Privacy Policy
Last updated: 9 August 2026
TrafficWeaver is software that runs on your Mac and handles your network connections. That makes this document more important than the usual boilerplate, so it starts with the part people actually want to know.
The short version
The application does not send the contents of your network traffic, the addresses you connect to, the names of the applications you run, or your connection log anywhere. None of it is transmitted to us or to any third party. It stays on your Mac. The only data that reaches us is what is needed to issue and check your licence, and it contains nothing about your traffic.
Who is responsible
Alexey Erenkov, an individual trading as TrafficWeaver, Dubai, United Arab Emirates. Contact for any privacy question, including requests described below: privacy@trafficweaver.app.
Data processed on your Mac and never sent to us
- Your rules, proxy server addresses and proxy credentials.
- The connection log: source application, destination address and port, matched rule, byte counts and status.
- A temporary in-memory mapping from IP addresses to host names, built by reading DNS responses that pass through the extension. This is what allows rules written against host names to match applications that resolve names themselves. It is held in memory only, discarded when the extension stops, and never written to disk or transmitted.
The application does not decrypt TLS and cannot read the contents of encrypted connections.
Data sent to us
Licence activation and validation
When you activate a licence, and periodically afterwards, the application sends: your licence key, a machine fingerprint, the application version, the macOS version and a timestamp.
The machine fingerprint is a salted one-way hash (HMAC-SHA256) of a hardware identifier. We do not receive the hardware identifier itself and cannot recover it from the fingerprint. Its only purpose is to count how many machines a licence is used on.
Legal basis, where the UK GDPR or EU GDPR applies: performance of the contract between us (delivering the licence you bought) and our legitimate interest in preventing licence misuse. Retention: for the life of the licence plus 24 months, after which activation records are deleted.
A machine fingerprint is treated as personal data under the GDPR even though it is pseudonymous, and it is handled accordingly.
Update checks
The application periodically requests an update feed from our server. That request necessarily reveals your IP address, the application version and your macOS version. Server logs containing IP addresses are retained for 30 days and are used only to detect abuse and diagnose faults. You can switch update checks off in the application's settings.
Crash reports
Crash reporting is off by default. If you turn it on, a report contains the stack trace, the application and macOS versions and the hardware model. Proxy credentials, licence keys, host names and connection data are excluded before a report is sent, and you are shown the contents before anything is uploaded. Retention: 90 days.
Purchases
Payments are handled by our reseller, who acts as merchant of record and is the controller of the payment data you enter. We receive your email address, the country used for tax purposes and the order details. We never see your card number. Please read the reseller's own privacy policy, linked from the checkout page.
Email you send us
If you write to support, we keep the correspondence for up to 24 months so we can follow up on the same issue.
What we do not do
- No analytics or telemetry in the application. There is no tracking SDK of any kind.
- No advertising, no profiling, no sale or sharing of personal data.
- No third-party cookies on this website. The site sets no cookies of its own.
Where data is stored
Licence and update infrastructure is hosted in the European Union. Support email is hosted by our email provider. Where personal data is transferred outside the UK or EEA, it is done under the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, and withdraw consent you previously gave. Write to privacy@trafficweaver.app and we will respond within 30 days. If you are in the EEA or the UK you may also complain to your national data protection authority.
Because activation data is tied to a pseudonymous fingerprint rather than an account, we normally locate your records by licence key or order email. If we genuinely cannot identify you from the information you provide, we will say so rather than guess.
Children
This is a developer tool and is not directed at children under 16. We do not knowingly collect their data.
Changes
If this policy changes in a way that affects what we collect, the date at the top changes and the application shows a notice at next launch. Previous versions are available on request.