Privacy policy
Last updated September 4, 2026.
StowLink is a native macOS app and a free iPhone app. Your saved links, folders, notes, and preview cache stay on the device unless you turn on iCloud sync in Settings.
What the app stores locally
URLs, titles, descriptions, notes, folder names, and cached preview images. On Mac, the license key, instance ID, and last successful validation time are stored in the macOS Keychain on that device only. They are not synced with iCloud.
Optional iCloud
If you enable iCloud, library data uses your Apple Account and Apple’s CloudKit. We do not operate a separate cloud database for your links. Enable iCloud in StowLink on both iPhone and Mac, signed in with the same Apple Account, when you want one library on both devices.
Anonymous usage
StowLink for Mac can send anonymous product signals through TelemetryDeck (TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg, Germany) so we can see that the app opened and whether that Mac has a license (yes or no). This is not advertising. The first time you open a version that includes this, StowLink asks once and does not send anything until you choose Keep sharing or Turn off. You can change that later in Settings → General → Share anonymous usage.
TelemetryDeck is built so signals are anonymized before they leave the device. According to TelemetryDeck’s privacy FAQ, a signal can include:
- an anonymized user ID for that app installation, hashed on the Mac so it cannot be traced back to you
- the action we send: that the app opened, plus licensed yes or no
- a timestamp rounded to the nearest hour
- device metadata such as system version, app version, build number, and Mac model (default parameters)
StowLink does not send your license key, instance ID, email, saved URLs, titles, notes, or folder names. TelemetryDeck does not store IP addresses in its database or logs, and it does not use cookies. Its SDK is open source. Servers are in the EU (Azure in Amsterdam, AWS in Frankfurt, and Hetzner in Germany). TelemetryDeck currently keeps these anonymous events with no guaranteed deletion date.
More from TelemetryDeck: privacy policy and privacy FAQ.
Licensing and payments
Checkout is processed by Lemon Squeezy as merchant of record. The app sends your license key and a generated instance name to Lemon Squeezy’s License API to activate, validate, or deactivate. It does not send an account API key, and it does not put license keys in URLs, logs, or analytics.
Updates
Sparkle checks a public HTTPS appcast for a newer notarized build. That request does not include your license key.
This website
The product site is hosted by Cloudflare. We do not run user accounts. If you join the Windows waitlist, we store the email you submit in Cloudflare KV and send it to Resend so we can confirm you joined and tell you when a Windows build is available. We do not use that address for marketing. Databuddy collects anonymized usage data such as page views, outbound link clicks, purchase-button clicks, completed-order events, waitlist joins, and performance metrics. Completed-order events include the Lemon Squeezy order id and amount paid, not your name, email, address, or payment details. It does not collect your StowLink license key.
Contact
Questions: support@forgelyte.com