MACTICIAN · PRIVACY
Telemetry and privacy
Mactician uses a small, bounded telemetry surface. It has no advertising SDK, account tracking, or stable installation identifier.
Updated September 21, 2026 · Performance metrics are collected for all users
Donation-page visits
The Donate button opens sergeinaumov.dev/mactician/donate, which counts the visit and immediately redirects to Lava. Only the total number of visits and an approximate count of unique browsers are saved. These aggregate counters contain no visitor ID, IP address, user agent or payment information and are kept while this feature is in use.
A first-party cookie named mactician_donate_visited contains only the value 1. It marks a returning browser and expires one year after its last successful visit. Clearing or blocking cookies, using a private window or switching browsers can count the same person again. The payment provider has its own privacy policy.
Controller, purposes, and legal bases
Sergei Naumov is the controller for telemetry received from Mactician. The basic first-session and activation-snapshot events are used to understand whether the launcher reaches a successful session, establish a fresh activation count after correcting earlier collection, plan compatibility work, and protect the small telemetry service from duplicate or abusive traffic. A daily-active heartbeat approximates DAU, while a separate anonymous session summary measures completed-session count and total play time as aggregate adoption indicators.
Where the GDPR, UK GDPR, or a similar law applies, the basic events, daily-active heartbeat, and anonymous session summary are processed on the basis of legitimate interests in measuring launcher reliability and adoption and securing the service. These events are deliberately minimized, aggregated immediately, and are not used for advertising, cross-service tracking, or user profiling. Optional extended diagnostics are processed only on the basis of your consent, which you can withdraw in Mactician settings at any time.
One-time activation snapshot
After updating, Mactician creates one activation_snapshot for snapshot version 1 when the launcher runs and the Extended Diagnostics choice is known. If the choice is still unknown, no snapshot is created until you choose. The event contains a fresh random event ID, snapshot version, the explicit state granted or denied, diagnostics-consent version, launcher version, and build number.
This basic event is sent whether Extended Diagnostics are granted or denied because it contains no game-session diagnostics. It does not contain duration, launcher settings, device properties, identity, logs, or a stable installation identifier. Clearing launcher preferences or using another macOS account can create another event, and an installation that never runs the updated launcher is absent, so the result is an active-installation census rather than a count of unique people.
The snapshot is aggregated after an explicit UTC backend cutoff and separately from the earlier first-session metric, whose historical total is a known undercount. The dashboard reports exact granted, denied, and unknown counts. Consent is granted / (granted + denied); refusal is denied / (granted + denied). It never infers refusal from missing diagnostic events.
The normalized transport source IP is retained for 365 days only for rate limiting and abuse investigation and is never used to identify, deduplicate, or count installations. The random event-ID hash and aggregate are retained for 730 days so delayed retries cannot increase the census.
Basic first-session event
After the first game session reaches the ready state and ends, Mactician sends one event for that retained macOS preferences domain. It contains a random event ID, calendar day, approximate duration bucket, launcher version, and build number.
It does not contain an installation or device identifier, exact time or duration, device properties, launcher settings, language, identity, logs, or a network-address field.
The server immediately increments an aggregate grouped by received day, version, build, and duration bucket. Every valid distinct event ID is counted; events are not capped per source. The server stores no raw basic payload. It retains the normalized transport source IP for 365 days to audit activation sources and investigate abuse. A separate SHA-256 hash of the random event ID is retained for 14 days only to reject retries. Source IPs are not displayed on the private metrics page. Aggregates without source IPs are retained for 730 days; small diagnostic cohorts are not displayed or exported.
Anonymous daily-active heartbeat
After the current telemetry notice is acknowledged, Mactician creates at most one daily_active event per retained macOS preferences domain and UTC day on which the launcher opens. It contains a fresh random event ID for that day, the UTC calendar day, launcher version, and build number.
It contains no stable installation or user identifier, duration, exact time, device properties, launcher settings, language, account information, or logs. Different active days use independent random event IDs and therefore cannot be joined into an installation history from the payload.
The server validates the reported day and immediately increments its daily aggregate without storing the raw payload or transport source IP. A SHA-256 hash of the random event ID is retained for 14 days to reject retries; the aggregate is retained for 730 days. The dashboard labels the metric Approximate DAU because separate macOS accounts or cleared preferences can count again, while old launchers and failed delivery can undercount.
Anonymous session summary
After every completed game session, Mactician sends one game_session_summary. It contains a fresh random event ID, session duration in seconds, launcher version, and build number. This minimal event is part of the launcher's basic usage measurement and is sent whether Extended Diagnostics are granted or denied.
It contains no installation or user identifier, account information, device properties, launcher settings, language, logs, calendar day, or exact start or completion time. A fresh random ID is used for each event, so separate sessions are not linked into a user or installation history.
The server assigns the received UTC day and immediately adds one session and its duration to daily aggregates. It does not retain the raw payload or the summary's transport source IP. A SHA-256 hash of the random event ID is retained with the aggregate for 730 days only to reject delayed retries; the daily counts and duration totals are retained for the same period. Up to 64 undelivered summaries may be queued locally on the Mac and are removed after delivery or a terminal rejection.
Performance metrics for all users
From Mactician 1.2.0, every Android launch attempt sends performance metrics, whether Extended Diagnostics is enabled, disabled, or has not been chosen. This standard collection helps measure launcher reliability and compare performance between updates. The launcher notice describes it for either choice; the optional diagnostics setting does not disable it.
A fresh random attempt ID links cumulative checkpoints for that attempt only. They include the start time, elapsed and ready times, launch outcome, launcher version/build, TFT edition and APK version/hash, runtime and graphics-profile hashes, detected cache activation, sampled frame-time histograms grouped by scene and session age, missing and background sample counts, collection time, sampled emulator memory and Mac thermal state. Mac model identifier, macOS version, total memory, logical CPU count and the applied display, graphics and guest-resource settings provide the context for comparisons.
In screenshot-based collector versions, occasional foreground game screenshots pass through memory for local scene classification. Those versions send coarse labels such as lobby, planning, combat, or unknown and early/late stage bands. Mactician never saves or uploads screenshots, recognized text, player names, or board contents. Frame measurements are short samples, not a continuous recording.
Compatible diagnostic versions also report the requested game language, classifier implementation version, and aggregate counts explaining unavailable measurements or game context. These distinguish capture and recognition failures, missing stage or phase information, screen transitions, and coarse non-gameplay states such as patching or login. Bounded counters describe screenshot resolution, partial recognition signals, collection backoff, and timing buckets for capture, classification, frame-statistics queries and sampling intervals. These loss diagnostics are part of standard performance collection; they contain no screenshots, recognized text or raw error messages.
Performance payloads have no consent-version assertion, stable user or installation ID, Mac name, serial number, MAC address, Apple or Riot identity, IP field, application list, password, authentication data, or game logs.
From Mactician 1.2.4, a passive experiment also reads up to 64 KiB of the current game log locally in memory. Only predefined lifecycle and garbage-collection departure categories, coarse event-age buckets, read outcomes and timing counts are sent. Raw log text, account or player identifiers, tokens, file paths and event timestamps are never saved or uploaded. In version 1.2.4 these observations accompany screenshot labels without changing them. Collectors using log-context diagnostics v3 instead read the log before and after a short frame sample, replacing screenshots and OCR in performance collection. They report recent lobby, matchmaking, match-starting or match activity, or unknown when evidence is stale, unavailable or changes across the sample. These labels do not identify the current combat/planning phase or numeric round; stage bands remain unknown.
The server keeps only the latest cumulative checkpoint per attempt, without a source IP, for 30 days from the attempt start; expired records are removed on server startup, subsequent writes, or report access. Up to 16 pending performance attempts, at most 256 KiB in total, may be queued in Mac preferences for up to seven days. After an unexpected launcher exit, the last checkpoint can be reported as interrupted on the next start; this does not identify a confirmed crash. Disabling optional diagnostics does not clear these checkpoints or stop collection and retries.
Optional extended diagnostics
Extended diagnostics are separate completed-session summaries, disabled until you explicitly grant consent in Mactician settings. Each contains a fresh random event ID; exact UTC completion time and duration; launcher version and build; consent version; profile and effects-quality IDs; display width, height, density, and UI scale; guest memory and CPU count; Mac model identifier; macOS version; physical-memory size; and logical CPU count.
These optional rows are retained for 365 days without an attached source IP. They contain no stable installation ID, Mac name, serial number, MAC address, Apple or Riot identity, password, authentication data, or game logs.
Turning Extended Diagnostics off stops new optional completed-session rows and removes their local pending queue. An optional request already in transit may complete. Activity, session-duration summaries and the performance metrics described above continue. A change to the optional diagnostic field set requires a new consent version.
Delivery, retries, and server processing
Pending events reuse their random event ID during retries. A snapshot is marked complete only after HTTP 2xx; every non-2xx response or network failure leaves it pending for a later launcher run. Daily-active events and session summaries remain pending after temporary failures and are removed after delivery, duplicate acknowledgement, or an unrecoverable client error. A pending first-session event keeps its existing behavior and expires locally after seven days.
The API rejects unknown or out-of-range fields and bounds request sizes. nginx passes the remote address only to the loopback telemetry service and keeps API access logging disabled. The service stores normalized source IP records for eligible first-session and snapshot events for 365 days for rate limiting and abuse investigation, first-session and daily-active event-ID hashes for 14 days, and snapshot and session-summary event-ID hashes for 730 days. It does not retain source IPs with daily-active events or session summaries, write source IPs or User-Agent headers to application logs, or attach them to stored extended diagnostic events.
Recipients and international processing
Telemetry is used only to operate and improve Mactician. It is not sold and is not shared with advertisers or data brokers. Infrastructure providers that host or protect sergeinaumov.dev may process the limited data described above only as needed to provide those services.
Depending on where you and the infrastructure providers are located, data may be processed outside your country. Safeguards required by applicable law are used for such processing. Email the privacy contact below for the current provider and transfer details relevant to your request.
Your choices and rights
The basic first-session event, one-time activation snapshot, anonymous daily-active heartbeat, anonymous summary of every completed session, and performance metrics for every Android launch are part of the current launcher behavior. Extended diagnostics are optional and can be enabled or disabled in Mactician settings at any time; disabling them withdraws consent for future diagnostic events and removes the local pending diagnostic queue, but does not disable performance collection, its active or pending checkpoints, daily-active events or anonymous session summaries. Mactician can also be inspected and built from source.
Subject to applicable law, you may request access, correction, deletion, restriction, or portability of personal data, object to processing based on legitimate interests, and lodge a complaint with your local data-protection authority. Basic events have no stable installation identifier. Locating one may require the source IP and an approximate time, and the source IP is unavailable after its 365-day retention period. Daily-active events and anonymous session summaries cannot be isolated after they have been aggregated because their raw payload and source IP are not retained.
Contact
For privacy questions or rights requests, email [email protected]. Include “Mactician privacy” in the subject.