Putback asks for one macOS permission, Accessibility, and uses it only to read the position and size of your windows and to move them. Your layouts (window frames, app identifiers, and display configurations) live in a local file that never leaves your Mac. You can inspect or delete it anytime at ~/Library/Application Support/Putback.
A few small things travel to our servers so licensing, the trial, and stability can work. Here is every one of them, with its exact contents. There are no user accounts.
When you activate a paid license, Putback sends your license key, a device identifier, and the device name (so you can recognise your Macs when managing the license). Nothing else.
During the 7 day trial, Putback checks in with an anonymous device identifier, the app version, and the macOS version. That is all it needs to count the trial days. No name, no email, no window contents.
If Putback crashes, the next launch sends an anonymous report: the app version, the macOS version, the hardware model, and the crash stack from Putback's own code. Never the contents of your windows, never anything you typed.
Putback checks for new versions through Sparkle, the standard macOS update framework. That is a request to our update feed so the app can tell you an update exists.
The site uses first-party analytics only. No cookies, no advertising, no third-party trackers. Each page view records the page path, the referrer, an optional campaign tag from the link you followed, and your country (read from Cloudflare's edge, never stored alongside anything that identifies you).
It also records a visitor number that is a one-way hash of your connection details (IP address and browser) mixed with the current date. Because the date is part of the hash, the number rotates every day, so it cannot follow you from one day to the next. The IP address itself is never stored.
When you finish a purchase, the thank-you page sends one more first-party beacon that ties that sale to the same session-level source above (the link or referrer that brought you), so we can tell which channels actually pay off. It carries no new identifier, no amount, and no email. We also keep a short-lived tally of how many people are on the site right now; it reuses that same daily-rotating visitor number and is discarded within minutes, so it is a live count, never a history.
Voting and commenting on the public roadmap use a random token saved in your browser's localStorage, so a vote counts once without an account. Clear the site's data and the token is gone.
Only when you explicitly hand it over: signing up for the newsletter, sending a support ticket, asking to be told when a roadmap idea ships, or buying a license. If you never do any of those, we never have your email.
A handful of processors help run Putback. We keep the list short and name them plainly.
Handles payments. Your card details go straight to Stripe and never touch our servers.
Sends transactional email: license keys, receipts, support replies, and the confirmations you ask for.
Configured as an alternate email sender we can switch to if we ever need it.
Hosts the website, stores the database, and routes inbound email to us.
Email [email protected] to ask what we hold about you, or to have it deleted. Our data lives on Cloudflare infrastructure.
Last updated: July 7, 2026. Rewrote this page around the honest split between what stays on your Mac and what leaves, named every processor, and noted the purchase-confirmation beacon and the live-visitor count.
