Back to legal Legal

Politica de privacidad

The app is local-first. The server receives limited operational data and a pseudonymous confirmation after the first healthy start to measure installations without duplicates.

This translation is provided for convenience. The Spanish version is legally controlling. Read the legally controlling Spanish version
Updated on Aug. 7, 2026

3C. Microsoft Store installation confirmation

The Microsoft Store package does not use the EXE installer's NSIS receipt. After the policies are accepted and the first healthy launch completes, it creates a random local identifier and sends a limited confirmation containing the version, build, architecture, launch time, and the hashed device fingerprint already used by presence.

The server derives a pseudonymous key with HMAC and counts at most one installation per device and channel. EXE and Store installations are displayed separately; a device that used both channels may appear once in each. This measurement is not the official Partner Center acquisition figure and excludes Store downloads that never opened the application.

3D. Estimated installation country

When an installation is first confirmed, the server may estimate the connection country to produce aggregate statistics by territory. The installation record retains only the two-letter ISO country code and does not store the IP address. The country may be unavailable or inaccurate when a VPN, proxy, or corporate network is used.

Per-device trial and commercial telemetry

To grant one trial per device, we process a hashed hardware fingerprint, the trial identifier and status, its start and expiry, platform, app version, and granted entitlements. The signed trial receipt is bound to that fingerprint. This record is retained to prevent reinstallations from generating repeated trials.

We may receive pseudonymous, idempotent commercial events for trial start or expiry, playback start and result, a reached limit, a skipped task, an unlock click, checkout start or cancellation, and a converted purchase. Accepted fields are limited to random or opaque identifiers, plan and mode, duration and result, version, platform, and time. Raw events are deleted after 90 days.

This flow does not collect macro names or content, keystrokes, windows, OCR content, screenshots, or paths. To measure conversion, the app may carry a signed opaque token through to the order; the device fingerprint is not placed in URLs or shared with the payment provider.

Abuse prevention, pseudonymous signals, and decisions

To maintain one trial per device and protect Free allowances, we may process a public key and its protection provider (TPM/CNG or protected storage), opaque grant and credential identifiers, and versioned HMAC commitments of device signals such as TPM, SMBIOS, motherboard, and MachineGuid. We do not retain those raw hardware values. We also process usage, cycle, and cooldown checkpoints, ledger-integrity hashes, and security events such as inconsistent clocks, restored state, rotated credentials, or concurrent use.

These signals are used to allow, recover, require Free, or refer a case to support. An IP, VPN, country, or shared network is never sufficient by itself to deny access. When state is inconsistent, user content is preserved and the least intrusive outcome described in the terms applies. Human review can be requested at support@macroquantic.com.

Minimal grants and pseudonymous aliases may be retained while the one-trial-per-device rule remains in effect. Detailed risk events are deleted or de-identified after 90 days; aggregate statistics without identifiers may be retained. HMAC keys are kept separately and rotated through a read key ring so existing devices are not treated as new.

See all policies