1. Scope
This privacy policy covers the online services of Macro Deck that work with a Macro Deck account:
- Macro Deck accounts at auth.macro-deck.app, used to sign in to all services below.
- Macro Deck Store, including the Store API that the Macro Deck desktop app uses to show packages, download counts, ratings and reviews.
- Creator Portal at creators.macro-deck.app, where creators publish plugins, icon packs and other packages, and where moderators review them.
- Licence service, which turns a purchase of the Macro Deck Companion app into a licence.
How the desktop app and the companion app handle data on your devices is described in their own tabs.
2. Controller
Responsible for data processing:
Macro Deck, Owner Manuel Mayer
Porzer Straße 142A
53859 Niederkassel
Germany
Email: legal@macro-deck.app
We are not required to appoint a data protection officer. For all data protection questions, please contact us at the address above.
3. Macro Deck Account
3.1 Identity service
Macro Deck accounts are managed with ZITADEL, an open-source identity and access management software that we operate ourselves at auth.macro-deck.app. For your account, we process:
- username, display name, first and last name if provided, email address and its verification status
- profile picture, if you upload one
- password (stored only as a hash), passkeys and second factors you set up
- linked external identity providers, if you sign in with one
- roles, for example Store tester or moderator, and whether your account is active or suspended
- sessions and security events such as sign-ins, IP address, browser and device information
The legal basis is Art. 6 para. 1 lit. b GDPR, as the account is required to use the services described here. Security events are processed on the basis of Art. 6 para. 1 lit. f GDPR; our legitimate interest is protecting accounts against misuse and unauthorised access.
3.2 Signing in with an external provider
If you choose to sign in with an external identity provider, the provider tells us that you have authenticated and passes on the profile data you approve there, usually a user ID, name, email address and profile picture. The provider processes your data under its own responsibility and privacy policy. The legal basis is Art. 6 para. 1 lit. b GDPR.
3.3 Account emails
We send emails that are required to run your account, such as email verification codes, password resets and security notices. We send them through ZeptoMail, a service of Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands, via its EU data centres. Zoho processes the recipient address and the content of the email on our behalf under a data processing agreement (Art. 28 GDPR). The legal basis is Art. 6 para. 1 lit. b GDPR.
3.4 Cookies on the sign-in pages
The sign-in pages at auth.macro-deck.app use cookies that are strictly necessary to keep you signed in and to protect the sign-in process, for example against request forgery. These cookies do not require consent (§ 25 para. 2 no. 2 TDDDG). No analytics or advertising cookies are used.
4. Macro Deck Store
4.1 Browsing and downloading
The list of Store packages, their descriptions, images and files are public. Package files and images are delivered through Cloudflare R2 (see section 7). When a package is downloaded through the Store API, we count the download. To count each device only once per day without storing its IP address, we store a salted SHA-256 hash of your IP address together with the package and version. These hashes are deleted after 24 hours. The legal basis is Art. 6 para. 1 lit. f GDPR; our legitimate interest is showing download numbers that cannot easily be inflated.
If you are signed in when you download a package, we also store your account ID, how often and when you first and last downloaded the package, and the last version. We use this to let you review packages you actually use and to mark a review as "downloaded before review". The legal basis is Art. 6 para. 1 lit. b GDPR.
4.2 Ratings and reviews
Signed-in users can rate a package from 1 to 5 stars and write an optional title and text. We store your account ID, the rating, title, text, the time of creation and last change, how often the review was edited, and whether you downloaded the package before reviewing it.
Reviews are public. Everyone can see the rating, title, text, dates and whether the review was edited, together with the display name and profile picture of your account. Your account ID is not shown. The creators of the package see the same information. Moderators additionally see your account ID and your other reviews in order to handle abuse.
You can change or withdraw your review at any time. When you withdraw it, the title and text are deleted and the review is no longer shown. We keep a record that you reviewed the package, so that each account can review a package only once and reviews cannot be used for spam. The legal basis for publishing reviews is Art. 6 para. 1 lit. b GDPR.
4.3 Moderation
To keep the Store free of illegal and abusive content, moderators can hide, remove and restore reviews. Every moderation decision is recorded with the action, the reason, an internal note, the moderator and a copy of the review's title, text and rating at that time. You are informed of the reason for a decision about your review. Before every change to a review, we check with the identity service whether your account is suspended.
The legal basis is Art. 6 para. 1 lit. c GDPR in conjunction with Art. 16 and 17 of the Digital Services Act, which require us to handle notices and explain moderation decisions, and Art. 6 para. 1 lit. f GDPR; our legitimate interest is a safe Store and being able to prove moderation decisions. Moderation records are kept as long as they are needed for these purposes, in particular to handle complaints and legal claims.
5. Creator Portal
5.1 Creator registration
To publish packages, you register as a creator with your Macro Deck account and accept the Creator Guidelines and Store Policies. We store your account ID and the time you accepted them. The legal basis is Art. 6 para. 1 lit. b GDPR.
5.2 Projects, organisations and publishing
For your projects we process the listing data you enter (name, summary, description, author name and URL, licence, tags, icons, banners and screenshots), your organisations and their members, pinned projects, the history of changes you propose, review decisions and the notes moderators send you. Builds are linked to the GitHub repository, workflow run, commit and tag they were built from, and to the account that uploaded them.
Published data is public. Once a version is approved, its listing data, the repository URL, licence, changelog and the publisher name are published in the Macro Deck Store registry, a public GitHub repository. The publisher name is the name set in the package, otherwise the organisation name, otherwise your account username. Published versions cannot be changed; a published project can be unlisted but not deleted, because users may already have installed it.
The legal basis is Art. 6 para. 1 lit. b GDPR.
5.3 Package signing
Every published package is signed so that the Macro Deck app can verify that it comes from the Store unchanged. For this we issue a signing certificate per project that contains the name of the project and an identifier of its owner. For personal projects this identifier is your account ID; for organisation projects it is the organisation's ID. These certificates are published in the Store registry and embedded in each signed package. Certificates can be revoked but not deleted, because installed packages still refer to them. The legal basis is Art. 6 para. 1 lit. b and f GDPR; our legitimate interest is protecting users from tampered packages.
5.4 GitHub connection
To publish from GitHub, you connect the Macro Deck GitHub App. We store the GitHub account or organisation login and ID of the installation, the repositories you grant access to, who connected them and when. When you sign in to GitHub for this, GitHub gives us a temporary access token, which we use only within that request and do not store. We read repository contents, tags and workflow tokens from GitHub and write package manifests to the Store registry. GitHub is operated by GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. The legal basis is Art. 6 para. 1 lit. b GDPR.
5.5 Security review of packages
Before a version is published, its code is checked automatically for malware and security risks. If this check flags parts of the code of a package from a public repository, short excerpts around the flagged parts are sent to OpenRouter, Inc. (USA), which passes them to AI models for an assessment. Secrets are removed from the excerpts first. The code may contain personal data such as author names in comments. Code from private repositories is not sent. The legal basis is Art. 6 para. 1 lit. f GDPR; our legitimate interest is protecting Store users from harmful packages.
5.6 Notifications
The Creator Portal shows notifications about your projects. We also email you about review results and other important events. To send an email, we look up your email address in the identity service at that moment and do not store it in the Creator Portal. You can turn off informational emails in the settings; emails that are required for publishing cannot be turned off. Emails are sent through ZeptoMail (see section 3.3). The legal basis is Art. 6 para. 1 lit. b GDPR, and Art. 6 para. 1 lit. f GDPR for informational emails.
When a project is submitted for review, a short message with the project name, package ID and a link to the review is posted to an internal Discord channel for moderators. Discord is operated by Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands. The legal basis is Art. 6 para. 1 lit. f GDPR; our legitimate interest is reviewing submissions quickly.
5.7 Browser storage
The Creator Portal sets no cookies. It stores your sign-in tokens and the progress of the GitHub connection in the session storage of your browser, which is cleared when you close the tab, and your dashboard sorting in local storage. This storage is strictly necessary for the functions you use and does not require consent (§ 25 para. 2 no. 2 TDDDG). The Creator Portal does not use analytics, tracking or external fonts.
6. Companion App Licences
When you buy the Macro Deck Companion app in Google Play or the App Store, the purchase itself is handled by Google or Apple under their own responsibility. To activate the licence, the companion app hands the proof of purchase to your Macro Deck computer, which sends it to our licence service. The proof contains the store, the product, the purchase or transaction ID, the order ID, the app package name and the transaction data signed by the store. We check the proof and issue a signed licence that contains a licence ID, the product and the store it came from. It does not contain your name, email address or a device identifier.
We keep the licence and the proof of purchase for as long as the licence exists, so that we can prevent the same purchase from being redeemed repeatedly and revoke licences after refunds, and beyond that for as long as commercial and tax law requires. The legal basis is Art. 6 para. 1 lit. b GDPR, and Art. 6 para. 1 lit. c GDPR for statutory retention.
7. Hosting and Service Providers
- Servers: the identity service, the Store API, the Creator Portal, the licence service and their databases run on servers operated by us.
- Cloudflare R2: package files, images and uploaded builds are stored and delivered by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, as our processor under a data processing agreement. Cloudflare receives the IP address of devices that download files.
- ZeptoMail: sending emails, see section 3.3.
- GitHub, OpenRouter, Discord: see sections 5.2 to 5.6.
Server logs record the IP address, time, request path without query parameters, status code, referrer and browser of each request. We use them only to operate the services and to detect and defend against attacks, on the basis of Art. 6 para. 1 lit. f GDPR. IP addresses are also used briefly in memory to limit the number of requests. Logs are deleted after 30 days at the latest, unless they are needed to investigate a specific security incident.
8. Transfers to Third Countries
Cloudflare, GitHub, OpenRouter and Discord are based in the USA or may process data there. Where a provider is certified under the EU-U.S. Data Privacy Framework, the transfer is based on the adequacy decision of the European Commission (Art. 45 GDPR); otherwise it is based on the standard contractual clauses of the European Commission (Art. 46 para. 2 lit. c GDPR).
9. Storage Duration
We store your account data for as long as your account exists. When you ask us to delete your account, we delete or anonymise the data linked to it, unless we have to keep it:
- Published packages, their signing certificates and the publisher name stay available, because users rely on them; we remove your account username as publisher name on request where this is possible.
- Moderation records are kept as described in section 4.3.
- Data subject to statutory retention obligations, such as licence records, is kept until the end of that period.
Deleted accounts are shown without name and picture on reviews that remain. Other data is deleted as stated in the sections above.
10. Obligation to Provide Data
You are not legally obliged to provide personal data. Without an account, you cannot write reviews, publish packages or activate a companion licence; browsing the Store remains possible.
11. Your Rights
You have the following rights with regard to your personal data:
- Access to the personal data we hold about you (Art. 15 GDPR).
- Correction of inaccurate data (Art. 16 GDPR).
- Deletion of your data (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Receiving the data you provided to us in a structured, commonly used and machine-readable format (Art. 20 GDPR).
- Objection to processing based on our legitimate interests (Art. 21 GDPR), on grounds relating to your particular situation.
To exercise these rights, contact us at legal@macro-deck.app. We may ask you to confirm your identity, for example by writing from the email address of your account.
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de/
13. Changes to This Privacy Policy
We update this privacy policy when our services or the legal requirements change. The current version is always available at macro-deck.app/privacy. Last updated: 16 September 2026.