Legal
Policies for purchasing and using LonelyDuck Software.
Privacy Policy
Effective Jun 25, 2026
We aim to collect as little personal data as possible while still operating a secure storefront (payments, licensing, support). If you have questions or deletion requests, email support@lonelyduck.io.
What we collect
Account data
- Email address
- Password hash (we never store your raw password)
- Email verification status
Purchase data
- Receipt email
- Purchased product identifier
- Transaction identifiers and status
License & activation data
- License key (entitlement identifier)
- Activation records (device UUID + basic device info)
- Activation timestamps
Operational data
- Server logs (IP address, user agent, timestamps)
- Security logs (e.g., failed login attempts)
The Canto app: private by default
Canto is built to run on your Mac. By default, your notes and AI processing stay on your device, and your note content is not uploaded to our servers.
Some optional features reach the internet when you choose to use them:
- Web Search / Research: when you run a web search or research, your search queries (and the links you ask Canto to read) are sent to our search provider to fetch results. Your notes are not uploaded wholesale.
- Connect your own AI model: if you point Canto at an external model endpoint you configure (for example a local or third-party server), your prompts are sent to that endpoint so it can respond.
- iCloud Drive Sync (optional): if you enable Sync, your vault is encrypted on your Mac before it is stored in your own iCloud Drive, so we cannot read its contents.
- Model downloads & updates: Canto downloads AI models and app updates from their hosting providers.
You can use Canto without any of these features. See the in-app Privacy settings for the exact, current details.
What we don't collect
- We do not store your full payment card details.
- We do not sell personal information. We do not run third-party ad trackers on purpose.
How we use your data
- Process purchases, deliver licenses/receipts, and provide downloads.
- Authenticate accounts and keep the platform secure.
- Provide customer support and resolve licensing issues.
- Prevent fraud and abuse.
Third parties
We use service providers to operate the platform. For example:
- Payment processing (Stripe, PayPal)
- Email delivery (transactional emails like verification, license delivery, receipts)
- Hosting/infrastructure
- Apple iCloud (only if you enable Sync)
- Our web search provider (only when you use Web Search/Research)
Data retention
We retain data as needed to provide licensing, customer support, accounting, and security. You can request deletion where legally and operationally feasible.
Your choices
You can contact us to request access, correction, or deletion of personal data. For support requests, include your receipt email and (if available) the order id.
For purchase policies, see Terms of Service and Refund Policy.