Privacy Policy
Effective: July 29, 2026
Mighty separates app telemetry from purchase and license records. Anonymous app analytics and crash/performance diagnostics start disabled and run only after explicit opt-in. Both have independent controls in Mighty → General → Privacy & Diagnostics and can be enabled or disabled at any time. Anonymous identifiers can still be pseudonymous data under privacy law; I therefore apply the safeguards, retention limits, and data-subject process described below.
1. What I Collect
Mighty collects these data categories:
- Anonymous product analytics — via PostHog, using EU ingestion and hosting. Mighty sends explicit events for app startup and navigation, onboarding and permission outcomes, device discovery and responsiveness, setting outcomes, profile and mapping adoption, license-flow outcomes, Launch at Login, updates, and support actions. PostHog assigns a random persistent device-level identifier so events can form one anonymous app session history; opt-out and re-enable reset it. Properties are fixed categories, booleans, bounded counts, coarse buckets, and capped durations. IP capture and person profiles are disabled. Mighty never identifies, aliases, or groups a user.
- Crash and performance diagnostics — via Sentry, using its EU region. Mighty sends crashes, app hangs, release health, sanitized operation failures, and manual performance spans. Default PII, request and response data, profiling, logs, network and UI breadcrumbs, screenshots, and view hierarchy are disabled.
- User-requested update availability — when you choose “Download Latest Version,” Mighty opens its download page and fetches a small version manifest from mighty.mikezamayias.com. The site and its delivery provider may process standard connection data, including your IP address, to return that file. Mighty sends PostHog only the check outcome, duration, and a boolean saying whether a newer version exists; it never sends the manifest, request URL, response body, or IP address through app telemetry.
- Purchase and license data — only if you buy Mighty Pro through Polar. Mighty stores the minimum license, order email, and activation records needed for license validation, support, refunds, and abuse prevention.
- Device data — Mighty reads the local mouse information needed to display battery status and apply settings, such as device name, vendor/product identifiers, connection state, battery level, DPI, polling-rate, button, and profile settings. This device data is processed locally unless you choose to send diagnostics for support.
2. What I Do NOT Collect
To be clear about what Mighty does not do:
- No account is required to use the free tier
- No advertising, cross-product tracking, person profiles, or telemetry tied to a license/customer identity
- No data is sold, shared, or used for advertising
- No third-party ad networks or trackers
- No license keys or fragments, customer email, Polar IDs, machine names, or usernames in app telemetry
- No device or receiver serials, runtime IDs, slot IDs, raw product identifiers, or model names in app telemetry
- No profile names, bound application bundle IDs, application names or paths, exact DPI, or exact polling values
- No button presses, key sequences, HID packets, support report/email contents, raw errors, URLs, query strings, authorization headers, request bodies, or response bodies
- No keystrokes, file contents, browsing activity, clipboard contents, or personal documents
- No macOS app Session Replay, screen or mouse-movement video, screenshots, text-field capture, or view hierarchy. Sentry does not currently support Session Replay on macOS.
- No device data is sent to Logitech
3. Payment Data & Merchant of Record
If you purchase the Pro tier, Polar handles all payment processing as the Merchant of Record. This means Polar is the seller of record for your purchase, collects and remits applicable sales tax and EU VAT on my behalf, and is responsible for compliance with consumer-protection rules across all jurisdictions where Mighty is sold.
I do not receive, store, or have access to your payment details (credit card numbers, billing address, etc.). Polar is the data controller for your purchase data and processes it under their own privacy policy: polar.sh/legal/privacy. Their MoR + tax disclosures are published at polar.sh/legal/terms.
4. License Keys & Activation Data
When Polar issues you a license key for Mighty Pro, a webhook delivers the key, the email address you used at checkout, and the order metadata to my Cloudflare Worker (mighty-api) so I can fulfil and validate your license. I store the following on Cloudflare's EU edge:
- The license key string and its current state (active, expired, deactivated, refunded)
- The order email address (used only to look up your license if you contact support)
- A salted hash of each activated machine's hardware identifier — never the raw machine ID
- An audit log entry per webhook event (encrypted at rest with AES-256-GCM)
When the Mighty app calls /api/activate or /api/validate, those requests go to mighty-api. The Worker validates your license with Polar, but it never sees your card or full billing address. If you request a refund, the corresponding webhook revokes your license. Minimal order, license, activation, and audit records may be retained as needed for support, refund verification, tax/accounting records, and abuse prevention.
5. Cookies & Checkout
The Mighty website uses only essential cookies required for basic functionality. No tracking cookies, no third-party advertising cookies, no cookie consent popups needed. Website PostHog, browser Sentry, server Sentry, and browser Session Replay are disabled; the native app controls described above do not silently enable website telemetry.
The Polar checkout (whether embedded as an overlay or opened on a Polar domain) sets its own cookies that are required for the checkout to function and for fraud prevention. Those cookies are governed by Polar's privacy policy and only run on pages where you have actively initiated a purchase.
6. Controls, Withdrawal & Retention
PostHog analytics is opt-in. Its current EU project plan may retain delivered analytics events for up to 84 months (seven years). This retention exception is approved for Mighty 2026.8.1; later releases require a new review. Sentry diagnostics is retained no longer than 90 days. Disabling either switch immediately stops future collection by that system. Mighty deletes queued, undelivered PostHog batches before analytics can restart, but does not remove events already delivered. Re-enabling starts a fresh SDK session and anonymous PostHog identity. Telemetry preferences never change app functionality, device access, licensing, Pro features, or support access. License and order records are retained while needed to validate purchases, handle refunds, support customers, keep audit history, and meet legal or accounting obligations.
7. Legal Basis, GDPR & Deletion
Mighty is built and operated from the EU (Greece). Both analytics (PostHog) and crash reporting (Sentry) use EU projects. I rely on your consent for this optional collection. Both controls start disabled, and you can withdraw consent at any time by disabling either control. Depending on context, anonymous identifiers may be pseudonymous personal data, so GDPR rights are not dismissed merely because Mighty does not intentionally collect direct identifiers.
For Pro purchases, Polar is the data controller for the order, billing, and tax data required to issue your receipt. As an EU consumer you have the right to access, correct, and delete that data and to a 14-day right of withdrawal under EU consumer-protection law, subject to the exception for digital content delivered immediately after explicit consent — which is how Mighty Pro license keys are delivered. Polar applies the correct VAT rate for your country at checkout and remits it to the relevant tax authorities on my behalf; no additional VAT is charged by me. Refunds and chargebacks are described in the Refund Policy.
To request access, correction, objection, restriction, portability, or deletion for data I control, contact support@mikezamayias.com. Include only enough information to locate the relevant license or support record. Truly anonymous telemetry may not be technically linkable back to you; if a vendor identifier is available, I will use the vendor's approved deletion process. Polar remains separately responsible for purchase, billing, and tax data.
8. Children's Privacy
Mighty is not directed at children under 13. I do not knowingly collect data from children. Paid purchases and license management should be handled by an adult.
9. Changes to This Policy
I may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of Mighty constitutes acceptance of the revised policy.
10. Contact
Questions or concerns about this Privacy Policy? Reach out:
Michail Anargyros Zamagias
contact@mikezamayias.com
+30 693 900 0455
Kritovoulidou 19
71201 Heraklion, Crete, Greece