Privacy Notice

Last updated: September 26, 2026

1. Who We Are

cflo inc. ("we", "us", "our") is a software company based in Wilmington, Delaware, United States. We sell macOS audio software for DJs and music producers. You can reach us at contact@cfloinc.com.

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: name, email address, billing address, payment method details (processed by our payment providers, Stripe or PayPal, depending on how you pay — we never store card numbers)
  • Purchase data: order history, products purchased, license keys issued
  • Usage data: pages visited, time on site, referring URLs (via Google Analytics, only with your consent)
  • Device data: machine identifiers for software license activation (stored by Keygen.sh)
  • App data: usage counts and crash reports from our Mac apps (see section 3)
  • Communications: support emails and messages you send us, including any diagnostic files and logs you choose to attach
  • Campaign attribution: the campaign parameters (UTM tags) in the link that brought you to our site — including links opened from the cflo inc. installer app, which carry campaign parameters but no device or installation identifier — stored alongside your email address if you subscribe to a product newsletter or waitlist

3. Data Our Apps Send

Our Mac apps send two kinds of data so we can keep them working and improve them: usage counts and crash reports. Neither ever includes your music, audio, song, playlist, crate or file names, or the contents of your library. The list below says what each app sends and how to turn it off.

Usage counts go to TelemetryDeck. They are numbers and fixed categories, for example how many tracks a scan found or whether a task finished. Each one also carries basic facts about your Mac and the app: the macOS version, Mac model and processor type, app version, language, region and time zone, display settings, and how often and how long you use the app. TelemetryDeck receives a scrambled (one-way hashed) identifier, not your name or email address.

Crash reports go to Sentry when an app crashes or hits a serious error. A report holds technical details: what the app was doing when it failed, the app version, the macOS version, your Mac's model, memory and language, and an identifier for your installation. It can also include the folder the app is installed in, which may contain your Mac user name.

Like any server, both services see the internet address your Mac connects from.

  • Dupes: usage counts (library size, crates, missing files, duplicates resolved, disk space reclaimed, the matching and keep settings you chose, and the types of errors the app hits) and crash reports. Once you activate a licence, Dupes' usage counts carry an identifier derived from your licence email address, and its crash reports include that email address so we can contact you about a problem. To turn both off: Settings > General > "Share privacy-preserving diagnostics & crash reports". This is on by default.
  • 3vise: usage counts (whether each file repair fixed the file, left it unchanged or failed, and whether the app is licensed) and crash reports, neither linked to your account. Both are on by default. Until the next update adds a Settings switch, you can turn both off by running this command in Terminal: defaults write com.cfloinc.3vise com.cfloinc.3vise.crashlytics.optOut -bool true
  • Stemverter: usage counts (whether each separation finished, how long it took, the stem and format options you chose, and ranges for the song's length, the file's size and your Mac's memory) and crash reports, neither linked to your account. Both are on by default. Until the next update adds a Settings switch, you can turn both off by running this command in Terminal: defaults write com.cfloinc.Stemverter2 com.cfloinc.Stemverter2.crashlytics.optOut -bool true
  • GoodbyeTunes (beta): usage counts about your library's size and each migration (numbers of tracks, playlists and files, counts by file format, bytes moved, free disk space, your Serato version, and which other cflo inc. apps are installed) and crash reports, neither linked to your account. To turn both off: Settings > General > "Send crash reports". This is on by default.
  • Cleanverter (beta): usage counts (whether a scan or export finished, how many flagged words a scan found, and whether the vocal separator ran), not linked to your account. It sends no crash reports. To turn usage counts off: Settings > Diagnostics & Privacy > "Share anonymous usage data". This is on by default. To find lyrics, Cleanverter also sends each song's title, artist and length, or its file name if the song has no title, to LRCLIB (lrclib.net), a free public lyrics database.
  • 3vise 2.0.1 and earlier (the version for macOS 10.12 to 11): each time it checks your licence, it sends your email address, licence key, Mac name, internet address, network hardware address, home folder path, Mac model, macOS version and file counts to Google Firebase. An upcoming 2.0 update stops this.

4. How We Use Your Data

  • Fulfilling your software purchases and delivering license keys
  • Managing license activations and machine limits
  • Sending transactional emails (order confirmation, license delivery)
  • Responding to support requests
  • Improving our website (analytics, with consent) and our apps (usage counts and crash reports, see section 3)
  • Measuring advertising effectiveness (Facebook Pixel, with consent)
  • Attributing newsletter and waitlist signups to the campaign or installer link that referred them, to measure which campaigns drive interest

5. Legal Basis (GDPR)

For visitors in the European Economic Area, we process your data under:

  • Contract performance — processing orders, delivering licenses
  • Legitimate interests — fraud prevention, security, responding to support and pre-sale inquiries, measuring which campaigns or installer links drive newsletter/waitlist signups, and keeping our apps working and improving them from usage counts and crash reports, which you can turn off in each app
  • Consent — cookie- and pixel-based analytics and advertising measurement (you can withdraw at any time via our cookie banner)

6. Third Parties We Share Data With

  • Stripe — payment processing (privacy policy)
  • PayPal — checkout payment processing (privacy policy)
  • Keygen.sh — license key management
  • Google Analytics — site analytics (with consent)
  • Meta (Facebook) — advertising measurement (with consent)
  • DigitalOcean — infrastructure and hosting
  • WooCommerce / WordPress — e-commerce platform
  • Atlassian — customer-support ticketing (Jira Service Management): support requests and correspondence, related contact details, and diagnostic files and logs you choose to send us (privacy policy)
  • TelemetryDeck: usage counts from our Mac apps, stored in the EU (privacy policy: https://telemetrydeck.com/privacy/)
  • Sentry: crash reports from our Mac apps, stored in the United States (privacy policy: https://sentry.io/privacy/)
  • Google Firebase: data sent by 3vise 2.0.1 and earlier (privacy policy: https://firebase.google.com/support/privacy)

We do not sell your personal data to third parties.

7. Data Retention

We retain your account and purchase data for as long as your account is active and for 12 months after account termination, or as required by law. Analytics data is retained per Google's default retention settings (14 months). Newsletter and waitlist subscriber data, including any campaign-attribution parameters stored with it, is retained until you unsubscribe or ask us to delete it.

App data: TelemetryDeck keeps app usage counts available for analysis for 24 months, then moves them to archive storage in the EU; it has no fixed deletion date and expects to delete them after 7 to 10 years. Sentry keeps crash reports for 30 days and deletes its backups 90 days after making them. We keep data sent by 3vise 2.0.1 and earlier for 12 months, then delete it.

Support tickets: retained 24 months after resolution, then deleted. Diagnostic-log attachments: deleted at the earlier of 30 days after resolution or 90 days after upload.

8. Your Rights

Depending on your location, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — ask us to limit how we use your personal data in certain circumstances, such as while we verify its accuracy or consider an objection
  • Portability — receive your data in a structured format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — update analytics and marketing preferences at any time via the cookie banner, and turn off usage counts and crash reports in each app's Settings
  • Opt out of sale or sharing — disable advertising cookies and pixels at any time via our cookie consent banner (see our Cookie Policy) (CCPA)

To exercise your rights, email contact@cfloinc.com. We will respond within 30 days.

Where applicable, you may also lodge a complaint with the competent data-protection or supervisory authority.

9. International Transfers

Our servers are located in the United States (DigitalOcean NYC). If you are in the EEA, your data is transferred to and processed in the US. Support requests are handled through Atlassian, which hosts support data globally and may process it in the US or other regions. We rely on Standard Contractual Clauses and the adequacy decisions of our processors to safeguard these transfers.

10. Changes to This Notice

We may update this Privacy Notice from time to time. We will notify registered users of material changes by email. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact

cflo inc.
221 W 9th St #549
Wilmington, DE 19801
United States
contact@cfloinc.com

Cart

Your cart is empty