Privacy policy
Tri-Peak Solutions, Weiden in der Oberpfalz, Germany. Questions: support@tri-peaksolutions.com. Last updated 16 September 2026.
CoreCohort runs on your Mac and keeps its data there. This page lists, in the order the GDPR asks for, the little that reaches us, why, on what legal basis, for how long, who else touches it, and what you can ask of us.
Who is responsible
The controller for everything described here is:
Tri-Peak Solutions, represented by Luka Zadel
Obere Bachgasse 8
92637 Weiden in der Oberpfalz
Germany
Email: support@tri-peaksolutions.com
We are a small company and have not appointed a data protection officer; the law does not require one for the processing described here. Write to the address above for anything about your data.
The short version
The app sends nothing to us except what a licence check needs, and an update check that asks our server for the latest version number. We do not run analytics in the app, we do not upload crash reports, we set no cookies on this website, this website only counts page views and downloads as anonymous daily totals, and we do not sell or share data. When you buy, we keep what a shop must keep to deliver and invoice.
What stays on your Mac
Command history, terminal blocks, saved commands and timers, workspace layouts, saved sites and their credentials (encrypted with the macOS Keychain through Electron's safe storage), side-browser cookies and history (in their own cookie jar), agent chat transcripts and images you paste into a chat all live in the app's data folder on your Mac. Settings → Data lets you export or delete all of it. We never see any of it.
The app edits ~/.zshrc (shell integration) and ~/.claude.json (to mark a folder as trusted for Claude Code) only when you ask it to, or when you have switched on auto-trust in Settings. It tells you before it writes and keeps a backup of the previous file.
What the app sends to our server
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Licence key, a random install id, your Mac's computer name (from macOS Sharing settings), the app version, the date and the IP address the request came from | Activating a licence, checking it is still valid (at most once a day, offline in between), letting you see and deactivate your Macs on the manage page, enforcing the 3-Mac limit | Performance of the licence contract (art. 6(1)(b)); the IP address is processed on our legitimate interest in preventing abuse and keeping the service running (art. 6(1)(f)) | Activations: for the life of the licence; a deactivated Mac is deleted after 12 months. IP addresses: only in the web server log, deleted after 14 days |
| The app version and your IP address | Update check: the app asks our server for the latest version once a day. Releases are hosted on our own server, so no third party is involved | Legitimate interest in shipping security fixes (art. 6(1)(f)); you can switch the check off in Settings → General | Not stored beyond the 14-day web server log |
| Team plan only: the commands, timers, workspace definitions and site profiles you mark as shared, with the licence email of whoever last edited each item | Syncing the shared library between the Macs on one Team licence | Performance of the Team contract (art. 6(1)(b)) | While the item is shared; a deleted item's tombstone goes after 6 months |
The computer name is set by you in macOS and often contains your first name ("Ada's MacBook Pro"). Rename it in System Settings → General → Sharing if you would rather it did not. Site passwords and SSH keys are stripped before a shared site leaves your Mac; a shared command is sent as you wrote it, so do not put secrets in shared commands.
What we keep when you buy
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Email address, the name you enter, your country, your VAT id if you give one, what you bought, price, VAT breakdown, invoice number, the ids Mollie assigns to the customer, payment and subscription | Concluding and performing the purchase: issuing the key, emailing it, renewing, refunding, letting you manage the licence | Performance of the contract (art. 6(1)(b)) | The abandoned checkout of someone who never paid is deleted after 90 days. Paid orders and licences: for the life of the licence plus the invoice period below |
| The invoice (name, address country, VAT id, amounts, date) | Bookkeeping and tax | Legal obligation (art. 6(1)(c); § 147 AO, § 14b UStG) | Ten years from the end of the calendar year of the invoice. After an erasure request the email is removed and only the invoice fields stay |
| Transactional emails: the licence key, receipts, a notice when a renewal payment fails, a notice when this policy changes materially | Delivering what you bought | Performance of the contract (art. 6(1)(b)) | Sent through Brevo and not stored by us beyond the order record |
| A per-licence event log (created, activated, renewed, refunded, revoked) and a record of each data request we answer | Support, dispute handling, proving we did what you asked | Legitimate interest (art. 6(1)(f)); records of data requests: legal obligation (art. 5(2)) | 2 years; records of data requests are kept |
We never see your card or bank details. Payment happens on Mollie's pages. We do not send marketing email and do not profile anyone. No decision about you is automated in the sense of article 22.
Who else receives data
Mollie B.V., Amsterdam, Netherlands: payment processing. Mollie is an independent controller for the payment itself (card data, fraud checks) and a processor for the customer record we create there; see mollie.com/privacy.Brevo (Sendinblue SAS), Paris, France: sends our transactional emails (licence key, receipts, renewal notices). Processor under Brevo's data processing agreement; the data stays in the EU.Hetzner Online GmbH, Gunzenhausen, Germany: hosts this server and the encrypted off-site backups. Processor under a data processing agreement; the data stays in Germany or Finland.Nobody else. We do not use analytics, advertising or tracking services of any third party on this website or in the app. Authorities receive data only when the law obliges us.
Transfers outside the EU
Mollie, Brevo and Hetzner process in the EU. The app itself is downloaded from our own server. Coding agents and AI servers you configure in the app are your own choice and your own contract.
Your rights
You can ask us, at the address above, for access to the data we hold about you (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), a copy in a machine-readable format (art. 20), and you can object to processing that rests on our legitimate interest (art. 21). We answer within one month. We will ask you to write from the address on the licence, or to quote the licence key, so we do not hand your data to someone else.
Erasure in practice: we cancel any renewal, delete the customer record at Mollie, delete your Macs from the licence, and replace your email on the licence, on orders and on team-library edits with an anonymous placeholder. Your licence key keeps working for the period you paid for, because the key itself is not personal data. Invoices stay for ten years without your email, as the tax code requires.
You also have the right to lodge a complaint with a supervisory authority. The one responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, lda.bayern.de. You may also complain to the authority of the EU country where you live.
Cookies and this website
This website sets no cookies and loads nothing from third parties: fonts and images come from our own server. The admin console used by our staff keeps its sign-in token in the browser's local storage. Mollie's payment page, which you reach from the checkout, uses cookies under Mollie's policy. The web server keeps a standard access log (IP address, time, page, browser) for 14 days to detect abuse, on the basis of art. 6(1)(f). Separately, to see whether anyone visits at all, we count how often the start page, the download and the checkout are opened: one number per day, plus the host name of the site a visitor came from. No IP address, cookie, browser fingerprint or other identifier is stored with these counts, so they are not personal data and cannot be traced to you.
Security
Data in transit is protected by TLS. Licence tokens are signed (Ed25519) and cannot be forged; links to the manage page and invoices are signed too. The server disk is encrypted, backups are encrypted before they leave the machine and are kept for 30 days, so erased data disappears from backups within that window. Access to the admin console is limited to the people who run Tri-Peak Solutions. Should a breach affect you, we notify the authority within 72 hours and you without undue delay, as articles 33 and 34 require.
Children
CoreCohort is a professional tool. We do not knowingly process data of children under 16 and the shop is not aimed at them.
Changes
When this policy changes in a way that matters, we note it here with the date and email paying customers before it takes effect. Older versions are available on request.