Version 2.1. Last updated 8 September 2026. Effective on publication.
This Privacy Policy describes how personal data is collected, used, disclosed and retained in connection with the websites operated at thatlev.com and stillon.dev, together with their subdomains and interfaces (the “Site”), and the StillOn application for macOS (the “Software”, and together with the Site, the “Services”). It forms part of the Terms of Service.
The controller responsible for the processing described in this Policy is Lev, an individual sole proprietor trading as ThatLev, contactable at hello@thatlev.com. No data protection officer is appointed, as no such appointment is required for processing of this nature and scale. All enquiries, including requests to exercise the rights described in section 9, should be directed to that address.
Personal data is processed on a data-minimising basis. The measurement performed across the Services is first-party and aggregate in purpose: it is designed to establish which projects attract interest and where visitors lose interest, not to identify individuals, build profiles, or follow people across unrelated services. No personal data is sold, rented or otherwise made available for consideration; no advertising network, advertising identifier, cross-context behavioural advertising or third-party tracker operates on the Services; and no automated decision-making producing legal or similarly significant effects is carried out.
When you visit the Site, the following are recorded: pages visited, the sections of a page reached, scroll depth, whether media playback began, interactions with links and controls, the destination of outbound links, sampled pointer and scroll positions expressed as relative page coordinates, screen touches on mobile devices, the project selected where a launch list is joined, timing measured from the opening of the page, an approximate location at country and city level, a general device category, and a reduced browser name and version. Where a requested address does not exist, that address and the general class of its referrer are recorded so that broken links can be repaired.
The following are expressly not recorded: the content you type into any field, individual keystrokes, form contents, the text beneath your pointer, page element identifiers, screen contents, and any precise location.
The same limited measurement operates on the public marketing pages of my other projects, so that a visit which continues onto one of them is not double-counted. It does not operate within signed-in product screens, customer-facing menus or ordering pages, administrative areas, or any other private route.
No analytics identifier is stored on your device. To distinguish a returning visit from a new one within a single day, network and browser characteristics are combined with a secret value that changes daily and are irreversibly transformed into a short-lived pseudonymous value. Your IP address is not stored. It is used to derive that value and to determine an approximate country, and is then discarded. The resulting value cannot be reversed to recover the inputs, ceases to correspond to you once the daily secret changes, and is held on the server rather than in your browser. Public counters display totals only and never expose an individual visit, address or location.
Where a licence is purchased, the following are processed: the email address supplied at checkout, transaction and payment references generated by the payment processor, the status of the licence, an irreversible representation of the licence key together with a short non-identifying fragment of it used for support, delivery timestamps, and, for each activated Mac, the name the operating system reports for that machine, an irreversible representation of an installation value generated by the Software, and activation and validation times. Correspondence you send to me is retained as part of the support record.
Complete payment-card details are entered directly with the payment processor. They are never received, handled or stored by me.
Website checkout additionally uses a random, one-hour server-side claim to associate the anonymous checkout-start and checkout-success events with the resulting transaction and licence. That claim holds references only: it contains no email address, network address, browser string, licence key or other customer-supplied identifier, and nothing is stored in your browser for this link. A management link sent to your email address is single-use and expires shortly after issue.
After a confirmed purchase, automatic activation may use a random five-minute handoff token between the browser and the Software. Only an irreversible representation of that token is stored. Its first use binds it to the irreversible installation representation described above, so it cannot activate a different Mac; the licence key itself is never placed in the handoff URL.
If you join the character updates list on thatlev.com, your email address, signup date and source are stored separately from project launch lists. You consent to occasional emails about the characters, how I make them, and other things I am working on. You can withdraw consent by replying to an email or writing to hello@thatlev.com. Your address is not sold. Bot checks, rate limits and duplicate detection protect the form. Genuine new signups may send me an operational notification.
The popup stores only a dismissal expiry or a joined flag in this browser, not your email address. Dismissal lasts seven days; the joined flag remains until you clear site data. These preferences are not used for tracking.
Joining the launch list for an unfinished project requires an email address. Where you join, the address, the project it concerned and the date are recorded, and the same submission records the join against your anonymous visit so that a visit counts once per project. You may join the list for more than one project. The address is used to send a single notification when that project launches. It is not sold, is not shared, and is not added to any other list. A notification containing the address is delivered to me so that it reaches my inbox; nothing further is forwarded anywhere.
The Software transmits a limited first-party product signal by default. It comprises an installation value generated by the Software itself, the application and build version, the major and minor version of the operating system, the processor architecture, a broad indication of licence state, a small number of milestone events such as a successful launch, completion of onboarding, first use of the principal features and licence activation, and an infrequent signal indicating that the installation remains in use. What is retained is one aggregate record for each installation, keyed to an irreversible representation of that value, rather than a history of individual events.
This telemetry does not include your name, your Mac’s serial number or hardware identifiers, your IP address, your email address, your licence key, file names, file contents, the applications you run, screen contents, keystrokes, or any measurement or sample of physical device state. It may be discontinued at any time using the corresponding setting within the Software, which takes effect for all future transmissions.
The Site sets only first-party cookies, and only these:
There is no analytics cookie, advertising cookie or third-party cookie. Clearing site data removes the above. The Software stores its settings, licence and related values in protected storage on your Mac; those values remain local to your machine except where transmitted as described in this Policy.
Where the General Data Protection Regulation or the UK GDPR applies, processing is carried out on the following bases:
No special categories of personal data are knowingly processed, and none is requested.
Personal data is disclosed only to service providers engaged to operate the Services, each bound by contract to process it solely on my instructions and to apply appropriate safeguards. They comprise providers of website hosting and request handling, managed database storage, content delivery and inbound email routing, payment processing, transactional email delivery, and a messaging service through which limited operational alerts reach me.
Personal data may additionally be disclosed where required by law, court order or a binding request from a competent authority, where necessary to establish, exercise or defend legal claims, or in connection with a transfer of the business or its assets, in which case notice will be given. Personal data is not sold or shared for cross-context behavioural advertising, and has not been in the preceding twelve months.
Links from the Services to third-party platforms are governed by the privacy policies of those platforms, over which I have no control.
Certain providers process data outside the European Economic Area, including in the United States. Where personal data is transferred to a country not benefiting from an adequacy decision, the transfer is made subject to appropriate safeguards, ordinarily the European Commission’s Standard Contractual Clauses together with supplementary measures where required. Details of the safeguards applied are available on request.
Individual measurement events are consolidated into aggregate daily figures and the underlying events are deleted after twelve (12) months; only the aggregate figures persist beyond that point, and those are not personal data. Launch list joins follow the same twelve-month period. Email addresses collected for a launch notification are held until the notification is sent or until erasure is requested. Website checkout claims that did not go on to produce a licence are deleted after 30 days. Expired automatic-activation handoffs are removed after one day. Purchase and licence records are retained for the duration of the licence and thereafter for as long as is reasonably necessary to meet tax, accounting, fraud-prevention and dispute-resolution obligations. Expired management credentials cease to be valid immediately and are removed periodically. Installation aggregates are retained while the Software remains in operation so that lifetime totals remain accurate, and are deleted on request.
Appropriate technical and organisational measures are maintained to protect personal data against unauthorised access, alteration, disclosure and destruction, including encryption in transit, access restricted to what is necessary to operate the Services, irreversible transformation of sensitive values wherever a stored plaintext value is not required, and short validity periods for credentials. No method of transmission or storage is entirely secure, and absolute security cannot be guaranteed. Where a personal data breach is likely to result in a risk to your rights and freedoms, the competent supervisory authority and, where required, affected individuals will be notified within the periods prescribed by law.
Subject to the conditions and exceptions in applicable law, you have the right to request access to the personal data held about you; to request rectification of inaccurate data; to request erasure; to request restriction of processing; to object to processing carried out on the basis of legitimate interests; to receive data you provided in a portable form; to withdraw consent at any time; and not to be discriminated against for exercising any of these rights.
Requests should be sent to hello@thatlev.com and will be answered without undue delay and in any event within thirty (30) days, a period that may be extended where permitted by law and where you are notified of the extension. Verification proportionate to the sensitivity of the request may be required before it is actioned. An authorised agent may submit a request on your behalf on proof of authority.
Because measurement data is pseudonymous by design and is not linked to a durable identifier, I may be unable to connect it to you. Where I cannot identify the data subject and you are unable to supply information enabling identification, applicable law permits me to decline to act on a request in respect of that data; this limitation follows from the same design that keeps the measurement anonymous.
If you are in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with your national supervisory authority. You are asked, but not required, to raise the matter with me first.
The Services are not directed to children, are not intended for use by any person under the age of sixteen (16), and no personal data is knowingly collected from such a person. If you believe a child has provided personal data, contact me and it will be deleted.
The measurement described in this Policy is first-party, is not used for advertising or profiling, and is designed to fall within the exemptions ordinarily available for strictly necessary and anonymous first-party audience measurement, which is why no consent banner is presented. Jurisdictions draw that boundary differently. If you consider that the rules applicable to you require a different approach, contact me and it will be addressed.
This Policy may be amended by publication of a revised version bearing a new effective date. Where an amendment materially changes how personal data is processed, reasonable notice will be given by an appropriate means before it takes effect. This Policy is drafted in English; any translation is provided for convenience and the English version prevails.
Privacy enquiries, including access, erasure and portability requests: hello@thatlev.com.
Related documents: Terms of Service