← Back to the store

Privacy policy

Last updated 24 September 2026 · Policy no. 001

Punchcard is a Mac app that watches which app is in front of you and prints a receipt about it. It does this entirely on your Mac. This policy is short because there is very little to describe.

What the app collects

While Punchcard is running it records, on your Mac only:

  • The name and bundle identifier of the application currently in the foreground, sampled every few seconds.
  • Whether your Mac has been idle, so that stepping away is not counted as work.
  • Only if you switch on itemized browsing: the website name (for example github.com) of the front tab in Chrome, Brave, Edge or Vivaldi. Never the full address, never the page title, and never anything from an incognito window.
  • The settings you choose: your clock-out time, working days, paper style, excluded apps and websites, and sound preference.

It does not record window titles, document names, file paths, full web addresses, page titles, keystrokes, screen contents, your location, or anything you type. Out of the box it requests no macOS privacy permissions: not Accessibility, Screen Recording, Full Disk Access, Contacts, or Camera, because it does not need them. Itemized browsing is the one exception, and it stays off until you switch it on: macOS then asks, once per browser, whether Punchcard may read the address of that browser's front tab. We keep the site name and discard the rest on the spot. You can switch it off in Punchcard's settings, or revoke it any time in System Settings, Privacy & Security, Automation.

What leaves your Mac

Your tracked day, never. Punchcard makes exactly one kind of network call: activating your license key. That call sends the key and this Mac's name to the payment provider and gets back a yes or no. It happens when you enter a key, and once on launch to catch a refund.

Nothing else in the app can reach the network, and that is enforced at build time rather than promised. Every release is blocked by two automated build gates: one that fails if a networking symbol appears anywhere in the source outside the single licensing file, and one that fails if the compiled binary references any analytics, crash-reporting or telemetry library. Your app names, website names, minutes and receipts are never sent anywhere.

There is no account, no login, no cloud sync, no backup service, no analytics, no crash reporting, no advertising identifier, and no telemetry of any kind, anonymous or otherwise. Tracking itself works with no connection at all; only activation needs one.

Where your data lives

In a single SQLite file on your Mac:

  • ~/Library/Application Support/Punchcard/punchcard.sqlite

You can inspect it, back it up, or delete it at any time. Deleting that file erases every day Punchcard has recorded. Deleting the app and that file removes Punchcard completely; there is no server-side copy to request, because there is no server.

Receipts you share

When you export a receipt, the image is written wherever you choose to save it, and a plain-text version is placed on your clipboard for use as alt text. Punchcard does not upload it anywhere. What happens to a receipt after you post it is between you and whichever app you posted it to.

Buying Punchcard

Payment happens on this website, not inside the app. Our payments are handled by Dodo Payments, which acts as the merchant of record. When you buy, Dodo collects your email address, billing details and the information needed to process the payment and charge the correct tax, and sends you a license key and an invoice. That information is held by Dodo under their privacy policy. We receive your email address, your country, and the fact that you bought a license; we never see your full card details.

This website

This site is static HTML. It sets no cookies, runs no analytics, embeds no trackers, and loads no third-party scripts or fonts. Our host records standard server request logs for security and reliability. Following the checkout link takes you to Dodo Payments, where their own policy applies.

Children

Punchcard is not directed at children under 13 and we do not knowingly collect information from them.

Your rights

Because the app holds your data locally and we hold none of it, most data requests are answered by your own Finder. For anything held by Dodo Payments in connection with a purchase (access, correction, export or deletion), email hey@everydaymactools.com and we will action it with them.

Changes

If this policy changes, the updated date at the top changes with it. Material changes will be noted on this page. We will not add tracking to Punchcard; if that ever ceased to be true, it would be a different app with a different name.

Contact

Punchcard is made by Caretopia Network Private Limited. Questions to hey@everydaymactools.com.