Skip to main content

KeyTiler Privacy Policy

Last updated: 2026-08-30

Product Usage Analytics is off until you explicitly allow it. During the Preview period, KeyTiler uses TelemetryDeck for optional analytics.

1. Scope

This policy describes the information processed by the installed KeyTiler macOS application, its optional in-app analytics, and its Sparkle-based update path. The update path includes update checks, the update feed, and update packages delivered through the official KeyTiler domain.

KeyTiler is intended to be available to users in the European Economic Area (EEA) and the United Kingdom. The regional considerations for those users are described in Section 12.

This policy does not cover the separate browser-based download flow on the KeyTiler website. That flow may involve additional security services, cookies, or browser-data processing outside the scope of this policy.

2. Operator and contact

KeyTiler is maintained and operated by 邱宇舟 (Qiu Yu Zhou), an individual.

3. What KeyTiler does

KeyTiler is a macOS menu-bar application that moves and arranges the active window in response to shortcuts or a Layout Panel choice. macOS Accessibility permission is required for the app to read the window information needed for the requested operation and to move the window.

4. Information processed only on the Mac

The following information is used locally to provide the app’s functions and is not included in KeyTiler-authored analytics events:

  • window-management state and the window properties needed to perform a requested layout action;
  • shortcut configuration and other app preferences;
  • local Layout Panel learning data, such as coarse usage context and the selected layout mode; and
  • local analytics counters and a random sampling identifier used to keep sampling consistent; these are created only after the user allows Product Usage Analytics.

The current implementation prunes non-global Layout Panel learning entries after 365 days of inactivity. The learning data can also be cleared from the app’s preferences. Local analytics counters and unsent KeyTiler summaries are cleared when Product Usage Analytics is turned off.

5. Optional analytics

Product Usage Analytics is off until the user explicitly allows it in the first-launch consent window or General Preferences. The same decision controls KeyTiler-authored usage summaries and the TelemetryDeck SDK’s new events. Before a decision, the app does not initialize the provider or record local usage counters.

KeyTiler currently uses TelemetryDeck for optional analytics during the Preview period. If the app’s analytics provider changes, this policy will be updated.

KeyTiler-authored summaries

KeyTiler records final layout actions in a local rolling window. When the ten-day window expires, the app may send one layout_usage_summary event for each non-zero metric, with no more than nine summary events for one window. Each summary contains:

  • a coarse layout category, such as a direct shortcut, a Layout Panel entry, or a layout family;
  • the count for that category in the window;
  • a random window_id used to align summaries from the same window; and
  • the window period and sampling rate.

These are window summaries, not individual-action logs. KeyTiler does not intentionally put the following into its own event payload: window titles or content, foreground application names, raw shortcuts or settings, display names, coordinates, window rectangles, display layout or resolution, learning or observation data, context fingerprints, raw logs, error text, email addresses, account identifiers, license or order information, IP addresses, device serial numbers, or hardware fingerprints.

The local sampling identifier stays on the Mac and is not sent as an event field or custom user identifier. TelemetryDeck may create an app-scoped pseudonymous installation identifier for its provider envelope; it is not an email address, account identifier, hardware serial number, or hardware fingerprint.

TelemetryDeck provider metadata

KeyTiler currently uses TelemetryDeck Swift SDK 2.14.2, integrated through Swift Package Manager.

TelemetryDeck’s public documentation says that app signals may contain an anonymized per-installation identifier, an app-defined action, an hour-rounded timestamp, device metadata, and publisher-defined metadata. It also states that IP addresses are not stored on TelemetryDeck’s servers or in its logs. These are TelemetryDeck’s provider-level statements; the KeyTiler-authored payload is described above.

The TelemetryDeck SDK may add provider-managed metadata to a request. Depending on the SDK and provider behavior, this can include app and SDK version/build information, operating-system and runtime context, device model and architecture, screen resolution and scale, time zone, locale or region, app language, color scheme and layout direction, calendar values, accessibility preferences such as Reduce Motion and Invert Colors, and session statistics.

After the user allows Product Usage Analytics, the current integration also enables session-start and first-install lifecycle signals and provider-managed session statistics. These provider-managed signals and metadata are separate from KeyTiler’s custom usage summaries. KeyTiler cannot reliably remove individual default fields through the SDK’s public API, so this policy does not promise that provider-managed fields are absent.

Turning Product Usage Analytics off

Turning off Product Usage Analytics stops new KeyTiler-authored summaries and new SDK events, and clears the application-owned local window counters and unsent summaries. Actions taken while Product Usage Analytics is off are not backfilled if it is enabled again; a new rolling window starts instead.

The TelemetryDeck SDK has its own memory and disk cache. KeyTiler has no supported public API to force-clear that cache. An event already accepted by the SDK may remain there and may be retried or sent after the setting is turned off. KeyTiler therefore does not promise that turning off Product Usage Analytics immediately retracts or deletes events already accepted by TelemetryDeck. See TelemetryDeck’s privacy FAQ for provider-managed data.

6. Sparkle update checks and update delivery

KeyTiler uses the Sparkle 2 update framework. The current application is configured to check the official update feed at /updates/appcast.xml.

Users can choose Never, Weekly, or Monthly update checks. Preview builds default to weekly checks and stable builds default to monthly checks. Checking can also be initiated manually. The app does not automatically download or install an update; a user-confirmed Sparkle update session is required.

Information involved in an update request

An update request necessarily exposes ordinary HTTP and network information to the update infrastructure, which can include the source IP address, request time, requested path, standard request headers, conditional-request headers, and the User-Agent. Sparkle documents that its default User-Agent can contain the app display name and version together with the Sparkle version; see the Sparkle API reference.

The current KeyTiler build does not enable Sparkle’s optional system-profiling feature. It does not intentionally send Sparkle’s optional profile fields such as macOS version, CPU details, Mac model, memory, or preferred language as a system profile. Sparkle describes system profiling as an optional feature in its system profiling documentation.

The update feed request does not use a stable account or installation identifier. The feed is publicly readable. Download requests for update packages add a short-lived, target-bound request proof containing a key identifier, timestamp, random nonce, and signature. This proof is used to verify the request and limit ordinary abuse; it is not a user account, a stable installation identifier, or a way to authenticate the person using the app.

The feed and packages are signed and verified as part of the Sparkle and application release-signing chain. The update service may use caching, rate limiting, and request-security checks to deliver the feed and packages. These controls do not change the information described above.

7. How information is used

Information described in this policy is used to:

  • perform the window-management and Layout Panel functions requested by the user;
  • remember local preferences and local Layout Panel learning state;
  • check for and deliver signed application updates;
  • protect the update path against malformed, excessive, or replayed package requests;
  • when Product Usage Analytics is enabled with the user’s consent, send optional coarse usage and session statistics; and
  • respond to privacy requests and comply with applicable legal obligations.

KeyTiler’s custom analytics events are not used to identify a person or to build an account profile. KeyTiler does not sell personal information or share it for cross-context behavioral advertising based on the current app design.

8. Cookies and similar technologies

The macOS application itself does not set or read browser cookies for its analytics or update functions. The separate website download flow may have its own provider-managed security mechanisms. This app-focused policy does not describe cookies or browser data used by that separate flow.

9. Service providers

Provider or componentRoleInformation that may be involved
TelemetryDeckReceives optional analytics events and provider-managed SDK metadataKeyTiler summaries, lifecycle/session signals, pseudonymous provider identifiers, and the metadata described in Section 5
CloudflareProvides infrastructure for the official update feed and packages, including edge delivery, caching, rate limiting, and short-lived request-proof verificationSource IP and ordinary HTTP/request metadata, requested update paths, request timing, and package-request security data
SparkleEmbedded open-source update framework that performs update checks and user-confirmed update sessionsLocal update state and the network requests described in Section 6; Sparkle is not a separate KeyTiler account or identity provider

Provider handling is also governed by the provider’s own policies. See TelemetryDeck’s privacy FAQ, architecture and security overview, and DPA, together with Cloudflare’s Privacy Policy and Sparkle’s documentation.

TelemetryDeck’s current public documentation states that app usage data is hosted within the European Union. It lists infrastructure in Amsterdam, the Netherlands, and Frankfurt, Falkenstein, and Nuremberg, Germany. KeyTiler has not independently verified the live infrastructure behind its account.

10. Retention

  • KeyTiler’s custom analytics counters are kept locally for the current ten-day rolling window. Once the window is settled, the app clears those local counters after creating the summaries. Turning Product Usage Analytics off clears the application-owned counters and unsent summaries.
  • Local Layout Panel learning data is kept on the Mac. Non-global entries are currently pruned after 365 days of inactivity; the user can clear the learning data from the app.
  • TelemetryDeck-managed analytics data is retained according to the provider’s applicable service terms and retention mechanisms. The provider states that retention can depend on the applicable service configuration; data outside active retention may be moved to cold storage rather than deleted. KeyTiler does not control the provider’s service-side retention period.
  • The TelemetryDeck SDK may retain accepted or pending events in its own service or device cache and may retry pending events. KeyTiler does not control that cache and does not promise immediate deletion of an event already accepted by the provider.
  • Cloudflare Workers Logs for the update service are configured with a maximum retention period of seven days. Rate-limiting records are retained for 60 seconds. The update path does not cache user data; any cache is used for public update content rather than user-provided information. Package request proofs are short-lived and are not intended to act as long-term identifiers.

The Cloudflare periods above describe the current deployment configuration. TelemetryDeck’s provider-managed retention, service regions, and applicable transfer safeguards may change under the provider’s terms. This policy does not promise a fixed retention period for provider-managed analytics data.

11. Choices and privacy rights

You can:

  • allow or decline optional Product Usage Analytics in the first-launch consent window, and later withdraw consent in General Preferences;
  • choose Never, Weekly, or Monthly update checks;
  • revoke Accessibility permission in macOS System Settings; and
  • clear local Layout Panel learning data in the app’s preferences or remove the app’s local data when uninstalling it.

Depending on applicable law, you may also have rights to request access to, correction of, deletion of, restriction of, or portability of personal information, to object to certain processing, to withdraw consent where processing is based on consent, and to complain to a data-protection authority.

To make a request, use the privacy contact published by the operator. Because KeyTiler does not require an account and does not use a stable update identifier, the operator or a provider may be unable to associate a request with a particular record. The operator may ask for limited information needed to verify and locate a request and will not ask for your passwords or private signing credentials.

12. Regional information

EEA, United Kingdom, and Switzerland

KeyTiler is intended to be available to users in the EEA and the United Kingdom. The operator has no establishment in the EEA or the United Kingdom. During Preview, Product Usage Analytics is opt-in: a new installation remains undecided and the current app initializes the provider only after the user allows it in the first-launch consent window or General Preferences. For the optional Product Usage Analytics processing described in this policy, the operator’s current legal basis is the user’s explicit consent under Article 6(1)(a) of the GDPR or UK GDPR, as applicable. The app does not initialize the provider, create usage counters, or send Product Usage Analytics before consent. Consent is not required to use KeyTiler, and it can be withdrawn at any time in General Preferences; withdrawal stops new Product Usage Analytics processing, subject to the SDK cache limitation described above.

Where applicable, the operator will provide the rights required by local data-protection law.

United States, including California

Based on the current app design, KeyTiler does not sell personal information or share it for cross-context behavioral advertising. Depending on applicable law, you may have rights to know or access, delete, correct, and opt out of certain uses or disclosures of personal information, subject to verification and legal exceptions. You can exercise these rights by contacting privacy@keytiler.yuzhouqiu.com.

13. International processing

TelemetryDeck, Cloudflare, and their service providers may process information in countries other than the country where you use KeyTiler. The providers’ policies and terms describe their processing locations and available safeguards. These locations and safeguards may change over time.

TelemetryDeck’s current public pages state that app usage data is hosted within the EU and list infrastructure in Germany and the Netherlands. The public pages do not identify a KeyTiler-specific retention period or provide a complete account-specific transfer record. For users in the United Kingdom, EU-based processing may constitute an international transfer under UK law. The safeguards applicable to that transfer depend on the provider’s current terms and service configuration.

14. Children

KeyTiler is a general-purpose macOS utility and is not directed to children. The operator does not knowingly collect personal information from children through the app. If you believe a child has provided personal information, contact the operator using the published privacy contact.

15. Security

The update path uses HTTPS, signed update metadata and packages, verification before package extraction, short-lived package-request proofs, and rate limiting. KeyTiler does not receive account passwords through the app. No method of transmission or storage is completely secure, and provider-managed systems are subject to the providers’ own security practices.

16. Changes to this policy

This policy may be updated when the app, analytics behavior, update path, providers, or applicable legal requirements change. The Last updated date will be changed with each revision. Material changes will be communicated through the app, the official website, or another appropriate channel where required by law.

17. Contact

Submit a privacy request through the Contact page

Official website: KeyTiler website