key, organization ID, fixed label RunShelf Mac, benefit ID, and activation ID to Polar. The full license key and activation ID are stored in the Data Protection Keychain; trial, display-key, and validation dates are stored in UserDefaults.
Error Diagnostics
Error diagnostics are enabled only when a shipped build contains a Sentry DSN. RunShelf 1.0.0 includes that configuration, so Sentry receives minimized crash and error diagnostics. RunShelf disables tracing, default PII, automatic sessions, automatic and network breadcrumbs, and network tracking, and applies redaction before sending app-generated errors. Sentry error events are retained for 90 days.
Crash diagnostics can still include technical crash information and app and build details. The app adds only these coarse allowlisted context fields: runtime kind, HTTP status, active connection count, requested target state, actual status, whether servers existed, known server count, failure category, and exit code. It also sends a normalized operation label. If a shipped build contains no DSN, diagnostics are disabled.
Update Checks
Automatic Sparkle checks are disabled. When you choose Check for Updates, Sparkle requests the configured RunShelf appcast; that request can expose your IP address and identifies the RunShelf and Sparkle versions. The last-check date is stored locally.
Support
Support messages and their metadata are used to answer and follow up on requests.
Purposes, Legal Bases, Retention, and Recipients
We process licensing and requested updates to perform a contract; site delivery, abuse prevention, minimized error diagnostics when enabled, and support follow-up for legitimate interests; and data where legal obligations apply.
Local data remains until you remove it or the stated cleanup runs. Provider-side diagnostic data, when enabled, remains subject to the project settings actually in force, legal duties, and provider backup and deletion processes.
International Transfers and Your Rights
Providers can use subprocessors outside Germany or the EEA under adequacy decisions, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses. You may have rights of access, correction, deletion, restriction, portability, objection, withdrawal, and complaint.
Send requests to [email protected]. You may also complain to the data protection authority for North Rhine-Westphalia.