Privacy & permissions
Last updated: October 2, 2026
Windsify Mac operates locally. No telemetry, no account, no analytics — typed text is never collected or sent. This page explains keyboard processing, optional support reports, permissions, and what this website collects.
The Accessibility permission
Windsify Mac uses Accessibility permission to:
- actively translate keyboard events;
- identify the frontmost application and focused control;
- obtain the focused window;
- move, resize, minimize, and restore windows.
Windsify Mac does not use Accessibility to read or store the text you type. Its logs never include characters, clipboard contents, window titles, document names, or accessibility values from text controls.
Input and event data
The event engine evaluates virtual key codes, modifier flags, event phase, and the frontmost application's bundle identifier — in memory. Each event is discarded as soon as the matching action is selected. There is no background keyboard recording, telemetry, or account system. The optional Shortcut Help test described below keeps one shortcut in memory for your review.
Optional Shortcut Help reports
In Settings → Shortcut Help, clicking Test shortcut starts a diagnostic session for one shortcut. It stops after that shortcut, ten seconds, cancellation, or leaving Windsify. Windsify previews the mapping without executing the command; macOS may still handle reserved system keys before they reach the test.
The report is filled in automatically: app and macOS versions, edition, keyboard-service and permission states, known conflict identifiers, input-source identifier, the function-key preference when available, and a limited list of connected keyboard product names, vendor/product IDs and transports. When accessible, it also includes numeric F1–F12 pairs from the keyboard driver’s advertised function-row mapping. This metadata lookup does not monitor raw HID input events. One test event can include its original key code, modifiers, event type, keyboard type and matching rule. The connected keyboard list does not identify which device sent the event.
Reports stay in memory. You can review the complete report, copy it, or open an email draft to hello@windsify.com. Nothing is sent until you send that email. Starting another test replaces the previous result; quitting Windsify discards it. Reports contain no typed text, clipboard contents, window titles, document names, license keys, Accessibility text or device serial numbers.
Network
Core keyboard and window functionality requires no network connection.
License activation, validation, and deactivation contact Polar's public customer license API. Those requests contain the license key, Windsify's Polar organization identifier, and — after activation — the device activation identifier. They do not contain typed text, clipboard contents, window titles, document names, or Accessibility values.
The 14-day trial stores its authoritative first-launch and most recently observed dates in the macOS Keychain, with Application Support and UserDefaults migration mirrors. The license key, device activation identifier, most recent successful validation time, and an authoritative inactive status when Polar rejects the license are stored together in the macOS Keychain for license recovery and offline access.
Windsify uses Sparkle to check the signed update feed at windsify.com/appcast.xml. You can start a check from the app menu, and Sparkle asks for permission before enabling scheduled checks. You can also explicitly choose to download and install future updates automatically.
Update requests expose ordinary HTTPS connection metadata and the update client user agent; system profiling is disabled. They do not include the license key, typed text, clipboard contents, window titles, document names, or Accessibility values. Signed and notarized update archives are downloaded from the public Windsify release repository.
Buy, Manage License, and Source open their corresponding pages in the system browser.
Screen Recording and optional screenshots
Core keyboard and window features use Accessibility and do not need Screen Recording. Optional frozen selection capture in Pro, including Ctrl+Shift+4 and Screenshot → Capture Selection to Clipboard, requires Screen Recording permission.
When you start frozen capture, Windsify takes snapshots of the current displays and holds those screen pixels in memory as passive backgrounds beneath the native macOS region selector. The selected area is copied to the system clipboard. Windsify removes the frozen backgrounds when selection finishes or is cancelled; the selected image remains in the clipboard until replaced or cleared. Windsify does not upload these images or save an image file in this capture path. A screenshot can include anything visible in the selected area, so check it before pasting or sharing it.
The ordinary Pro Win+Shift+S mapping invokes native macOS Control+Shift+Command+4 clipboard selection without the frozen backgrounds. Inside Windsify's own secure text fields, its local shortcut handler uses frozen capture for this chord too, so that path also needs Screen Recording. See the screenshot shortcut guide.
Purchase, review and feedback links
When you choose to buy from the app, fixed labels identify the purchase entry: menu, Free mode banner or License settings. These labels contain no user or installation identifier. Review links open Product Hunt in your browser; you choose whether to sign in and submit a review. Feedback links open an email draft for you to review and send. Email feedback stays private unless you give permission to publish it.
This website
windsify.com serves static files and sets no cookies. Cloudflare Web Analytics counts visits and page views, while anonymous product actions such as downloads, lead submissions and checkout clicks are stored only as aggregate counters. The site uses browser sessionStorage for the current tab session to remember only the landing page language, a language-neutral content label, and anonymous campaign/provider labels. This lets a later download or checkout be attributed to the language and source that first brought that tab session to the site. It does not create or store a random visitor ID, and the attribution is not carried across browser sessions. Recognized search-engine or assistant referrers retain only the provider name, never the referrer URL, search terms, conversation URL, or typed content. These anonymous attribution labels may be carried into Polar checkout so aggregate page-language, landing-language, checkout and order performance can be compared.
Purchases are handled by Polar as the merchant of record. When you buy a license, checkout happens on Polar's pages and your payment details go to Polar — not to windsify.com. Polar's privacy policy governs checkout.
Questions
See Source & License for the Free and Pro edition terms. For anything else, email hello@windsify.com.