Release and purchase status
Better UnArchiver is available through the Mac App Store, where Apple handles transactions and restoration. Direct website checkout, License issuance, and account recovery remain disabled. Do not send payment information or transaction credentials to support.
BetterMac Privacy Policy and Personal Information Notice
Version: 2026-09-20
Effective date: August 24, 2026
Last updated: September 20, 2026
Key summary: BetterMac applications perform their core operations locally on your Mac; the per-application scope is set out in Appendix E. The files, contents, file paths, and content passwords you select are not automatically uploaded to BetterMac as a result of those operations. Information necessary for an online function is sent to us or a designated service provider only when you actively use customer support, direct website purchasing, License recovery, or another clearly identified connected feature.
1. Scope and relationship with other documents
1.1 Scope. This Policy applies to BetterMac-branded websites, including all language versions of bettermac.net, each BetterMac-branded macOS application listed in Appendix E (each an “App”), customer support, and—when clearly made available on the relevant page—direct website checkout, License issuance, activation, device management, and License recovery services.
1.2 Exclusions. Apple, payment institutions, browsers, operating-system providers, independent third-party websites, and other third parties may determine their own purposes for processing personal information. Their own privacy notices apply to that independent processing, and this Policy does not replace those notices.
1.3 Other documents. The BetterMac Cookie Policy provides the technical cookie inventory and controls. The BetterMac Terms govern software licensing, purchases, refunds, and use. A just-in-time notice, attachment-upload confirmation, checkout notice, or separate consent provided for a particular feature forms part of the complete notice for that context together with this Policy. If they conflict, the more specific and legally effective notice that better protects the individual applies to that processing.
1.4 Terminology. “Personal information” includes personal information, personal data, or other information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to a natural person under applicable law. “Processing” includes collection, storage, use, transmission, disclosure, publication, and deletion. For individuals in Mainland China, Beijing Habitai Technology Co., Ltd is also the personal information handler under the Personal Information Protection Law. For individuals in the EEA or UK, we are the controller under applicable data protection law unless a particular context states otherwise.
2. Personal information handler, controller, and contact details
2.1 Operating entity. Beijing Habitai Technology Co., Ltd is the BetterMac website operator, App provider, and personal information handler/controller under this Policy, with registration number 91110108MAKBJBRM9N and registered office at Room CG05-172, Building 8, Courtyard No.1, Zhongguancun East Road, Haidian District, Beijing, China.
2.2 Privacy contacts.
- Privacy and rights-request email: support@bettermac.net
- Online privacy-request channel: support@bettermac.net (by email; there is currently no separate web form)
- Postal address: Room CG05-172, Building 8, Courtyard No.1, Zhongguancun East Road, Haidian District, Beijing, China
- Personal information protection officer or data protection officer: Not applicable at present; privacy matters are handled through support@bettermac.net
- Dedicated office or representative in Mainland China: Not applicable; the operating entity is registered in Mainland China
- European Economic Area: the Apps are distributed through the Mac App Store and are available in the EEA; privacy enquiries and rights requests from the EEA are handled through support@bettermac.net and the postal address above
- United Kingdom: the Apps are distributed through the Mac App Store and are available in the United Kingdom; privacy enquiries and rights requests from the UK are handled through the same channels
2.3 Allocation of roles. Apple generally determines independently how it processes Apple Account, App Store payment, refund, and store-security information. A direct-payment provider may act as an independent seller, an independent controller, or a processor, as identified at checkout and in Appendix B. BetterMac is responsible only for processing for which it determines the purposes and means.
3. Our core privacy commitments
We process personal information according to the principles of lawfulness, fairness, necessity, transparency, purpose limitation, data minimization, and storage limitation. We make the following commitments:
- Core operations in each App are local by default and do not automatically upload files, file contents, full paths, or content passwords;
- We do not sell personal information, share personal information for cross-context behavioral advertising, engage in targeted advertising, or use profiles for differential pricing;
- Public pages may use Google Analytics 4 for measurement only after you accept analytics cookies. Advertising features and remarketing are disabled. We do not use third-party advertising tools on public pages;
- Support screenshots and diagnostics packages are always previewed and affirmatively selected by you one by one. Refusing attachments does not prevent text-only feedback;
- We do not ask you to provide full payment-card numbers, security codes, online-banking credentials, Apple Account passwords, content passwords, or full License keys through ordinary email;
- We do not use file contents, content passwords, support attachments, or identifiable support communications to train general-purpose artificial intelligence models. If we intend to change this commitment in the future, we will give specific, prominent notice before that processing begins and obtain consent where required by law;
- We do not make decisions based solely on automated processing that produce legal or similarly significant effects on an individual;
- We delete or anonymize information when the purpose has been fulfilled, the retention period has expired, or deletion is otherwise legally required, unless the law requires continued retention.
4. Information we process
4.1 Local processing in the App
Files, folders, file contents, paths, content passwords, output locations, and task status that you expressly select through an open panel, save panel, drag and drop, or a system file picker are processed by the App on your Mac to perform the core operations described for that App in Appendix E. This information is not automatically transmitted to BetterMac as part of those core tasks.
If you choose to remember a password, it is stored in macOS Keychain on the current device. BetterMac does not receive passwords stored in Keychain, and the item is not synchronised through iCloud Keychain.
The App may locally store recent-task information, preferences, Free-tier counters, bookmarks, or security-scoped access credentials to preserve features you select. This data ordinarily remains on the device until you clear it in the App, delete the related files, reset App data, or uninstall the App. It is not personal information held on BetterMac servers.
4.2 Local diagnostics and optional export
For troubleshooting, the App may locally record an event code, component, processing phase, error code, duration, content format, file count, coarse size range, and an environment snapshot such as the App version, macOS version, hardware architecture, and language. Default local diagnostics are retained for no more than seven days and no more than 10 MiB in total. Temporary detailed mode lasts no more than 30 minutes.
Diagnostics are designed not to record content passwords, License keys, file contents, filenames, full paths, user names, email addresses, macOS bookmarks, Keychain data, or StoreKit transaction identifiers. A selected file is sent to the support system only after you preview and affirmatively choose to upload the diagnostics ZIP.
4.3 Website access, network, and security information
When you visit the website or call an online interface, your browser, network, and the server may automatically generate an IP address, request time, requested path, referring page, browser or client type, broad operating-system type, response status, bytes transferred, TLS/network information, rate-limit results, and security-event records. We use this information to return pages, maintain availability, troubleshoot faults, prevent abuse, investigate security events, and maintain necessary audit records.
When the App retrieves online help content, the request additionally carries the interface language, the App build number, and whether the current entitlement is Free or Pro, so that we can return the correct help version. That request does not carry your email address, files, filenames, paths, or content passwords.
Unless an appendix or just-in-time notice states otherwise, we do not use these records to track you across websites or build an advertising profile.
4.4 Feedback, support cases, and attachments
Current status. The website “Contact us” form and in-app feedback are available only when the relevant released product version and production support service display them as available; the relevant product support page and App state the categories and entitlement scope currently accepted. Better Cleaner allows text feedback to be submitted independently and provides a secure case session after verification. If the device is offline or the support service is unavailable, you may instead email support@bettermac.net. That mailbox is hosted by an external mail provider, and its transmission and storage follow that provider’s rules. Content submitted through the form, App, or email is handled under the purpose limits, access controls, and retention periods in this Policy.
You may submit a full name for the website Contact us form, an email address, issue category, title, description, reproduction steps, App version, macOS version, hardware architecture, interface language, the relevant product entitlement status (“free” or “pro” for Better Cleaner and other products that support a paid entitlement), and later correspondence. The website form requires a full name, email address, necessary text, and a declaration that you are at least 14 years old or have guardian consent (we record the declaration itself and do not collect a date of birth); in-app feedback does not require a name. These fields are used to verify the relationship to the case, diagnose the issue, respond, maintain service quality, and handle disputes.
Screenshots, website PNG/JPEG images, and diagnostics ZIP files are entirely optional. Each attachment must be previewed and separately selected for the current submission, and the upload choice is not carried forward automatically to a later submission. Where an App provides a support screenshot feature, it captures only that App’s own content window; the product-specific scope and exceptions are in Appendix E. The public website Contact us form accepts only a PNG or JPEG image that you affirmatively select. The server validates file type and size, re-encodes and normalizes images, and applies an entry allow-list, path-safety checks, and decompression-bomb limits to the diagnostics ZIP. These are structural safety checks and are not equivalent to malware scanning.
When you initiate a website submission, the server may create a recoverable unverified draft before attachment upload and email verification are complete. A failed response does not mean that the case was submitted successfully or the email was verified, and does not prove that no draft or attachment was stored. While the page remains open, the form keeps the submission and retry credentials only in the current page’s memory so you can retry the same draft, retry or remove an attachment, or continue with text only. Reloading or closing the page does not delete a server draft; unverified drafts and their attachments expire after 24 hours. A new submission requires fresh attachment selection and consent.
Email verification. Both the website form and in-app feedback send a one-time verification link to the address you entered before a case is opened: a draft that is never verified is deleted with its attachments after 24 hours, the secure case session is available only after verification, and the longer attachment period starts from verification or a case-status update. Either channel accepts a text-only submission.
Before submission, remove unrelated personal information, third-party information, filenames, full paths, trade secrets, full License keys, passwords, and payment credentials. If an attachment contains information that is unnecessary for the request, we may redact, isolate, or delete it early where reasonably practicable.
4.5 Mac App Store purchases and StoreKit entitlements
Apple primarily processes the Apple Account, payment method, billing, tax, receipt, and refund information for Mac App Store purchases under Apple’s rules. Only for an App that offers a paid entitlement, the App may obtain a product identifier, verified transaction status, purchase date, revocation or refund status, and entitlement result through StoreKit to unlock Pro or restore a purchase. An App with no purchase function does not perform that processing.
The App itself does not send us raw StoreKit transaction identifiers or your Apple ID: the device’s StoreKit state is the sole authority for its Pro switch and entitlement. For an App where we have enabled that intake on the server, our server receives Apple App Store Server Notifications. Apple pushes signature-verified notifications about purchases, renewals, refunds, revocations, and refund reversals directly to our server, and those may contain a transaction identifier, an original transaction identifier, a product identifier, and the event type and time. The server only records and reconciles support facts; it does not grant or correct Pro entitlement in the App. Raw notifications are retained for no more than 30 days, and necessary purchase, refund, and revocation facts for no more than three years. Appendix E states whether a given App has that intake enabled; for an App without it, no such processing takes place and purchase information is handled by Apple under its own rules. We do not receive a full card number, security code, or Apple Account password, and we do not receive your Apple Account sign-in details.
4.6 Direct website purchases, Licenses, and device management
Only when direct website sales are clearly enabled may we process: an email address; payment-provider order, transaction, and customer identifiers; the product, Offer, amount, currency, tax, payment status, and refund status; License status, product scope, and device limit; a hashed or pseudonymous device identifier; activation, last-use, deactivation, and reissuance records; and information necessary for contract performance, reconciliation, tax, audit, and disputes.
Full payment-card numbers, security codes, and online-banking authentication information should be processed only by the payment provider and should not enter BetterMac systems. The actual seller, payment provider, server region, and allocation of roles are identified at checkout and in Appendix B.
4.7 License recovery and secure sessions
Only when recovery is enabled and you use it may we process the email address you submit, digests of one-time links or challenge values, short-lived session and CSRF information, an IP-address digest, operation time, masked License and device records, and deactivation actions. Raw one-time tokens should exist only briefly and become invalid after exchange or expiry. The recovery page displays only masked information necessary to complete the request.
4.8 Administration, security, compliance, and audit
To restrict administrative access, investigate events, process high-risk License actions, and demonstrate compliance, we may record the authorized actor, target record, action type, result, time, reason, associated case, and IP-address digest. Ordinary audit logs should not contain a full License key, raw device fingerprint, recovery token, session token, or administrator authentication secret.
5. Purposes, necessity, and legal bases
We use personal information only where an applicable legal basis exists and the processing is necessary for the relevant purpose. The principal purposes and bases are:
| Purpose | Typical information | Principal EEA/UK basis | Principal Mainland China basis |
|---|---|---|---|
| Provide the App, website, support, purchase, License, and recovery functions | Selected information, email, order, License, device digest, session information | Performance of a contract or steps at your request before entering into a contract | Necessary to conclude or perform a contract to which the individual is a party |
| Website delivery, troubleshooting, network and product security | IP, request, error, security, and audit records | Our legitimate interests in protecting the service, users, and systems; legal obligation where applicable | Compliance with legal duties; reasonable security management, with consent where the law requires it |
| Payments, refunds, tax, accounting, and regulatory matters | Order, amount, currency, payment/refund status, invoice information | Performance of a contract and legal obligation | Contract performance and statutory duties or legal obligations |
| Support, rights requests, complaints, and disputes | Case, communication, verification, and disposition records | Contract performance, legal obligation, and legitimate interests in establishing, exercising, or defending legal claims | Contract performance, legal obligations, and lawful dispute handling |
| Optional support attachments or future optional features | Screenshots, diagnostics packages, or other information you affirmatively select | Consent; some support processing may also be necessary for contract performance | Consent; separate consent where required for sensitive information, disclosure, or cross-border transfers |
| Fraud and abuse prevention and manual review | License status, device digest, rate limits, and security events | Legitimate interests in protecting transactions, services, and other users | Compliance with security obligations or processing necessary within the scope of the contract |
5.1 Legitimate interests. When we rely on legitimate interests, those interests generally include operating and protecting a small software service, preventing fraud, troubleshooting errors, maintaining product quality, and establishing or defending legal claims. We assess necessity, impact on individuals, and available safeguards and do not rely on this basis where your rights and freedoms override those interests.
5.2 Consent. Consent is used only for genuinely optional processing or where the law expressly requires it. You may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. Refusing optional attachments, analytics, or marketing does not prevent core App functionality or text-only support. If information is necessary to complete a particular service, however, we may be unable to provide that service without it.
5.3 Change of purpose. Before using information for a new purpose that is incompatible with the original purpose, we will explain the new purpose, basis, impact, and available choices and obtain new consent where required. General wording in this Policy does not authorize a material secondary use that has not been disclosed.
6. Sensitive personal information and information we do not seek
Order, refund, or payment status may be property or sensitive personal information under some laws. Recovery tokens, License credentials, and support attachments may also present elevated risk. We restrict access, shorten retention, use encryption or hashing, explain necessity and effects on individual rights where required, and obtain separate consent where the law requires it.
We do not actively request or plan to collect full payment-card numbers, security codes, online-banking passwords, Apple Account passwords, biometric information, precise location, contacts, health information, government identifiers, file contents, or content passwords. Do not send this information through support text, ordinary email, or screenshots. If you submit it voluntarily, we will use it only where necessary and lawful for the request; otherwise, we will delete it promptly or direct you to a secure channel.
7. Cookies, local storage, and similar technologies
Public product, support, and legal pages may show an analytics consent banner. Until you accept, we do not load Google Analytics and do not send measurement requests. After you accept, Google Analytics 4 may set _ga / _ga_* measurement cookies as described in the Cookie Policy. We do not use advertising, profiling, or social-media cookies, and we do not use localStorage or sessionStorage to track users across visits. A first-party better_mac_analytics_consent preference cookie stores your Accept or Reject choice. Only when the corresponding function is enabled and you actually use it do the support-case, License-recovery, and administration functions set strictly necessary, short-lived cookies:
| Name | Context and purpose | Principal attributes and lifetime |
|---|---|---|
better_mac_support_session | Maintains the authenticated support-case session after you open your case link | HttpOnly, SameSite=Strict, Secure, path /, 8 hours |
better_mac_support_csrf | Stores a short-lived CSRF value for support-case actions and validates it against a request header | SameSite=Strict, Secure, path /, 30 minutes |
better_mac_recovery_challenge | Binds a pre-authentication challenge to a recovery request and prevents forgery and replay | HttpOnly, SameSite=Strict, Secure, scoped to /v1/recovery, 15 minutes |
better_mac_recovery_csrf | Stores a short-lived CSRF value and validates it against a request header | SameSite=Strict, Secure, scoped to /v1/recovery, 15 minutes |
better_mac_recovery_session | Maintains the short recovery session after a one-time link is exchanged | HttpOnly, SameSite=Strict, Secure, scoped to /v1/recovery, 15 minutes |
better_mac_admin_session | Maintains an authenticated administrator session and is not used for visitor analytics | HttpOnly, SameSite=Strict, Secure, path /; 12-hour maximum and 30-minute server-side idle expiry |
Production session cookies travel only over HTTPS. You may block or delete cookies in your browser, and you may reopen the analytics Accept / Reject control from the Cookie Policy or the site footer. Blocking strictly necessary cookies does not prevent access to public pages, but the relevant recovery or secure sign-in function will not work. Because we do not sell or share personal information for cross-context advertising, Global Privacy Control or a similar signal does not trigger an additional data sale, but we will still recognize and honor the signal where applicable law requires it.
8. Sources of information
Personal information may come from:
- Information you enter, select, upload, or provide in support communications;
- Information generated automatically by your browser, Mac, App, and network connection when you use a feature;
- StoreKit product, transaction, and entitlement status that Apple provides to the App or an authorized server;
- Order, payment, refund, tax, and fraud-prevention results supplied by a direct-payment provider or merchant of record;
- Records created by our authorized personnel when handling support, Licenses, security, rights requests, or compliance matters.
We do not purchase personal information from data brokers and do not build personal marketing profiles from public sources.
9. Processors, recipients, and disclosures
We provide information only to recipients necessary for a defined business purpose and restrict their processing through access controls, contracts, confidentiality, security requirements, and vendor review. Appendix B identifies specific names, roles, regions, and data categories. Principal categories include:
- Apple: independently processes App Store account, payment, refund, and store-security information and provides necessary entitlement status to the App or an authorized server;
- Website, database, CDN, and security providers: deliver pages, host services, resist attacks, and retain necessary records;
- Email providers: send email verification, support messages, License delivery, and secure links;
- Private object-storage providers: store support attachments that you affirmatively upload;
- Direct-payment providers or merchants of record: process payment, tax, refunds, and fraud prevention;
- Professional advisers, auditors, insurers, or authorities: receive limited information where necessary for confidentiality-protected advice, disputes, audit, regulatory matters, or legal obligations.
We do not sell personal information and do not provide information to a third party for its independent targeted advertising or cross-context behavioral advertising. Except where the law permits processing without consent, a disclosure, joint processing arrangement, or public disclosure involving personal information of an individual in Mainland China will be subject to the required notice, impact assessment, and separate consent where applicable.
10. Cross-border processing and international transfers
BetterMac’s operating entity, service providers, and users may be in different countries or regions. The actual production providers and data-storage regions must be identified in Appendix B. We do not use broad statements such as “global operations” as a substitute for naming the relevant recipients and regions.
For personal information transferred from the EEA, UK, or another jurisdiction with transfer restrictions, we use an applicable adequacy decision, European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, or another valid mechanism and, where necessary, assess destination-country law and apply supplementary measures.
Before personal information collected and generated in operations in Mainland China is provided outside Mainland China, we identify the overseas recipient’s name, contact details, purposes, methods, information categories, retention arrangements, and rights channel, conduct a personal information protection impact assessment, and—depending on applicable thresholds—complete a security assessment, standard-contract filing, certification, or other required mechanism. We obtain separate consent where the law requires it. Direct sales, support attachments, or another feature creating a new cross-border data flow must not launch before those facts and mechanisms are implemented.
You may contact support@bettermac.net for a summary of transfer safeguards applicable to you. We may redact contracts where necessary to protect trade secrets and security.
11. Retention and deletion
We retain information for the shortest period necessary for the purpose, taking account of the contract term, refund and dispute windows, tax and accounting duties, security risk, and applicable limitation periods. Appendix C provides the principal periods.
After the period expires, we delete, anonymize, or place information in a state restricted solely to legal retention or security isolation. If the law requires continued retention, we restrict processing other than storage and necessary security, and delete the information once the reason for retention no longer applies.
Local files, task history, Keychain items, and diagnostics on your device are controlled by your device and App settings and are not subject to BetterMac server-retention periods. Deleting the App may not automatically delete an item you elected to save in macOS Keychain; you can manage it through the App or Keychain Access.
12. Security measures and incident response
Based on risk, we use measures such as encryption in transit, encryption or hashing at rest, key separation, least privilege, strong authentication, access approvals, private object storage, short-lived signed downloads, input validation, structural validation of attachments, rate limits, audit logging, vendor management, and personnel confidentiality.
We seek to keep raw secrets out of logs and retain traceable records for high-risk actions. We periodically review permissions, deletion jobs, dependencies, and security events and conduct a personal information protection impact assessment or data protection impact assessment where required.
No internet service can guarantee absolute security. If a breach, alteration, or loss may create a risk to individual rights, we take containment, investigation, remediation, and mitigation measures and notify affected individuals and authorities as required, including the nature of the incident, likely effects, measures taken, and recommended steps to reduce risk.
13. Your privacy rights
Depending on applicable law and the particular legal basis, you may have the right to:
- Be informed and request an explanation of the processing rules;
- Access personal information or obtain a copy;
- Correct or supplement inaccurate or incomplete information;
- Request deletion where the purpose has been achieved, the period has expired, processing is unlawful, consent has been withdrawn, or another legal condition applies;
- Restrict processing or object to processing based on legitimate interests, direct marketing, or another specified ground;
- Obtain data in a structured, commonly used, machine-readable format or request transfer where the legal conditions are met;
- Withdraw consent-based processing at any time;
- Avoid a decision based solely on automated processing that has legal or similarly significant effects and request human review;
- Appeal a denial or outcome and lodge a complaint with a competent authority;
- Exercise rights in good faith without discrimination or an unreasonable reduction in service quality;
- In Mainland China, have a close relative exercise relevant rights relating to a deceased individual for a lawful and legitimate interest;
- Exercise any other right granted by applicable law.
These rights are not absolute. For example, we may retain necessary information to comply with law, protect another person’s rights, maintain security, address fraud, or establish, exercise, or defend legal claims. We explain why a request cannot be fulfilled in full and identify available complaint channels. Rights requests apply only to information that BetterMac controls; local data that has never left your Mac should be managed through the App, Finder, macOS Settings, or Keychain Access, and information held by Apple, a payment provider, or another independent handler should be requested from that party.
14. Rights requests and privacy complaints
14.1 How to submit. Email support@bettermac.net (there is currently no separate web form) and identify the product, relevant email, relationship to an order/case/License, and the type of request. You do not need to use legal terminology. A request for an applicable region may also be submitted through a representative listed in Appendix B.
14.2 Verification. To prevent impersonation, we request only verification necessary for the request, such as confirmation of control of the relevant email address, secure case link, order, or License. We do not request unrelated identity documents unless necessary and a secure channel is available. An agent, guardian, or close-relative request may require proof of authority and identity.
14.3 Timing. We respond within the period required by applicable law. Ordinarily, an EEA/UK request is handled within one month; a verifiable consumer request subject to California law is ordinarily handled within 45 days, with a permitted extension and explanation where applicable; a Mainland China request is handled promptly. Extensions, fees, or refusals for complex, repetitive, or excessive requests apply only where the law permits them.
14.4 Support-attachment deletion. When the secure case page is available, you may delete attachments early before case closure or during the retention period. Deletion of an entire case, order, or License record enters the formal privacy-request process because some records may be subject to contract, tax, fraud-prevention, or dispute-retention duties.
14.5 Complaints. You may use the same email address to complain about our processing. For a complaint subject to UK law, we provide a clear complaint channel, acknowledge receipt within 30 days, investigate without undue delay, keep you informed, and communicate the outcome. Other complaints are handled within mandatory local periods. You may also complain to a competent data protection, cybersecurity, consumer, or other authority in your place of residence or work or where the alleged infringement occurred.
14.6 Appeal. If we deny a request or you disagree with an outcome, you may ask for review through the same channel, after receiving the outcome, and place “Privacy Appeal / 隐私申诉” in the subject line. An appropriate person who did not make the original decision will conduct the review, subject to any different requirement under applicable law.
15. Automated decisions, marketing, analytics, and artificial intelligence
We currently do not use personal information for differential pricing, targeted advertising, cross-context behavioral advertising, marketing profiles, or a solely automated decision that has legal or similarly significant effects. Security rate limits, License status, and anti-abuse rules use predefined conditions. If a result may be wrong or affect a legitimate entitlement, you may request human review.
We do not send unsolicited marketing email. Service notices, purchase records, security alerts, support replies, and material policy notices are not marketing. If we later offer optional marketing, it will use a separate subscription, clear unsubscribe controls, and an applicable consent mechanism.
We do not use file contents, content passwords, support attachments, or identifiable support communications to train general-purpose artificial intelligence models. If we later use artificial intelligence to assist support or security analysis, we will first conduct vendor due diligence and a risk assessment, limit input and output information, verify whether model training or independent provider use occurs, provide an appropriate just-in-time notice, and obtain consent or offer an opt-out where required.
16. Children
The product is intended for users able to enter a software License and purchase contract and is not directed to children under 14 or below any higher protected age applicable in their location. We do not knowingly collect children’s personal information and do not knowingly sell or share minors’ information for behavioral advertising.
If you believe a child’s personal information was submitted without valid guardian authorization, contact us. After verification, we will delete it, restrict processing, or take another legally required safeguard. Before offering a child-directed service, we will implement a specific notice, age-appropriate design, and guardian-consent process.
17. Legal disclosures, corporate transactions, and third-party links
We may disclose limited information to an authority, court, professional adviser, or relevant party where necessary to comply with law or valid judicial or regulatory process, protect life or property, investigate fraud and security events, or establish or defend a legal claim. We assess the legality and scope of a request.
In a merger, acquisition, financing, asset sale, reorganization, insolvency, or change of control, personal information may be transferred to relevant participants subject to confidentiality and due-diligence restrictions. Before and after completion, we require the recipient to continue this Policy or provide protection no less than applicable law requires and give advance notice, obtain consent, or offer a choice where required.
The website or App may link to a third-party page. This Policy does not apply where the third party independently determines its processing. Review its privacy notice before providing information.
18. Policy updates, versions, and language
We may update this Policy for changes to the product, data flows, providers, law, or security requirements. Before a material change—such as a new information category, a materially new purpose, sale or advertising sharing, a substantial retention extension, an important cross-border change, or a clear reduction in individual rights—we provide prominent notice through the website, App, email, or another appropriate channel and obtain renewed consent where required.
An update does not retrospectively authorize processing that was not lawfully disclosed when the information was collected. The page identifies the current version, effective date, and last-updated date. Prior versions or change summaries are available at https://bettermac.net/en/privacy/ (this is the first version; superseded versions will be listed there) or on request through the privacy email.
The Chinese and English versions are intended to be consistent. Where an interpretation differs, Chinese prevails to the extent applicable law allows, but a language-priority rule does not restrict mandatory data protection rights in your location.
19. Contact us
Personal information handler/controller: Beijing Habitai Technology Co., Ltd
Registration number: 91110108MAKBJBRM9N
Registered address: Room CG05-172, Building 8, Courtyard No.1, Zhongguancun East Road, Haidian District, Beijing, China
Privacy postal address: Room CG05-172, Building 8, Courtyard No.1, Zhongguancun East Road, Haidian District, Beijing, China
Online privacy-request channel: support@bettermac.net (by email; there is currently no separate web form)
Privacy email: support@bettermac.net
Personal information protection officer/data protection officer: Not applicable at present; privacy matters are handled through support@bettermac.net
Do not send passwords, full License keys, payment-card information, government identifiers, or unredacted sensitive attachments through ordinary email.
Appendix A: Personal information inventory
| Context | Information category | Purpose and necessity | Source and whether it leaves the device |
|---|---|---|---|
| Local processing in the App | Selected files, folders, file contents, paths, content passwords, output locations, task status | Perform the core operations listed for that App in Appendix E; necessary for the feature | Selected by you; processed locally on the Mac by default and not automatically sent to BetterMac |
| Local settings and diagnostics | Preferences, Free-tier counter, event code, error code, duration, format, count, coarse size range, environment snapshot | Preserve settings, meter the Free tier, and troubleshoot locally; necessary for the selected feature | Generated by the App locally; leaves the device only if you affirmatively export and upload it |
| Website access | IP, time, requested path, client/browser, response status, network and security events | Deliver pages, maintain availability, troubleshoot, and prevent attacks and abuse | Generated by the browser and infrastructure; sent to website/CDN/hosting systems |
| Support case | Full name for the website form, email, issue category, title, details, reproduction steps, App/system/architecture/language/entitlement snapshot, correspondence | Verify relationship, diagnose and respond, handle disputes; necessary for an online case | Submitted by you; sent to support, database, and email systems |
| Optional support attachments | A PNG/JPEG image from the website form, a PNG of the App’s own content window, or a fixed-structure diagnostics ZIP | Assist diagnosis; entirely optional | Previewed and affirmatively selected by you for each attachment; uploaded to private object storage |
| App Store entitlement | Product identifier, verified transaction status, purchase/revocation/refund status, entitlement result | Unlock Pro, restore purchases, reconcile refunds | On-device entitlement is supplied by Apple to the App and is not sent back by the App; only for an App marked in Appendix E as having server intake enabled, Apple pushes signature-verified transaction and refund events, including a transaction identifier, to our server through App Store Server Notifications |
| Direct order | Email, order/transaction/customer identifier, product, Offer, amount, currency, tax, payment/refund status | Checkout, delivery, reconciliation, tax, refunds, and disputes; necessary for direct sales | Supplied by you and the payment provider; sent to BetterMac and relevant providers only when direct sales are enabled |
| License and device | License status, product scope, device limit, device digest, activation, last use, deactivation, and reissuance | Issue and verify Licenses, count the device pool, prevent abuse, and provide support | Generated by the App/server; processed only when Direct Licenses are enabled |
| License recovery | Email, token/challenge/session digest, CSRF, IP digest, time, masked License and device information, action record | Verify control, prevent replay, display and deactivate devices | Generated by you and the system; processed only when recovery is enabled and used |
| Administration and audit | Authorized actor, target, action, result, time, reason, associated case, IP digest | Access control, event investigation, compliance, and accountability | Generated by the back end and authorized personnel; held in a restricted audit system |
| Privacy requests and complaints | Contact details, request type, verification material, communications, decision, and disposition | Verify and fulfill rights, handle complaints, demonstrate compliance | Generated by the requester, agent, and us; sent to a restricted privacy-case system |
Appendix B: Recipients, service providers, and regions
| Recipient/category | Role and region | Information and purpose | When applicable |
|---|---|---|---|
| Apple Inc. and relevant affiliates | Independent handler/controller as determined by Apple’s published notices; region according to Apple’s service arrangements | Apple Account, App Store payment, refund, and store security; supplies product and entitlement status to the App or authorized server | When the Mac App Store is used |
| Website and database hosting | Alibaba Cloud (Singapore) Private Limited (the Alibaba Cloud International contracting entity), acting as a processor; data stored in Japan; remote administration performed from Mainland China | Website requests, support-case and License database, security records | In production use |
| CDN, DDoS, and security service | Not used at present | Not applicable | The website is served directly from the origin; no CDN, DDoS scrubbing, or WAF is deployed. This table will be updated before any is enabled |
| Email service | Alibaba Cloud (Singapore) Private Limited (the Alibaba Cloud International contracting entity), using Alibaba Cloud DirectMail, acting as a processor; sending infrastructure in Japan | Email verification, support communications, License delivery, secure links | In use for customer support |
| Private object storage | Alibaba Cloud (Singapore) Private Limited (the Alibaba Cloud International contracting entity), using Object Storage Service, acting as a processor; objects stored in Japan | Website PNG/JPEG images, App-window screenshots, and diagnostics ZIP files you affirmatively submit; private bucket, server-side encryption, and short-lived signed downloads | When attachment upload is enabled |
| Object storage encryption and keys | Alibaba Cloud (Singapore) Private Limited (the Alibaba Cloud International contracting entity), acting as a processor; the private buckets use server-side AES-256 encryption with provider-managed keys, and no separate external key management service is used | Only the minimum information needed to encrypt the attachment objects above | When attachment upload is enabled |
| Exchange-rate service | api.frankfurter.dev, an independent third-party open-source service that republishes European Central Bank reference rates, acting as an independent controller for the connection it receives; hosted in the European Union | Receives the base currency code, plus the connection metadata inherent to any request, including the IP address; returns reference rates | When you open currency conversion or refresh rates in Better Calc Pro |
| Error or security monitoring | None. No error, crash, or analytics monitoring service is used in the App or on the server; role according to the production configuration | Not applicable | When actually used; enter “None” if not used |
| Direct payment/merchant of record | Not applicable; direct website sales are not enabled; role as identified at checkout | Order, payment, tax, refund, invoice, and fraud prevention; full card information is processed by that provider | When direct website sales are enabled |
| Professional advisers, auditors, and insurers | Region relevant to the matter; subject to confidentiality and professional duties | Limited information necessary for disputes, audit, compliance, insurance, and corporate transactions | When necessary |
| Judicial, regulatory, and law-enforcement authorities | Competent authority | Information necessary to comply with law or protect substantial interests | Where legally applicable |
For an export of personal information from Mainland China, the overseas recipient’s legal name, contact details, and individual-rights channel are: Alibaba Cloud (Singapore) Private Limited (the Alibaba Cloud International contracting entity), 51 Bras Basah Road #03-06, Lazada One, Singapore 189554, with data stored and processed in Japan, acting as a processor for website and database hosting, transactional email (DirectMail), and private object storage. To exercise rights in relation to that processing, contact us at support@bettermac.net; we will pass the request on and respond. That provider also publishes its own privacy contact details on its official website. If a provider change creates a new category, materially new purpose, or new high-risk international transfer, we update this table before the change takes effect and complete required notice, assessment, contract, and consent steps.
Appendix C: Retention schedule
| Record | Primary-system period | Final deletion |
|---|---|---|
| Local diagnostics | No more than 7 days and 10 MiB by default; detailed mode no more than 30 minutes | Device-only rotation; the user may clear earlier |
| Website access logs | 30 days | Deleted by the lifecycle rule after expiry |
| Security, rate-limit, and general audit records | 30 days; material incident records may be extended for an investigation, claim, or legal requirement | An extension is limited to relevant records, which are deleted after expiry |
| Unverified support draft and attachments | 24 hours | Deleted by the expiry cleanup job |
| Case Magic Link | 24 hours and single-use | Invalid after use or expiry; expired record cleaned within 24 hours |
| Case session | 30 minutes idle or 8 hours maximum | Invalid record cleaned within 24 hours |
| Support attachments | During case handling; no later than five years after the most recent relevant verification or case-status update; closure shortens the deadline to 30 days, with earlier user deletion available | Deleted by the cleanup job after expiry |
| Raw Apple notifications and request headers | No more than 30 days | Deleted by the Apple-provider cleanup task |
| Apple purchase, renewal, refund, and revocation facts | No more than three years, subject to a longer period for an unresolved dispute or legal requirement | Deleted by the Worker or isolated for legal retention after expiry |
| Case text and status | Deleted or anonymized 2 years after closure; a formal deletion request may start earlier | Subject to legal hold |
| Recovery challenge, one-time link, and session | 15 minutes; an exchanged token cannot be replayed | Expired record cleaned within 24 hours |
| Admin pre-authentication challenge | 10 minutes | Expired record cleaned within 24 hours |
| Admin session | 12-hour maximum and 30-minute idle expiry | Revoked or expired record cleaned within 24 hours |
| Direct order, payment, refund, invoice, and tax records | 10 years from the end of the relevant tax year, and 30 years for vouchers that form part of statutory accounting records under Chinese accounting-archive rules, or a longer period required by applicable law | Deleted/anonymized after the legal period and any pending dispute |
| License and device records | While the License remains valid; 3 years after termination, refund, or end of relationship. Necessary entitlement records for a perpetual License remain while it is valid | Device detail is deleted or aggregated when no longer necessary |
| High-risk administrative actions, License resets, and security-incident audit | 3 years or longer while a relevant investigation or claim remains pending | Deleted or anonymized after the period |
| Privacy-rights request, complaint, consent, and assessment records | 3 years after closure, or a longer legally required period | Retain only the minimum needed to evidence handling |
Appendix D: Regional supplements
D1. Mainland China
Legal grounds and notice. We process personal information under the Personal Information Protection Law and other applicable laws and provide clear notice before processing of the handler’s identity and contact details, purposes, methods, categories, retention period, and rights channels. Where consent is required, it must be voluntary, explicit, and based on full knowledge. We obtain separate consent where required for sensitive personal information, disclosure to another handler, public disclosure, or provision outside Mainland China.
Necessity and consequences of refusal. We process necessary information only where required to conclude or perform a contract to which you are a party, comply with legal duties, respond to an emergency, or rely on another statutory ground. Refusing optional attachments, analytics, or marketing does not affect core functions. Refusing an email address, order relationship, or License-verification information may make online support, delivery, or recovery impossible.
Sensitive information. Before processing sensitive personal information that may include order or refund property information, we explain necessity and impact on rights and apply strict protection. Do not send full payment credentials, passwords, or government identifiers to support.
Disclosures and cross-border transfers. A processor contract limits purpose, period, method, category, and safeguards. Before disclosure to another handler or provision outside Mainland China, we complete the required notice, identify the recipient and rights channel, conduct a personal information protection impact assessment, and implement a security assessment, standard contract, certification, filing, or other applicable mechanism. We obtain separate consent where required. Related assessments and processing records are retained for at least the legally required period.
Rights. You may know, decide, restrict or refuse processing; access, copy, correct, supplement, delete, or transfer information; and request an explanation of the rules. A close relative may exercise relevant rights relating to a deceased individual for a lawful and legitimate interest. If a request is denied, you may request reasons and pursue a complaint or legal remedy.
Local representative. If Beijing Habitai Technology Co., Ltd is an overseas handler and the extraterritorial rules of the Personal Information Protection Law apply, we will establish a dedicated office or appoint a representative in Mainland China and place its name and contact details in Section 2 and Appendix B: Not applicable; the operating entity is registered in Mainland China.
D2. EEA and UK
Controller and legal bases. Beijing Habitai Technology Co., Ltd is the controller for processing described in this Policy. Section 5 identifies performance of contract, legal obligation, legitimate interests, and consent. If special-category data is processed, we identify an additional applicable condition; we do not ask you to submit such data.
Rights and complaints. You may exercise rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights concerning automated decisions. You may object to processing based on legitimate interests, and an objection to direct marketing is effective at any time. You may complain to a supervisory authority in your habitual residence, workplace, or the place of the alleged infringement, although we encourage use of Section 14 first.
International transfers. For information transferred outside the EEA or UK, we use an adequacy decision, European Commission Standard Contractual Clauses, the UK IDTA/UK Addendum, or another valid mechanism and, where necessary, encryption, access limits, and a transfer impact assessment. The Apps are available in the EEA and the United Kingdom; privacy enquiries and rights requests from those territories are handled through support@bettermac.net and the postal address given above.
UK complaint procedure. For a data protection complaint subject to UK law, we provide an electronic complaint channel, acknowledge receipt within 30 days, conduct an appropriate investigation without undue delay, keep the complainant informed, and communicate the outcome.
D3. California and other applicable U.S. states
This section applies only where the relevant state privacy law applies to BetterMac and the processing.
Categories and sources. During the preceding 12 months, we may have collected the categories listed in Appendix A: identifiers (email, IP, order or transaction identifiers), commercial information (purchase, refund, and License information), internet or network activity (requests and security events), device and technical information, customer-support communications, and necessary audit information. Sources are described in Section 8, and business or commercial purposes are described in Section 5.
Disclosures. We may disclose applicable categories to service providers, contractors, or third parties in Appendix B for hosting, email, payment, support, security, audit, and legal purposes. We do not sell personal information or share it for cross-context behavioral advertising, do not offer a financial-incentive program, and do not use sensitive personal information to infer characteristics or for a purpose beyond legally permitted uses.
Rights. Where applicable, you may request to know/access, delete, correct, or obtain a copy; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a denial. You will not be discriminated against for exercising a right. Because we currently do not sell, advertising-share, or use targeted advertising, an opt-out request will ordinarily be recorded as already satisfied. We recognize a qualifying browser opt-out preference signal where applicable law requires it.
Requests. Submit a request under Section 14. We may verify a request and accept a qualifying authorized agent. We do not require creation of a new account for an opt-out request and do not charge a fee prohibited by law.
Appendix E: Per-application supplements
This Policy applies to each BetterMac-branded macOS application listed in this Appendix. Sections 1 to 19 and Appendices A to D apply only to processing the relevant App actually performs; each entry describes its specific processing and exceptions. Adding a new App to this Appendix does not change the disclosures that applied when information was collected through an App you already used.
E1. Better UnArchiver
- Application. Better UnArchiver for macOS, bundle identifier
net.better.mac.unarchiver, distributed through the Mac App Store. - Core local operations (Section 4.1). Compression, extraction, listing, preview, integrity checking, and salvage of archive files. Archive files, archive contents, filenames, full paths, and archive passwords are processed on your Mac and are not automatically transmitted to BetterMac.
- Content passwords (Section 4.1). An archive password is held in memory for the current operation. It is written to the macOS Keychain only if you expressly choose to save it, is marked accessible on this device only, and is not synchronized to iCloud. BetterMac never receives it.
- Local records. Recent-task history, Free-tier monthly counters, preferences, and macOS security-scoped bookmarks are stored in the App’s sandbox container so that the features and permissions you select persist. They remain on the device.
- Diagnostics (Section 4.2). File sizes are recorded only as a coarse band (under 1 MiB, 1–10 MiB, 10–100 MiB, 100 MiB–1 GiB, over 1 GiB), never as an exact size and never with a filename or path.
- Support screenshot (Section 4.4). The screenshot feature captures only the Better UnArchiver content window, not the desktop, other applications, notifications, or the menu bar.
- Purchases (Section 4.5). Pro is a one-time, non-consumable Mac App Store in-app purchase, verified on the device through StoreKit. The App does not transmit transaction identifiers, receipts, or Apple Account information to BetterMac; Apple may separately send server notifications as described in Section 4.5. Only the value “free” or “pro” accompanies a support submission or an online help request.
- Connected features. Online help retrieval and customer support only. The App contains no analytics, advertising, attribution, or crash-reporting component, and makes no network request to any host other than bettermac.net.
- Direct sales. Not enabled for this App. Section 4.6, Section 4.7, and the corresponding rows of Appendices A, B, and C do not currently apply to it.
E2. BetterMac bmtop
- Application. BetterMac bmtop for macOS, command name
bmtop, released under the MIT License and distributed through GitHub Releases, Homebrew, and source code. - Core local operations (Section 4.1). Locally reads process, CPU, memory, network, disk, GPU, hardware, and sensor metrics; Apple Silicon also exposes SoC power, frequency, temperature, and fan status. Monitoring data is not automatically transmitted to BetterMac.
- Local records and output. bmtop has no telemetry or runtime network client. Machine-readable JSON redacts hardware identifiers by default, and output is produced only when you run or save it in the terminal.
- Permission boundary. Normal collection needs no administrator access and runs no daemon. Only an explicitly requested enhanced sample or operation on another user’s process invokes a constrained
sudopath with a fixed binary and arguments. The TUI does not run as root and does not store passwords. - Process control. Termination requires your confirmation and revalidates the PID and process start time before sending a signal. PID 0, PID 1, and bmtop itself are protected.
E3. Better Monitor
- Application. Better Monitor for macOS, bundle identifier
net.better.mac.monitor, distributed through Homebrew Cask and signed direct releases. - Core local operations. The app reads process, CPU, memory, disk, network, port, startup-item, battery, and sensor information through macOS interfaces and stores monitoring history locally. It does not automatically upload monitoring data.
- Connected features. A public-IP lookup is sent to
api.ipify.orgonly when you request it. If you configure an AI provider and request a summary, the selected process snapshot is sent to that provider. The API key is sent only to that provider as request authentication, is not included in the prompt or process snapshot, and is not sent to BetterMac. The provider’s own retention and training terms apply. - Support. When you open the support link, your browser visits BetterMac support. A support request sends only the information you enter; optional attachments require separate review and consent. The app does not run an automatic crash-reporting or analytics service.
- Local controls. API keys are stored in macOS Keychain. You can clear monitoring history and local AI conversations in the app; clearing local data does not retract information you already submitted to a third-party AI provider or support channel.
E4. Better Cleaner
- Application. Better Cleaner for macOS, bundle identifier
net.better.mac.cleaner, distributed through the Mac App Store. - Core local operations (Section 4.1). Scanning folders you have expressly authorized for large files, duplicate files (including SHA-256 and byte-by-byte comparison) and similar images, storage-usage analysis, identifying development build artifacts and tool caches (“Developer Storage”), browsing installed applications and their associated files, and moving items you confirm — including an application you uninstall — to the Trash. Files, file contents, filenames, and full paths are processed on your Mac and are not automatically transmitted to BetterMac.
- Local records. macOS security-scoped bookmarks for folder authorizations, clean-up history and deletion receipts, the monthly free-cleanup allowance counter, and preferences are stored in the App’s sandbox container so that the permissions you grant and the actions you take persist. They remain on the device.
- Diagnostics (Section 4.2). The App may record allowlisted events and environment fields locally using a versioned diagnostics schema: event codes, components, stages, error codes, duration bands, count bands, size bands, formats, and environment information, including the entitlement value
freeorpro. It excludes filenames, full paths, file contents, bookmarks, user names, email addresses, License keys, and other secrets. Retention and optional export follow Section 4.2; scan results and file contents are not uploaded. - Support screenshots and attachments (Section 4.4). A support screenshot captures only the Better Cleaner content window. Screenshots and redacted diagnostics packages are entirely optional and subject to the individual and combined limits shown in the App and support service. You must preview and separately consent to every attachment; refusing or removing an attachment does not prevent independent text feedback.
- Purchases (Section 4.5). Pro is an auto-renewable Mac App Store subscription offered in one subscription group with two tiers, monthly and yearly, each with a one-week free trial for eligible accounts, verified on the device through StoreKit. Billing, renewal, cancellation, and refunds are handled by Apple. The App does not upload transaction identifiers to us. The App Store Server Notifications intake described in Section 4.5 is not enabled for this App: we do not receive purchase, renewal, refund, or revocation notifications for it, so no purchase-history processing takes place for this App.
- Connected features. When you open the in-app Support Center, the App reads a support configuration (available categories, size limits, service availability) once from
https://bettermac.net/v1; that request contains nothing you typed. Only when you submit a case are the email address and text you entered sent, and screenshots or a diagnostics package are uploaded only after you preview and consent to each one. Terms, privacy, and refund pages open in your default browser. Apart from those requests and StoreKit purchases handled by Apple, the App makes no network requests and contains no analytics, advertising, attribution, or automatic crash-reporting component. - Direct sales. Not enabled for this App. Section 4.6, Section 4.7, and the corresponding rows of Appendices A, B, and C do not currently apply to it.
E5. Better Share
- Application. Better Share for macOS, bundle identifier
net.better.mac.share, distributed through the Mac App Store. - Core local operations (Section 4.1). Discovering devices on the same LAN, binding trusted devices, sending and receiving files and folders, and sharing or receiving files through a browser link. File contents, filenames, and destination paths travel only between your Mac and the peer device; they do not pass through a BetterMac server and are not transmitted to BetterMac.
- Local network broadcast. While running, the App publishes over Bonjour on the local network an editable display name (your Mac’s name by default), the first 8 characters of a random device identifier, the supported capabilities, and the operating system type. It does not publish hardware identifiers, network addresses, or Apple Account information.
- Local records. Bound devices, transfer history (peer name, filenames, sizes, state, and timestamps; for browser uploads also the browser name and LAN IP address), the clipboard event log, and preferences are stored in the App’s sandbox container and remain on the device. You can clear the history in the App or export it as CSV / JSON.
- Clipboard. Clipboard monitoring is off by default. When enabled, only metadata (type, size, filename, and the first 80 characters of text) is read to show a prompt; items from password managers and text that looks like keys, certificates, or one-time codes are suppressed and produce no prompt. A link is generated or a transfer sent only when you click.
- Keys. The device identity key and pairing keys are stored only in the macOS Keychain, marked accessible on this device only, and are not synchronised through iCloud Keychain. Files received over the network are given the macOS quarantine attribute.
- Diagnostics (Section 4.2). The App contains no analytics, advertising, attribution, or crash-reporting component and makes no network request to the internet; all network traffic stays within your LAN.
- Purchases (Section 4.5). The App is free and contains no in-app purchase or subscription.
- Direct sales. Not enabled for this App. Section 4.6, Section 4.7, and the corresponding rows of Appendices A, B, and C do not currently apply to it.
E6. Better Calc Pro
- Application. Better Calc Pro for macOS, bundle identifier
net.better.mac.calc, distributed through the Mac App Store. - Core local operations (Section 4.1). Expression parsing and evaluation, the multi-line worksheet, variables, history, unit conversion, the formula library, and the command palette all run on your Mac. The expressions, values, and results you enter are not transmitted to BetterMac.
- Local records. Worksheets, history, variables, formulas, conversion favourites and conversion history, the cached exchange rates, and settings are stored as JSON in the App’s sandbox container; preferences are stored in macOS UserDefaults. They remain on the device, and you can clear the history or delete worksheet lines in the App.
- Connected features. The App makes one network request: when you open currency conversion or refresh rates, it asks
https://api.frankfurter.dev, an independent third-party service that republishes European Central Bank reference rates, for those rates. The request carries only the base currency code, with no identifiers, device information, expressions, or other user content. As with any network request, that provider necessarily sees the connection metadata, including your IP address. Rates are cached on your Mac with a timestamp; offline, the last successful rates are reused and labelled as such in the interface. - Clipboard. The clipboard is read only while you have switched on Pin on Top in the compact calculator, and only its arithmetic part (digits, operators, parentheses, and decimal separators) is used; dates, phone numbers, times, IP addresses, version strings, and similar content are discarded. Text the App itself copied is never read back. Turning off Pin on Top stops reading immediately. The clipboard text itself is never stored, logged, or transmitted; if you then calculate the arithmetic that was extracted, that expression and its result are saved to local history like any other calculation.
- Permission boundary. The App requests no system permissions: no Accessibility, Screen Recording, Full Disk Access, or Automation. The global hotkey is registered through a system API that needs no Accessibility trust and does not observe keystrokes outside the App’s windows. The sandbox declares exactly two entitlements: the App Sandbox itself, and outgoing network access for the exchange-rate request. The App declares no file-access entitlement, has no open or save panels, and does not scan or index the file system.
- Diagnostics (Section 4.2). The App contains no analytics, advertising, attribution, or crash-reporting component and makes no network request to any host other than the exchange-rate service above.
- Scope of the general sections. The App has no diagnostics subsystem, makes no online-help request, contains no in-app purchase, and stores nothing in the Keychain. The second paragraph of Section 4.3, the local-diagnostics parts of Section 4.2, Section 4.5, and the Keychain paragraph of Section 4.1 therefore do not apply to it, together with the matching rows of Appendices A and C.
- Purchases (Section 4.5). The App contains no in-app purchase or subscription.
- Direct sales. Not enabled for this App. Section 4.6, Section 4.7, and the corresponding rows of Appendices A, B, and C do not currently apply to it.
E7. Better Recorder Pro
- Application. Better Recorder Pro for macOS, bundle identifier
net.better.mac.recorder, distributed through the Mac App Store for Apple silicon Macs running macOS 15 or later. - Core local operations (Section 4.1). Screen recording, camera recording, and the combined picture-in-picture recording all run on your Mac. The resulting video and audio are written to the folder you choose. BetterMac does not receive, upload, or host recordings on its servers, and the App does not read or index anything beyond the recordings it saved.
- LAN Share. When you start LAN Share from the Library, Better Recorder temporarily runs an HTTP download service on your Mac on the selected local network interface and exposes only a snapshot of recordings that were in the Ready state when sharing started. The browser page is reachable only on the local network. It is download-only: visitors can list and download the shared recordings, but cannot upload files, play recordings in the browser, or access recordings added later. Each session uses a random temporary session token and, if enabled, a six-digit PIN. The session expires at the selected time—15 minutes, 1 hour by default, 4 hours, or until you stop it—and becomes unavailable when you stop sharing, the session expires, the network binding is lost or invalidated, or the App quits. Recordings are served directly from your Mac to the browser; BetterMac does not relay, receive, store, or host them, and LAN Share provides no cloud or Internet sharing. LAN Share uses local HTTP; we do not represent this transport as encrypted. Use it only on a network you trust. Better Recorder does not log or persist client IP addresses or raw User-Agent headers. A coarse device label shown in the current Activity view is kept only in memory and is cleared when the share session ends.
- Local records. Each recording’s index (duration, resolution, frame rate, codec, segment file names, and the display names of the sources you selected) and your preferences are stored in the output folder you chose and in macOS UserDefaults, and stay on the device. You can rename or delete a recording in the Library; deleting moves the file to the Trash.
- Permission boundary. The App asks only for what the sources you selected require: Screen Recording to capture a display or window, Camera for the camera modes, and Microphone only when you have actually selected a microphone. With no microphone selected, no microphone permission is requested. The App requests no Accessibility, Full Disk Access, or Automation permission; the sandbox declares only camera, audio input, and user-selected file read/write.
- iPhone as a camera or microphone (Continuity Camera). The camera and microphone lists show whatever capture devices macOS offers, which can include an iPhone that Apple’s Continuity Camera makes available. If you select one, its video, and its audio when you also select its microphone, is recorded into the same local file as any other source. The destination is unchanged and BetterMac still receives nothing. The App does not pair with, sign in to, or install anything on the iPhone: the connection is established and mediated entirely by Apple and macOS, and whether an iPhone appears at all depends on Apple’s own device, Apple Account, and proximity requirements. The App receives only the live camera and microphone streams that macOS hands to any capture client. It has no access to the iPhone’s screen contents, photos, files, contacts, messages, call history, location, health data, or notifications, and it declares no Bluetooth, USB, or local-network entitlement through which it could reach the device directly. An iPhone is never chosen for you: built-in and USB devices take priority, and a Continuity device is used only after you select it yourself.
- Capture-device names and identifiers. So that your source selection survives between sessions, the App stores the identifier macOS assigns to the camera and microphone you picked in macOS UserDefaults, and writes those devices’ display names into the recording index in your output folder. For an iPhone, that display name is the name you gave the device and may contain your own name. Both stay on your Mac. Device identifiers and device names are never included in the diagnostics log described below, in a feedback submission under Section 4.4, or in anything else sent to BetterMac.
- Recording other people. A recording can contain the faces, voices, and surroundings of identifiable people, and in some jurisdictions such material is sensitive personal information. Because the recording is created and kept on your Mac, you decide what to capture and you are the party responsible for it: obtain the consent required where you are, and respect the rules of the meeting, workplace, or venue. BetterMac has no copy of the recording and therefore cannot retrieve, delete, or disclose one on anyone’s behalf.
- Diagnostics (Section 4.2). The local diagnostics log is off by default; you switch it on in Help & Support › Diagnostics. It is kept for 7 days, capped at 10 MB, and switching it off deletes what was already collected. Entries contain only an event code (such as
recording.completed), a timestamp, the App version and build, the macOS version, the machine architecture, the interface language, the valuefreeorpro, and bucketed durations and file sizes. They never contain recording content, file names, folder paths, window or application titles, device serial numbers, Apple Account information, or transaction identifiers. - Customer support (Section 4.4). Data reaches BetterMac only when you submit feedback yourself in Help & Support › Feedback: the email address you enter, the title and description you write, optional reproduction steps, and the diagnostics package above only after you tick consent for that specific attachment. The App offers no automatic screenshot attachment and never captures your screen or camera for support purposes.
- Purchases (Section 4.5). Pro is a one-time, non-consumable Mac App Store in-app purchase, verified on the device through StoreKit. The App does not transmit transaction identifiers, receipts, or Apple Account information to BetterMac; Apple may separately send server notifications as described in Section 4.5. A support request carries only the value
freeorpro. - Connected features. Customer support (
bettermac.net) and Apple’s own StoreKit traffic are the only BetterMac/Internet network activity. LAN Share is a user-initiated direct connection from the Mac to devices on the same local network; it does not send recordings to BetterMac. The App contains no analytics, advertising, attribution, or crash-reporting component, and makes no request to any host for statistics or update checks. - Direct sales. Not enabled for this App. Section 4.6, Section 4.7, and the corresponding rows of Appendices A, B, and C do not currently apply to it.
E8. Better Moment
-
Application. Better Moment for iOS, bundle identifier
net.better.mac.moment, intended for distribution through the App Store. A macOS edition may follow later; until then this entry covers iOS only. -
Core local operations (Section 4.1). On-device scanning and grouping of similar, duplicate, blurry, and screenshot photos; review drafts; confirmed deletions that move items to Recently Deleted in Apple Photos. Photo contents and derived features stay on the device for analysis and are not automatically uploaded to BetterMac.
-
Local records. Scan indexes, review drafts, preferences (including UserDefaults / App Group preferences), and optional Share Extension imports remain in the App sandbox / App Group container on the device.
-
Documents and receipts. Identity documents and receipts are presented for manual review only and are not auto-selected for removal.
-
Purchases (Section 4.5). Not enabled for the initial free release. In-app purchases and subscriptions are out of scope until separately disclosed.
-
Connected features. Opening Privacy / Terms / Support pages in Safari and optional email to support@bettermac.net that you initiate. The App contains no analytics, advertising, attribution, or automatic crash-reporting component, and does not upload photos for cloud inference.
-
Direct sales. Not enabled. Section 4.6, Section 4.7, and the corresponding rows of Appendices A, B, and C do not currently apply to it.
-
Additional local processing and controls. This includes existing photo-location metadata, Vision face quality/landmarks (not identity recognition), transient OCR for classification, locally retained barcode content, local notifications, and imported filenames/hashes. Clear All Better Moment Data removes App records and active/removed/temporary imported copies without changing Photos originals or system-managed backups. Unresolved operations block clearing; a partial failure is reported for retry. See the product privacy notice for scope, retention and the 2026-09-20 change summary. Apple-managed iCloud downloads and synchronization are separate from BetterMac website/email processing.