Privacy policy
Last updated: August 25, 2026
Station is a local-first Mac app with no telemetry. The website uses Umami Cloud and Vercel Web Analytics for aggregate analytics on a small set of public pages. The app can be tried without an account or card. A Clerk account is used for purchase, license recovery, device-code activation, and account management.
What Station stores
What Station collects about you
The Mac app does not collect analytics or crash reports. On tracked public website pages, Umami Cloud and Vercel Web Analytics receive the page path without its query string or hash, the referring public Station page without its query string or hash (or only the referring site's origin for external and private referrers), and coarse device, browser, and country context. Umami also records a download-click event whose only event property is its placement, such as the header, hero, closing call to action, or account area.
Private paths and admin, account, checkout, license, activation, sign-in, and sign-up paths are not included in page-view analytics. The website account area stores the minimum records needed for licensing: Clerk user ID, email, Paddle customer and transaction IDs, license status, active device labels, device hashes, signed lease metadata, and hashed request IP buckets used to protect the public license API from abuse.
Purchase and account services
Clerk provides authentication for the account center. Paddle is the merchant of record for checkout, receipts, invoices, refunds, and payment portal access. Station receives Paddle webhook events so it can issue or revoke licenses.
The Mac app contacts Station servers to activate a license key, poll a device-code activation, refresh a signed license lease, or deactivate a Mac. It can keep running during the offline grace window using the signed lease stored locally.
AI Doctor and your data
AI Doctor is off until you configure a provider and approve local inspection. When you run a diagnosis, Station sends redacted evidence - runtime status, port listeners, log excerpts, manifest summaries, and env variable key names only - to OpenAI using your own API key. Secret values are redacted before anything is sent. Your use of OpenAI is governed by OpenAI's own terms and privacy policy.
By policy, AI Doctor never reads Keychain or credential stores, SSH or GPG material, cloud and Kubernetes credentials, browser profiles, or Mail and Messages data.
Contact
Questions about this policy: support@usestation.app