Privacy policy

Last updated: July 2026

Pulli is a native macOS download manager. We do not use usernames or passwords. Your account is a random key like pulli-XXXX-XXXX-XXXX. This policy explains what data we process, why, how long we keep it, and what you can do about it.

Data controller

Pulli is the data controller for the personal data described in this policy. For privacy inquiries, contact privacy@pulli.app.

Using Pulli anonymously

This is the default, not a hidden option. Generate a key, never attach an email, and the only things we hold are the key itself, the coarse country it was minted in, and one row per Mac you activate. We never ask for a name, and nothing in the app requires an account beyond that key. Attaching an email is a convenience for recovery and receipts, and you can detach it later.

Paying for Pro is the one place a real identity appears, because a card has a name on it. Polar handles that as merchant of record, and they do not pass it back to us.

What we process and why

For a field-by-field breakdown of every data point we store, see our transparency page . The table below covers the legal basis for each processing activity.

Contract
License activation, device management, feature gating. We need this data to provide the service you signed up for.
Legitimate interest
Aggregate install statistics, crash diagnostics, OS version breakdown, and abuse prevention. We use these to keep the app working across macOS versions and to stop anyone from hammering our API. You can object to this at any time.
Consent
Optional email attachment and opt-in diagnostic / usage sharing. You give us your email for receipts and recovery. In Settings you can turn on "Share anonymous usage data" to send warning and error logs to Axiom tagged with a random diagnostics id, plus a daily anonymous resource summary and feature-preference flags to our API on Cloudflare. "Share diagnostic logs" sends the complete debug trace to Axiom when you ask us to help debug a problem. Both toggles are off by default. Withdraw any of these by removing your email, turning off the toggle, or deleting your account.

How long we keep it

License dataUntil you delete it
Your license and activation records persist until you request erasure. Free licenses never expire.
Event dataIndefinitely, without identifiers
Website and app events (page views, downloads, update checks) are retained for aggregate statistics. No event row carries a license key, and the device id is replaced at write time with a keyed hash of that id plus the current month, computed under a secret only our server holds. The value changes every month, so rows from different months cannot be matched to each other, and nobody without the secret can test a device against our rows. While your license exists we could recompute the hash from the device id on your activation row; erasing your license deletes that row, and with it the last thing that could reconnect the events. This describes event rows only; opt-in diagnostic logs are covered separately below.
IP addressUp to 1 hour
We never write your IP to the database. Cloudflare's edge key-value store holds a keyed hash of it as a rate-limit counter, which expires on its own. We use the IP for nothing else: no analytics, no profiling, no location beyond the coarse country described above.
EmailUntil you remove it or delete your account
If you attached an email, it stays until you detach it or erase your account.
Polar recordsPer Polar's retention policy
Polar retains transaction records for legal/accounting requirements. When you erase your account, we ask Polar to delete your customer record with anonymization on: active subscriptions are cancelled, and the details Polar must keep are stripped of your name, email, and billing address.
Server logsUp to 72 hours
Cloudflare Workers logs are ephemeral and expire on their own inside that window. We do not maintain long-term access logs, and we cannot search or delete a single visitor's entries while they are alive.
Diagnostic logs (Axiom)30 days
If you opt in, application logs are retained in Axiom for 30 days. Turning both diagnostic toggles off stops transmission immediately, deletes the local diagnostics id, and existing lines expire on their own at the end of the window. Because they are tagged with a random diagnostics id rather than your license, we cannot single out and delete yours before then.
Anonymous usage metrics24 months
If you opt in, daily resource summaries (memory, CPU, thread count, active download count) and feature-preference snapshots land on our Cloudflare database with no license or device id. The request is signed so only activated installs can post, but nothing from that auth is stored. Turning the toggle off stops new uploads right away. Existing rows expire on their own after 24 months.

Who else sees your data

Polar.shMerchant of Record
Processes payments, stores card details, and manages subscriptions. We never see your payment information. When you start a checkout we send Polar an opaque internal account id and your IP address so they can work out the right currency and tax; your license key is never sent, and if you attached an email they receive that too. Polar acts as data controller for payment data. Their privacy policy is at polar.sh/privacy.
CloudflareInfrastructure
Hosts our website and API on Cloudflare Workers. Derives your coarse country from IP at the edge, and holds a keyed hash of your IP briefly in edge storage to enforce rate limits. Cloudflare is a data processor under our instructions. Their DPA is at cloudflare.com/gdpr.
ResendEmail delivery
Sends the only emails we send: your key when you attach an email, and your key again when you ask to recover it. Resend receives your email address and the message, which contains your license key. No newsletters, no marketing sends. Resend is a data processor under our instructions. Their privacy policy is at resend.com/legal/privacy-policy.
AxiomDiagnostic logging (opt-in)
Receives application logs only if you opt in under Settings. Two separate toggles control how much you send. "Share anonymous usage data" sends warning and error events to Axiom, plus a daily anonymous resource summary (memory, CPU, thread count, active download count) and feature-preference flags (appearance, scheduler, system, extension, fetch, network, notifications) to our own API on Cloudflare. "Share diagnostic logs" sends the complete debug trace to Axiom, which we reserve for when you ask us to help debug a problem. Logs contain component names and timing data; we filter out URLs, file paths, emails, tokens, and credentials before transmission. Each line is tagged with a random diagnostics id minted when you turn a diagnostic toggle on and deleted when you turn both off; turning diagnostics back on mints a fresh id. That id is not your license, not your install id, and not your device id, so Axiom lines cannot be joined to an account. Neither sends what you download or how much. Axiom is a data processor under our instructions. Their privacy policy is at axiom.co/privacy.

International data transfers

Pulli runs on Cloudflare's global edge network. Your request may be processed in a data center outside your country of residence. Cloudflare relies on Standard Contractual Clauses (SCCs) for transfers from the EEA. Polar.sh may also process data outside the EEA under their own SCCs. Resend, which delivers our key emails, is US-based and relies on the EU-US Data Privacy Framework and SCCs. If you opt in to diagnostic logging, Axiom receives it at their EU region by default, under SCCs for anything that leaves the EEA. We do not transfer data to countries lacking adequacy decisions.

Cookies and tracking

No analytics scripts, no advertising pixels, no third-party cookies, and nothing that follows you between sites. The website sets exactly two first-party cookies, neither of which identifies you:

  • viewport — remembers whether your screen is phone, tablet, or desktop sized so the first paint is the right layout. Holds one word. Expires after a year.
  • pulli_unlock — only while the site is in early access, and only after you enter an access code. It records that the code was correct and nothing else.

The desktop app stores your license key locally on your machine; that is device storage, not a cookie.

We do not respond to Do Not Track signals because we do not track you in the first place. California residents: we do not sell or share your personal data for cross-context behavioral advertising, and no such sale has occurred in the past 12 months.

Browser extension

The Pulli Chrome extension intercepts downloads in the browser and forwards them to the Pulli desktop app running on your Mac. It does not download anything itself, and it does not send data to any remote server. All communication with the desktop app uses Chrome's native messaging API, which restricts communication to a locally registered host (app.pulli.host) installed by the Pulli app.

When a download is intercepted, the extension reads the following from the browser and forwards it to the local app:

  • Download URL — the address of the file being fetched.
  • Referrer URL — the page that initiated the download.
  • Cookies — session cookies for the download's domain, so authenticated downloads succeed in Pulli without re-authenticating.
  • Filename and file size — the suggested name and expected size from Chrome.

This data stays on your machine. It is not sent to pulli.app or any other remote endpoint. The extension does not include analytics, telemetry, or tracking.

To catch drag-to-fetch gestures, the extension asks Chrome for access to every site you visit and runs a small content script in every page and frame as it loads. That access is broad by necessity: a download can start anywhere. The script reads link URLs and page titles when you drag a link, and sends them to the background script for forwarding to the local app. It does not read page content, browsing history, keystrokes, or mouse movement outside of drag gestures, and nothing it reads leaves your machine.

Security

All traffic between the app, our website, and our API travels over HTTPS with TLS 1.2+. License keys are signed with Ed25519 and verified on every request. Your account key is minted on our server, stored there as your account, and kept on your Mac in the keychain. Database access is restricted to the Cloudflare Workers runtime; no human reads your data unless you ask us to.

If a data breach occurs that risks your rights, we notify the relevant supervisory authority within 72 hours and inform you directly if the breach is likely to result in a high risk to you.

Your rights

Under GDPR and UK GDPR, you have the following rights. To exercise any of them, email privacy@pulli.app with your account key.

Access
Ask us for a copy of everything we hold linked to your account key. We send it to the email on file (or one you provide).
Erasure
Delete your key and all associated data. Use the form at /key, or email us. We cascade-delete your license and activations. Website and app event rows survive because there is nothing in them to erase: they carry no key and no device id, only a keyed hash of the device id and the current month, computed under a secret that only our server holds. Opt-in anonymous usage metrics and diagnostic logs are the same story: metrics rows store no license or device id, and diagnostic logs are tagged with a random diagnostics id minted only while the toggle is on, so we cannot pull one person's lines out of Axiom or the metrics table on request. They expire on their own (metrics within 24 months, Axiom logs within 30 days), as Cloudflare's request logs do within 72 hours. If you ever paid for Pro, we also ask Polar to delete your customer record: that cancels any active subscription, revokes benefits, and anonymizes the details Polar keeps for tax records.
Portability
Receive your data in a machine-readable format. Ask us and we export it as JSON.
Objection
Tell us to stop processing your data for a specific purpose. We honor it unless we have a compelling legal ground to continue.
Rectification
Correct inaccurate data. Attach or update your email at /key, or tell us what is wrong.
Restriction
Ask us to limit processing to storage only while a dispute or accuracy claim is resolved. We freeze the data until we resolve your request.
Complaint
Lodge a complaint with your local data protection authority. You can find your DPA at edpb.europa.eu. You do not need to contact us first.

Children

Pulli does not target children and we do not knowingly process data from anyone under 16. If you believe we hold data from a minor, contact us and we will delete it.

Changes to this policy

We update this page when our data practices change. The "last updated" date above reflects the most recent revision. Material changes will also be announced in the app.