← ClickSorcery

Privacy Policy

Last updated: September 11, 2026

The Short Version

ClickSorcery is a local-first desktop application. Your conversations, documents, API keys, and business data stay on your device — we never see them.

What we collect is minimal: your email address and license key, used only to activate and manage your purchase.

1. Who We Are

Controller: Wicmath OÜ (registry code: 12189863), Estonia.

For privacy questions: help@clicksorcery.com.

This Privacy Policy explains what personal data we collect when you use ClickSorcery, why we collect it, how long we keep it, and what rights you have under GDPR and Estonian data protection law.

2. What We Collect and Why

For license activation and purchase management:

  • Email address — license delivery, purchase confirmation, critical product updates
  • License key — verifying your entitlement
  • Machine ID (hashed) — associating your license with up to two devices; no identifiable hardware data stored on our servers
  • Order ID and purchase date — purchase records and support
  • Optional download updates list — email and marketing consent timestamp if you opt in on the download page
  • Optional feedback — message content, feedback type, optional email, app version, plan, and machine ID when submitted from the app

Legal basis: Performance of a contract (GDPR Article 6(1)(b)). The public marketing site (clicksorcery.com) uses Vercel Web Analytics — aggregated page views only, no cookies, no cross-site tracking. The desktop app does not send usage analytics by default.

3. What We Cannot See

We have no technical ability to access:

  • Your API keys (stored encrypted on your device)
  • Your conversations with AI agents
  • Your documents, files, or Obsidian vault
  • Your business data, client information, or financial records
  • Your n8n workflows or automation outputs
  • Messages sent via connected services (Telegram, email, Slack, etc.)

When ClickSorcery connects to third-party services using your API keys, the connection goes directly from your device to that service. We are not in that data flow.

4. Third-Party Services You Connect

You connect your own accounts to services like OpenAI, Anthropic, Google, Stripe, n8n, Telegram, and others. Their privacy policies govern your use of those services.

We do not receive any data from them on your behalf, and your API keys never leave your device. We are not a data processor for any third-party service you connect through ClickSorcery.

5. Payment Processing

Payments are handled by Stripe. We never see or store your card details. Stripe's privacy policy applies: https://stripe.com/privacy

6. Service Providers

We use trusted processors to run our services:

  • Stripe — payment processing
  • Supabase — license, purchase, feedback, and optional download-lead database hosting
  • Vercel — website and API hosting
  • Resend — transactional email

7. Data Retention

Email + license key: until you request deletion, or 5 years after last activation.

Support correspondence: 2 years from last interaction.

Purchase records: 7 years (Estonian accounting law). Purchase records cannot be deleted due to legal retention requirements.

8. Your GDPR Rights

You have the right to access, correct, delete, restrict, export, or object to processing of your data. Email help@clicksorcery.com with subject "Privacy Request" — we respond within 30 days.

You may lodge a complaint with the Estonian Data Protection Inspectorate (https://www.aki.ee) or your local supervisory authority.

9. Security

License and activation data is stored with encryption at rest and access controls. No unencrypted transmission of your license data.

If we become aware of a breach affecting your rights, we will notify you as required by GDPR Article 33.

10. International Transfers

Stripe, Inc. and Vercel, Inc. participate in and are certified under the EU-US Data Privacy Framework (DPF), administered by the U.S. Department of Commerce. Supabase, Inc. and Resend, Inc. rely on Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR. All transfers are conducted in accordance with Chapter V of the GDPR.

For B2B clients requiring a Data Processing Agreement (DPA), please contact privacy@clicksorcery.com.

11. Children

ClickSorcery is not directed at children under 16. We do not knowingly collect personal data from children.

12. Changes to This Policy

Material changes will be communicated by email or in-app notice. The "Last updated" date at the top will reflect the latest version.

13. Contact

Questions about privacy? Contact help@clicksorcery.com.

Wicmath OÜ Registry code: 12189863 Estonia