← Back to the store

Privacy policy

Last updated 20 August 2026 · Policy no. 001

Punchcard is a Mac app that watches which app is in front of you and prints a receipt about it. It does this entirely on your Mac. This policy is short because there is very little to describe.

What the app collects

While Punchcard is running it records, on your Mac only:

  • The name and bundle identifier of the application currently in the foreground, sampled every few seconds.
  • Whether your Mac has been idle, so that stepping away is not counted as work.
  • The settings you choose: your clock-out time, working days, paper style, excluded apps and sound preference.

It does not record window titles, document names, file paths, browser tabs, URLs, keystrokes, screen contents, your location, or anything you type. It requests no macOS privacy permissions: not Accessibility, Screen Recording, Full Disk Access, Contacts, or Camera, because it does not need them.

What leaves your Mac

Nothing. Punchcard contains no networking code at all. Every release is blocked by two automated build gates: one that fails if a networking symbol appears anywhere in the source, and one that fails if the compiled binary references any URL-loading symbol. A build that could reach the internet does not ship, because it does not build.

There is no account, no login, no cloud sync, no backup service, no analytics, no crash reporting, no advertising identifier, and no telemetry of any kind, anonymous or otherwise.

Where your data lives

In a single SQLite file on your Mac:

  • ~/Library/Application Support/Punchcard/punchcard.sqlite

You can inspect it, back it up, or delete it at any time. Deleting that file erases every day Punchcard has recorded. Deleting the app and that file removes Punchcard completely; there is no server-side copy to request, because there is no server.

Receipts you share

When you export a receipt, the image is written wherever you choose to save it, and a plain-text version is placed on your clipboard for use as alt text. Punchcard does not upload it anywhere. What happens to a receipt after you post it is between you and whichever app you posted it to.

Buying Punchcard

Payment happens on this website, not inside the app. Our payments are handled by Dodo Payments, which acts as the merchant of record. When you buy, Dodo collects your email address, billing details and the information needed to process the payment and charge the correct tax, and sends you a license key and an invoice. That information is held by Dodo under their privacy policy. We receive your email address, your country, and the fact that you bought a license; we never see your full card details.

This website

This site is static HTML. It sets no cookies, runs no analytics, embeds no trackers, and loads no third-party scripts or fonts. Our host records standard server request logs for security and reliability. Following the checkout link takes you to Dodo Payments, where their own policy applies.

Children

Punchcard is not directed at children under 13 and we do not knowingly collect information from them.

Your rights

Because the app holds your data locally and we hold none of it, most data requests are answered by your own Finder. For anything held by Dodo Payments in connection with a purchase (access, correction, export or deletion), email hey@punchcard.app and we will action it with them.

Changes

If this policy changes, the updated date at the top changes with it. Material changes will be noted on this page. We will not add tracking to Punchcard; if that ever ceased to be true, it would be a different app with a different name.

Contact

Punchcard is made by Caretopia Network Private Limited. Questions to hey@punchcard.app.