Privacy

Doghouse has no accounts, no telemetry and no tracking. This page explains the little data that does exist, and why.

At a glance

Who we are

Sprout Media Limited is the data controller for the processing described here.

This policy covers the Doghouse macOS application and the doghousevault.com website. Purchases are additionally covered by the privacy policy of Polar, our payment provider (see “Buying a licence”).

What the app collects

Almost nothing. To be specific about the negatives: Doghouse does not create an account, does not identify you, does not log what you do, does not read your files, and never transmits vault contents, file names, passwords or encryption keys. There is no analytics SDK and no crash reporter.

The app makes network requests in two situations only.

1. Update check

Doghouse asks doghousevault.com/api/version.json whether a newer version exists — at most about once a day, and when you press “Check Now”. The request contains no identifiers we generate. As with any web request, our server and Cloudflare can see your IP address, user agent and the time of the request.

Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in letting people know about security fixes and new versions. You can turn this off at any time in Settings → “Tell me when an update is available”, after which the app makes no update requests at all.

2. Licence activation

If you buy a licence and enter your key, the app contacts Polar once to activate that Mac. It sends the licence key, our organization identifier, and a device label. The device label is your Mac’s name as macOS reports it — please note that Mac names often contain a personal name (for example “Anna’s MacBook Air”). It is sent so that you can recognise and deactivate your own devices. If you would rather not send it, rename your Mac in macOS System Settings before activating.

After a successful activation the key is stored in your Mac’s Keychain and the app does not contact Polar or us again, unless you deactivate the Mac. Legal basis: performance of a contract (Article 6(1)(b) GDPR) — verifying the licence you bought.

This website

The site is a set of static files served by Cloudflare. There are no analytics, no advertising pixels and no tracking of any kind. No third party collects information about your activity across websites, here or elsewhere.

Cookies: this site sets no cookies. Cloudflare may set a strictly necessary security cookie when it needs to protect the site against automated abuse; that is used only for security and not for tracking, and requires no consent under the ePrivacy rules. You will not see a cookie banner because there is nothing to consent to.

Do Not Track: some browsers send a “Do Not Track” signal. We do not track visitors across websites in the first place, so no change of behaviour is required — the signal is honoured by design. The same is true of Global Privacy Control signals.

Cloudflare processes standard request logs (IP address, user agent, requested URL, timestamp) to serve the site and protect it from attack. Legal basis: legitimate interests (Article 6(1)(f)) in security and reliable delivery.

Buying a licence

Purchases are handled by Polar Software, Inc. as merchant of record. Polar takes the payment, issues the invoice, handles tax, and emails your licence key. For that payment and billing data Polar acts as an independent data controller under its own privacy policy, not on our behalf — see polar.sh/legal/privacy.

We never see your card details. What reaches us from Polar is limited to what we need to support your purchase, such as the email address used and the licence details. For the licence activation described above, Polar acts as our processor under a data processing agreement.

Contact form

If you write to us through the contact page, the message is delivered by Cloudflare Email Routing to our company mailbox at our mail host. We receive the name, email address and message you provide, and use them only to reply and to keep a record of the request. You are not added to any mailing list. Legal basis: legitimate interests (Article 6(1)(f)) in answering enquiries, or performance of a contract where the enquiry concerns your purchase.

Who your data reaches

We do not sell, rent or share personal data for advertising, profiling or any other purpose, and we never have. We disclose data otherwise only where the law requires it.

International transfers

Both Cloudflare and Polar are based in the United States, so some data is transferred outside the European Economic Area. Those transfers are made under the EU–US Data Privacy Framework where the recipient is certified, and/or under the European Commission’s Standard Contractual Clauses together with an assessment of the transfer. You can request a copy of the safeguards through our contact form.

How long we keep things

Security

Vaults are encrypted on your Mac with AES-256, using Apple’s own encrypted disk image format. Traffic between the app, this site and Polar uses TLS. Because the encryption keys never leave your device, we hold nothing that could expose your files — and, for the same reason, we cannot recover a vault whose password has been lost.

Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, and to data portability. We make no automated decisions that produce legal effects.

Right to object: where we rely on legitimate interests — the update check, server logs and contact correspondence — you may object at any time through our contact form. You can also stop the update check yourself in the app’s Settings.

To exercise any right, use our contact form and choose “Privacy or data request”. We reply within one month, free of charge, and you will never be treated differently for asking.

If you believe we have handled your data improperly you may complain to the Irish supervisory authority:

Children

Doghouse is not directed at children. We do not knowingly collect personal data from anyone under 16 in Ireland, or under 13 in the United States. If you believe a child has sent us personal data, write to us and we will delete it.

United States residents

California. We are not a “business” as defined by the California Consumer Privacy Act — we fall well below every threshold in the Act. Regardless, we do not sell or share personal information, have never done so, and do not use it for cross-context behavioural advertising. That is why you will not find a “Do Not Sell or Share My Personal Information” link here: there is nothing to opt out of. California residents may still ask us to access or delete their personal information through our contact form, and we will honour it voluntarily.

Reviewing or changing your information. Because we hold so little, the fastest route is the contact form; we will tell you what we have, correct it, or delete it.

Other states. The consumer privacy laws of Virginia, Colorado, Connecticut, Utah and Texas do not currently apply to a company of our size and activity. The commitments on this page apply to everyone regardless of where they live.

Changes to this policy

If we change this policy we will update the date below. Where a change is material — for example a new recipient of data or a new kind of processing — we will additionally post a notice on this website before it takes effect.

Sprout Media Limited · Registered in Ireland, company number 525040 · 26 Upper Pembroke Street, Dublin D02 X361 · VAT IE2975141FH
Effective date: 30 August 2026 · Last updated: 30 August 2026