Orthanc Privacy Policy

Effective date: August 9, 2026

Orthanc is a macOS app and set of browser extensions (Chrome, Firefox, Safari) that give you one-click AWS SSO login and AWS Console access. It is built and operated by an independent developer, and this policy describes everything Orthanc does with data, which is very little. The short version: your AWS credentials never leave your Mac, the only telemetry is anonymous counters you can turn off, and we store no identifier for you at all: no device ID, no account, no email.

1. Who we are

Orthanc is developed and published by Sebastien Stormacq, an independent (indie) developer.

Contact for anything in this policy, including data-deletion requests: orthanc@stormacq.net

2. Your AWS data stays on your device

Orthanc's core functionality is entirely local:

We (the developer) have no server involved in any of the above and no visibility into your AWS accounts, profiles, sessions, or activity.

3. Anonymous usage statistics (optional)

To know roughly how many people use Orthanc, the app can send a small, truly anonymous ping to our backend when it launches. The complete contents of that ping are:

That is the entire payload. It contains no device identifier, no user identifier, no IP-derived data, and no hash of anything. Deduplication happens on your Mac (the app remembers locally whether it already pinged today), so the server only increments aggregate counters. No per-device record of any kind is created, and there is nothing in our database that could be traced back to you, your Mac, or your purchase.

Because the data is aggregate-only, an individual ping cannot be located, exported, or deleted after the fact: there is no record of it as such, only counters that went up by one. This is a deliberate design choice. We would rather be unable to identify you than hold data we would then have to protect.

You can turn this off in the app: Settings → Privacy → the "Share anonymous usage statistics" toggle. When disabled, no ping is sent.

4. Purchases

Orthanc is free to use with two profiles. Unlocking unlimited profiles is a one-time purchase, and how it is processed depends on where you got the app.

If you installed from the Mac App Store, the purchase is an in-app purchase handled entirely by Apple. Payment processing, receipts, refunds, and your payment details are all handled by Apple under Apple's Privacy Policy. We never receive your name, email, Apple ID, payment information, or receipts. Your entitlement is verified on your device by StoreKit; our server never sees it, and we store nothing about your purchase.

If you downloaded Orthanc directly from our website, the purchase is processed by Stripe, using Stripe Managed Payments, which means Stripe (through its Link service) is the merchant of record, not us. The transaction will appear on your statement as LINK.COM*, and your receipt and invoice come from Link. Stripe collects and processes your payment details and email under Stripe's Privacy Policy; we never see or receive your card details, and we do not receive your email address.

What we store for a direct purchase is one or more rows containing only:

There is no name, no email, no address, no payment data, and no device identifier in that row, and it is not linked to any other data we hold. Its only purpose is to let you retrieve your license key again from our website (via the success page or the "Recover my license" page) if you lose it. We keep it for as long as the license is valid, that is, indefinitely, because deleting it would leave you unable to recover a key you paid for.

Your license key itself is validated on your Mac, against a public key bundled in the app. Orthanc does not phone home to check your license, at launch or ever, so we have no record of you using it.

If you want that license row deleted, email us with your Stripe/Link receipt number and we will remove it, with the consequence, which we will restate before doing it, that you will no longer be able to recover your key from our site.

5. Browser extensions

The Chrome, Firefox, and Safari extensions:

The data-use declarations we file with the Chrome Web Store (Developer Program Policies disclosure) and Firefox Add-ons (AMO) match this policy: the extensions themselves collect no user data.

6. What we do NOT do

7. Data processors (where the small amount of server data lives)

Three companies process data on our behalf or in connection with Orthanc, strictly as described above:

Separately, and not on our behalf, the app connects directly to your AWS endpoints for SSO login and console access (§2). In that relationship AWS is your provider, not our processor.

8. Your rights (GDPR, CCPA, and similar laws)

Legal bases (GDPR):

Your rights: you may request access to, correction of, or deletion of any data we hold. In practice:

CCPA/CPRA: we do not sell or share personal information as those terms are defined in California law. Beyond the license row described in §4, which contains no personal identifiers, we collect no personal information categories. There is no cross-border sale of data, or any sale of data, of any kind.

If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

9. Children

Orthanc is a professional developer tool and is not directed at children under 16. We do not knowingly collect data from children.

10. Changes to this policy

If we change what data Orthanc collects or how it is used, we will update this policy, change the effective date at the top, and for material changes note it in the app's release notes. The current version is always available at this URL.


Questions? Email orthanc@stormacq.net.