Legal

Privacy Policy

Last updated: August 3, 2026

The short version: Your scripts, workflows, and everything you type stay on your Mac — always. The App does send anonymous usage analytics — enough to tell us it is being used, which versions are out there, and whether people reach the upgrade screen. They carry no identifier of any kind — no account, no device ID, nothing that persists between launches — so they cannot be traced back to you, and we could not single you out even if asked. It contacts external services in three ways — to verify your license key, to check for updates, and to send that usage data. There is no advertising and nothing is sold. This website is separate: it uses cookieless visitor analytics that identify nobody, switched off entirely for EU visitors — see This Website. Exactly what the analytics contain is set out under Usage Analytics in the App.

Who We Are

Typestream is made by Bot in Space LLC. We are responsible for the data described in this policy, and we are the people to contact about it.

  • Company: Bot in Space LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA
  • Privacy contact: [email protected]

We aim to meet the standards set by data protection law wherever you live, including in Europe and the United Kingdom. The sections below explain what we handle, why, how long we keep it, and what you can ask us to do about it.

Overview

Typestream ("the App") is a macOS application that simulates human typing by replaying user-authored scripts via low-level keyboard event simulation. This Privacy Policy explains what data the App and this website do and do not collect, and how they operate with respect to your privacy.

We are committed to your privacy. The App works locally and requires no account. It contacts external services in only three limited, non-content ways — license verification, update checks, and anonymous usage analytics — each described below. It never transmits your scripts or the text you type.

Data We Do Not Collect

Typestream does not collect, store, or transmit:

  • Your scripts, workflow content, or any text you type through the App
  • The identity of the applications you type into, or anything shown in them
  • Keystroke logs — the App injects keystrokes, it does not record them
  • Your name, Apple ID, contacts, browsing history, or location
  • Anything that identifies you in the usage analytics — no account, no email, no device identifier, and nothing that persists between launches
  • Any detail of what you automate — never a workflow's name, its contents, or the tags and steps inside it

The limited data the App does send — your license key and device identifier for verification, update checks, and three anonymous events — is described in the sections below.

Local Data Storage

All data created within Typestream — including your workflows, step configurations, and preferences — is stored locally on your Mac using standard macOS storage mechanisms (UserDefaults for preferences, and workflow files saved to locations you choose). Your license key is stored securely in the macOS Keychain.

This data never leaves your device and is not accessible to us or any third party.

Accessibility API Usage

Typestream requests access to macOS Accessibility APIs solely to simulate keyboard events in other applications — this is the core mechanism that makes the App work. This permission:

  • Is used only to inject keystrokes during active playback sessions
  • Does not read, record, or transmit the content of other applications
  • Does not monitor your activity when the App is idle or in the background

You can revoke this permission at any time in System Settings → Privacy & Security → Accessibility. Revoking it will prevent the App from typing in other applications.

Usage Analytics in the App Anonymous

The App sends anonymous usage analytics through Aptabase, an open-source, privacy-focused analytics service for desktop apps. We use it to know whether people are actually using Typestream, which versions are in circulation, and whether the upgrade screen is being reached. (This section is about the App. The website is covered separately under This Website.)

It never sends your scripts, the text you type, or anything about the applications you type into. Aptabase's servers see the IP address of the request, use it to derive a rough country, and then discard it without storing it.

Nothing in this identifies you, and that is a property of the design, not a promise. There is no account, no email, no device identifier, and no persistent ID of any kind. Nothing identifying is stored on your Mac — no cookie, no analytics file, no identifier. The only thing tying two events together is a session marker held in memory that is discarded when the App quits, so even we cannot tell whether two launches came from the same person. We do not sell this data, share it for advertising, or use it to build a profile.

Aptabase handles this data on our behalf, on the terms of its Privacy Policy, which sets out how long it retains what it receives.

There is no switch for this in the App. We would rather tell you that plainly than imply a control that does not exist. Because these events carry nothing that points to a person, there is no individual record for us to find, show you, or delete — but if you would prefer not to send them at all, write to [email protected] and we will tell you how to disable them on your machine.

License Verification

If you purchase Typestream Pro, the App contacts our licensing provider, Lemon Squeezy, to activate and periodically verify your license key. To manage the number of devices tied to your license, the App sends a per-device hardware identifier as the activation's instance name, along with your license key. This is your Mac's platform UUID, or — on a Mac that does not report one — a random identifier generated once and kept on your Mac so that the same machine is not counted twice.

This identifier is retained only for as long as the activation is live. It is deleted when the device is deactivated, or when your license ends. If you never enter a license key, no license data is transmitted.

Lemon Squeezy is the seller of record for your purchase. Your order, payment, and invoice details are held by them under their own Privacy Policy, on their own terms rather than ours — and they are required by tax law to keep invoice records for a number of years, which is not something we can shorten or delete on request. See How Long We Keep Things below.

Software Updates

Typestream checks for new versions using Sparkle, a widely used open-source update framework for macOS. The App requests an update feed from our own server; like any web request, this includes your IP address, and the request identifies which version of Typestream and of Sparkle is asking. By default this happens about once an hour while the App is running.

Like any web request, these produce ordinary server logs, which Cloudflare keeps for us for a short period. Nothing is added to the request to track you, and nothing about the update check is stored on your Mac.

If you would rather not send these requests at all, you can turn off automatic update checks in Settings → General → Updates. You will then need to check for new versions yourself, so we'd encourage leaving them on for security fixes — but the choice is yours.

This Website

This website (typestream.app) is a static site hosted on Cloudflare Pages. It sets no cookies and runs no advertising or cross-site tracking scripts.

All typefaces are self-hosted and served from our own domain, so viewing this site sends no request to Google Fonts or any other third-party host. Two things involve your data when you visit:

  • Server logs. Cloudflare handles standard request data, including your IP address, user agent, and the pages you request, in order to serve the site and protect it from abuse. It does this on our behalf, under its own Privacy Policy.
  • Cloudflare Web Analytics. We use Cloudflare's privacy-first analytics to see which pages get visited and how quickly they load. Cloudflare adds a small measurement script to the pages we serve, which reports the page you viewed, the page that referred you, your rough location and device type, and page load timings. It sets no cookie, stores nothing on your device, builds no profile, and does not fingerprint you or follow you to any other site. There is no advertising use and no data is sold.

If you are visiting from the EU, this is switched off entirely. We have configured Cloudflare to exclude European visitors, so the measurement script is not added to the pages you receive and no analytics data about your visit is collected at all. For everyone else, the section below explains what we do with it.

Visiting the /buy page redirects you to a checkout hosted by Lemon Squeezy, where their privacy policy and cookies apply.

Third-Party Services

Typestream does not integrate with any advertising or cross-site tracking services, and does not sell or share your data. Where a provider handles data on our behalf, we have an agreement in place requiring them to use it only for what we've asked and to keep it secure. The external services involved are:

  • Lemon Squeezy — license activation and verification, and your purchase, on their own terms (only if you buy Pro)
  • Sparkle update feed — checking for new App versions (served from our own infrastructure)
  • Cloudflare — hosting for this website and the update feed, and cookieless visitor analytics for the website only (not for EU visitors), on our behalf
  • Aptabase — anonymous usage analytics for the App, on our behalf

Why We Handle This Data

We only handle data where we have a clear reason to, and we think it's fair to tell you what that reason is in each case:

  • License activation and verification — because it's part of providing what you bought. Without it we can't unlock Pro features or manage how many Macs your license covers.
  • Update checks — because keeping installations current is how security fixes reach you. You can switch these off.
  • App usage analytics — because we need to know whether Typestream is being used at all, which versions are still out there, and whether people are running into the Pro limits. Without it we would be guessing about what to build and when it's safe to retire an old release. We think a handful of events that identify nobody is a fair way to find that out, and we have kept the data deliberately too thin to say anything about any individual.
  • Serving this website — because a web server cannot deliver a page without handling the request.
  • Website analytics — because we'd like to know which pages people find useful and whether the site loads quickly, and we think a cookieless measurement that identifies nobody is a fair way to find out. We have switched it off for EU visitors rather than ask you to dismiss a consent banner.
  • Support correspondence — because you wrote to us and we'd like to answer.
  • Invoice and tax records — because the law requires them to be kept. These are held by Lemon Squeezy as the seller of record.

How Long We Keep Things

We keep data only as long as it's needed for the reason it was collected:

  • Device identifier for licensing — for the life of the activation. Deleted when the device is deactivated or the license ends.
  • Website and update-feed server logs — kept by Cloudflare for a short period, in line with its standard log retention.
  • App usage analytics — retained by Aptabase in line with its Privacy Policy. Because the events carry no identifier, there is no individual record to keep or delete — what remains is a count.
  • Website analytics — retained by Cloudflare for a limited period in line with its standard retention for this product, then dropped. What we see is aggregate page and performance counts; because nothing identifies a visitor in the first place, there is no individual record to keep or delete.
  • Support emails — kept while we sort out your question, and for a reasonable period afterwards in case you write back, then deleted.
  • Purchase, invoice, and tax records — kept by Lemon Squeezy for as long as tax law requires, commonly seven to ten years. This one is a legal obligation, so it can't be shortened or erased on request.

Everything you create in the App — your workflows, steps, and preferences — is stored only on your Mac. We never receive it, so how long it sticks around is entirely up to you.

Where Your Data Is Handled

We are a United States company, and the providers we rely on operate internationally. Cloudflare serves this website and our update feed from data centres around the world, including inside Europe. Lemon Squeezy handles purchases and licensing in the United States. Aptabase receives the App's usage analytics on servers in the United States.

Where data belonging to people in Europe or the UK reaches any of them, it is covered by the contractual protections for international transfers that each provider includes in its standard terms. If you'd like the details for a particular provider, email [email protected] and we'll point you to them.

Your Choices and Rights

Some of these you can act on yourself, without asking us:

  • Turn off update checks — in Settings → General → Updates.
  • Remove your device identifier — press Deactivate in Settings → License, which removes this Mac's activation.
  • Revoke Accessibility access — in macOS System Settings, at any time.
  • Usage analytics — there is no switch for these in the App. Write to us and we'll tell you how to turn them off on your Mac.

Beyond that there is not much left for us to hold. With no account, usage analytics that carry no identifier, and website analytics that identify nobody, the only record connected to you is your license — and even that sits with Lemon Squeezy rather than with us. Where we do hold something, you can ask us to show it to you, correct it, delete it, send you a copy, or stop using it for a particular purpose. Email [email protected] and we'll reply within a month at the outside. There's no charge.

One honest caveat: most of what reaches us can't be traced back to a person at all, so we may need your license key before we can tell which data is yours. For the usage analytics this is not a limitation we can work around — those events contain nothing that points to anyone, so there is genuinely no way for us, or for anyone else, to pick your data out of them.

If you think we've handled your data badly, we'd much rather you told us first so we can put it right. You also have the right to complain to the data protection authority in your country, and you can do that whether or not you come to us.

Children's Privacy

Typestream is not directed at children, and we do not knowingly collect personal information from anyone under 16 — or under the lower age limit set by your country, where one applies. Since the App requires no account and collects no directly identifying data from anyone, this holds universally.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. If we make a material change to what we collect or why, we will notify you in the App before the change takes effect, and where the change requires your consent we will ask for it.

Questions?

If you have any questions about this Privacy Policy or how Typestream handles data, please don't hesitate to reach out.

Visit our Support page →