Legal
Privacy
This notice is short because the design is: TinyRocket checks links on your own Mac, and the app does not send anything this page does not name. It covers this website, buying and support, the app’s license and trial requests, optional Cloud Check, and Flight Check when that service is available.
Flash Media Solutions, Inc. is the data controller. Use the contact form about anything on this page.
What this website stores
- No download signup. The download page asks for no email, account or waiting-list entry; like every page here, it still uses the short-lived web session and anonymous page count described below.
- Support conversations, briefly. A message you send through the contact form is kept encrypted with our replies so the conversation holds together. Answered and closed threads are deleted 30 days after the last message; an unanswered request stays open so we can reply, but is deleted after 7 years at the latest. A dispute, chargeback or abuse record a person marks to preserve stays only while that reason requires it; an erasure request removes the live support-desk copy unless law requires the record. Replies are written by a person; an AI tool running on the same infrastructure that already carries the mail may translate the message and suggest a first draft, and nothing you write is used to train anything. A normal support notification contains only a link to the encrypted desk, not your name, address or message text. Email sent directly to support first has a raw inbound copy in Amazon S3 for up to seven days. Messages with attachments, and messages received while the desk is unavailable, are also forwarded to the owner mailbox for manual handling.
- A web session while you browse these pages. Visiting this site creates a short-lived session row holding your IP address, a browser identifier, a timestamp, and an encrypted session payload. If a form returns with an error, the values you entered may be held in that session so the form can be repopulated instead of making you type everything again. It exists so the contact form can be protected against cross-site request forgery. It expires after two hours of inactivity, and stale rows are physically removed by the nightly privacy prune.
- A count of page views, attached to nobody. The web server records the requested path without its query string, when it was requested, the response status and size, and which language was shown. Your IP address, your browser’s identity and the page you came from are all discarded before the line is written — not stored and then ignored, but never written down. A separate security log keeps the same identity-free fields for suspicious paths; both logs roll by size, and rolled log files are deleted after 30 days.
- Short-lived abuse counters. Forms, license lookup, checkout and app endpoints use temporary counters based on an IP address, a one-way email hash, or a one-way machine fingerprint to slow automated abuse. The counter stops applying when its short time window ends, and expired database rows are physically removed by the next nightly privacy prune.
We do read one report from Google: Search Console supplies the search phrase, clicks, impressions, average position and day for this site’s appearance in Google results. That is Google reporting on its own search results, not this site watching you — it needs no code on the page and sets nothing in your browser. Imported daily rows contain no visitor identifier and are deleted after 18 months.
When you buy
- A license record: purchaser name and email, license key, order and payment reference, seats bought, amount and currency, app language and version entitlement, purchase and contact timestamps, and any refund, revocation or retention state. It exists so we can re-send your license, manage seats, and honour the refund promise.
- Payment goes through Stripe. Stripe collects the full payment credentials; TinyRocket never receives the full card or bank details. We keep the receipt: what was bought, when, for how much. An owner-only support lookup can request the payment brand, last four digits, fees and refund state from Stripe; that response stays in request memory and is not saved locally.
- Signing in to your license page uses a six-digit code sent to your email, which expires in minutes. There is no password to store. Expired code rows are removed by the next privacy prune.
- Each Mac using a seat is recorded with a salted one-way, pseudonymous fingerprint the app computes on the machine. The row can also hold the optional Mac label you see in the app, plus last-seen and deactivation times. We cannot turn the fingerprint back into the hardware identifier, and a seat silent for eighteen months is released back to you automatically.
- Kept as long as the license lives. After 7 years of silence we warn you by email, then remove the person from the record and keep only the accounting row — the same anonymisation an erasure request performs. Follow the signed link and confirm to keep your license and contact details on file; the retention clock restarts that day.
Cookies and browser settings
tinyrocket-session— the browsing session described above. Expires after two hours.XSRF-TOKEN— the anti-forgery token that makes the contact form safe to submit. Expires with the session.locale— the language you picked, so the site does not forget it on the next page. Nothing but a language code, kept for a year.themeandmotion— optional display preferences saved in your browser’s local storage. They never leave your browser.
There is no analytics cookie, no advertising cookie, and no third-party cookie of any kind, so there is nothing here to ask your consent for and no banner to click past. That is not only a promise: the site sends a Content-Security-Policy that tells your browser to refuse any script, image, font or connection from anywhere but this domain, so nothing here can load a third-party tracker even by mistake.
What the app sends
- Standard link checks send no link. They run on your Mac against threat data on your disk.
- The trial sends a salted one-way machine fingerprint. We store it with the trial start and last-contact times so reinstalling the app does not restart the trial. A short-lived IP-based counter limits new trial records; it stops applying at the end of the day and its row is removed by the next nightly prune. A trial row is deleted after the later of its trial period or last check-in has been silent for two years.
- App and threat-data updates use scheduled fetches. The app requests the update feed, the update package itself when you install a new version, and the signed threat-data files — the manifest and its signature, the known-bad-domain, URL-shortener and look-alike-brand lists, and the public-suffix list; those requests do not contain a checked link, license, email or app account. The server necessarily receives a network address to return the file, but its access log discards that address and every request header before writing the path, time, status and size.
- License and sign-in requests send only what they need. Activation and deactivation send the license key, the one-way machine fingerprint and an optional Mac label; email sign-in also sends the email, a short-lived code and the app language; the machine list uses the license key.
- Buying in the app sends the seat count and app language. Stripe collects the payment details; the app keeps a random claim token and uses it with the Stripe session reference to collect the license after payment.
- A problem report is sent only when you submit it. It contains your email and description; the app version, macOS version, Mac model, current default link handler, target browser, threat-data version, entitlement state and app language shown for your approval; and an optional recent-log excerpt. It does not send your license key.
- Cloud Check never sends the clicked URL. Before the check, the app exchanges the same one-way machine fingerprint used for its trial for a short-lived day token in a request that contains no checked link; no token-to-machine mint record is stored. A license key is never part of this exchange. The app also renews this token quietly in the background about once a week; that renewal is identical in content to the exchange above, carries no checked link, and a success is kept on your Mac as a receipt for up to 30 days. When you ask for a check, the app removes the full host’s subdomains, path, query, fragment and userinfo locally. The request carries only the canonical public registrable domain and that pseudonymous token, with no clicked URL, license, email or app account. The service does not contact the destination website. The day-token design avoids a stored browsing history, but it is not cryptographic anonymity: an operator holding the token key and trial records could correlate a token.
-
Flight Check sends one exact address only after you consent to that link.
Unlike local checking and Cloud Check, the exact full address, including its subdomain, path, query and fragment, goes directly from the app to TinyRocket’s isolated scanner. The scanner endpoint necessarily receives your network address and request timing so it can answer; TinyRocket’s site authorization service receives a URL-free entitlement request, and neither that service nor Cloud Check receives the exact address or report.
The scanner runs one top-level navigation in a fresh remote browser and may follow server or client redirects and request page subresources. The destination and contacted third parties see the scanner rather than your browser, but they may keep their own request logs under their policies and TinyRocket cannot erase those observations.
TinyRocket captures the redirect chain, DNS and TLS facts, response headers, page text and DOM, a sanitized screenshot, network metadata, and bounded attempted-download evidence. No personal browser cookies, saved credentials or existing session are sent. The scanner will not enter credentials, submit forms, approve prompts, launch external apps or run downloaded files.
The visit may consume a password-reset, sign-in, invitation, unsubscribe or other one-time link, fire analytics, notify a sender, contact third parties, or cause effects from a GET request. The app therefore shows the exact address, processor, region, fields and retention and requires fresh authority and lawful-use confirmation before every submission; there is no standing consent.
The scanner signs and encrypts the report and sanitized artifacts to a one-time key created by the app. Only that TinyRocket app process holds the decryption key, and the decrypted report remains in memory unless you explicitly export it. After verified delivery the app discards its one-time proof and decryption keys and requests acknowledgement and deletion.
Target-derived data in TinyRocket-controlled systems is cryptographically erased after acknowledged delivery or within 60 minutes of scanner acceptance, whichever comes first. The deadline cannot be extended by a retry, failure or cancellation. URL-free quota, cost and security receipts remain under the account and accounting retention rules described on this page.
Flight Check is processed by Amazon Web Services, Inc. (AWS) in US East (N. Virginia), region
us-east-1, under the AWS Service Terms, which incorporate the AWS Data Processing Addendum. AWS publishes its subprocessor list. A Flight Check report describes one bounded visit from one scanner vantage. It cannot prove that a page is safe; a site may cloak, change, require a login or behave differently on your Mac. - Domain age comes from the public registry. When Cloud Check reports how old a domain is, it asks the public domain registry (RDAP) and keeps only the public registrable domain, its registration date, and when we asked — for up to 30 days, never beside a token, network address, or clicked URL.
- A dangerous-domain check may send a partial fingerprint to Google. Our server keeps a local copy of Google Web Risk’s list of malicious sites, stored as truncated fingerprints rather than names, and checks your domain against that copy without contacting anyone. Only when a domain’s fingerprint matches does our server ask Google to confirm it, and that question carries the first four bytes of the fingerprint — never the domain itself, the clicked link, your token, or your address. Four bytes cannot be turned back into a domain, though someone who already suspects a particular domain could test that suspicion against them. The question comes from our server, so your Mac is never in contact with Google. Google’s answer is kept on our server until the expiry Google sets, so the same question is not asked twice. Advisory provided by Google.
Who else is involved
-
Amazon Web Services hosts this site and carries the support mail; the drafting assistant described above runs on that same infrastructure, and nothing you write trains anything. AWS also operates the isolated Flight Check processing described above in US East (N. Virginia),
us-east-1. - Google supplies the malicious-site list described above, through its Web Risk service. It receives a four-byte fingerprint from our server when a domain matches our local copy of that list — never a domain, a link, a token, or your address, and never a request from your Mac.
- Stripe processes payments and keeps the full payment credentials. TinyRocket receives transaction and receipt facts, and can request limited payment-method facts for the owner-only support lookup described above.
Backups and deleted data
Nightly database snapshots — in which the sensitive columns are already encrypted: names, emails, license keys, support bodies — are used only for disaster recovery, so a record removed from the live database can remain in an older snapshot until that snapshot expires. Fourteen local snapshots rotate nightly. Offsite snapshots follow the storage bucket’s separately configured lifecycle; if a backup is restored, the retention and erasure jobs must run before normal service resumes.
Your rights
You can ask us for a copy of what we hold about you, to correct it, or to delete it. Requests through the contact form are handled within 30 days, free of charge. If you are in the UK or EU you may also complain to your data protection authority.
Changes
The date at the top marks each material change to this notice. This list and the app’s consent screen must name a request before TinyRocket can send it.