Legal

Privacy Policy

Last updated: 7 September 2026

The short version. This website has no analytics, no cookies and no trackers. Your donor records stay on your computer, encrypted — we cannot read them. Before you activate a license key, Mich sends nothing anywhere unless you ask it to. We have never sold personal information and never will.

1. Who we are

Mich is made and sold by Naughty Robot LLC, doing business as Mich Software, a limited liability company registered in Washington State, United States. In this policy, "we", "us" and "our" mean Naughty Robot LLC.

You can reach us at support@michmeansgift.com.

2. What this policy covers

It covers two things: the michmeansgift.com website, and the Mich desktop application you install on your own computer. They behave differently, so they are described separately below.

It does not cover other people's websites we link to, or services you choose to connect Mich to yourself.

3. The website

We do not use analytics, advertising, tag managers, social media pixels, session recording or any other tracking. We do not set cookies. There is no login and no account.

Like any website, ours is served by a hosting provider that keeps standard server logs — typically the requesting IP address, the page requested, and a timestamp — for security and troubleshooting. We do not use those logs to build a profile of you, and we do not combine them with anything else.

4. When you contact support

If you email us, we receive what you send: your email address, your message, and anything you attach. We use it to answer you, and we keep the correspondence so that if you write again we have the history.

We will not add you to a mailing list because you asked a support question. If you ever want your support correspondence deleted, ask and we will delete it.

There is one list, and you have to ask to be on it: if you email interest@michmeansgift.com to hear when the macOS or Linux version is ready, we keep your address for that one purpose. We will use it to tell you about that release and nothing else, and we will delete it on request or once the release has gone out.

5. When you buy a license

Purchases are sold through Link, a Stripe service, acting as the merchant of record. In plain terms, Stripe is the seller on the transaction: you enter your card details on Stripe's systems, not ours, and we never see or store your full card number. Stripe also sends your receipt and invoice directly to you — those emails come from Link, not from us.

From a completed purchase we receive order information such as your name, email address, country, the amount paid, and the last four digits of the card for reconciliation. We use that to issue your license key, honor refunds, and keep the business records we are required to keep.

Because Stripe is the merchant of record, it holds the payment relationship with you under its own privacy policy, and it also handles tax, fraud checks and payment disputes. If you check out with a Link account, you can view your orders and request deletion of your Link data directly through Link.

6. When you activate a license

License activation is handled by LicenseSeat, and it is the one part of Mich that must contact the internet. When you activate a purchased key — and periodically afterwards, in the background, to confirm the license is still valid — Mich sends:

That is the whole list for activation. No donor records, no organization data and no personal details are sent when a key is activated or re-checked.

Mich never asks you for an email address

There is no trial to request and no sign-up. Mich is free to use with record limits, and the only reason it contacts anyone is to check for a newer version and, if you buy one, to activate and re-check your license. Your email address is never sent by the software at all — if we have one, it is because you gave it to us when you purchased, or wrote to us.

The device fingerprint is a one-way cryptographic hash derived from a few stable characteristics of your computer. It exists so a license can be tied to one machine. It is a fixed-length string of letters and numbers; it cannot be reversed to reveal anything about your hardware, and it does not identify you personally.

An unlicensed copy sends nothing about you or your computer. It does make one kind of request: it asks whether a newer version of Mich has been released. That request says which product and platform is asking — nothing else. No device fingerprint, no email address, no operating system or timezone details, and nothing whatsoever from your database. As with any web request, the server sees the IP address it came from.

The details listed above are sent only once you activate a license, and only then.

7. Your donors' data

This is the part that matters most to the organizations who use Mich, so we will be precise.

Everything you record in Mich — donors, gifts, pledges, events, receipts — is stored in a database file on your own computer. It is encrypted at rest using a master password that you choose. That password is never stored anywhere: not in the file, not in a settings file, not on any server of ours.

The practical consequence is that we cannot read your data. Not on request, not for support, not if compelled. We do not have a copy and we do not have the key. The same fact means we cannot recover your data for you if you lose your password — please keep it somewhere safe.

Your backups are yours, kept wherever you choose to put them. They are not sent to us.

8. Optional features that contact other services

Two features can send information outside your computer. Both are off until you turn them on, and both are described here so the choice is an informed one.

Address verification — off by default

If you switch on address verification in Settings → Data Entry, Mich checks addresses as you enter them by querying OpenStreetMap's Nominatim service. When it does, it sends only the address fields: street address, city, state or region, postal code and country.

No donor name, email address, phone number, gift amount or any other record detail is included. Even so, a postal address can identify a household, so this is a real disclosure and not a formality — if your organization would rather no donor address left your machine, leave this setting off, which is how it ships.

Email delivery — off by default

Mich can email receipts and event invitations, but only through an email account you supply — SendGrid, Resend or Mailgun. The message goes from your provider account to your recipient. We are not in the middle of it and we do not receive a copy. Your relationship with that provider is governed by their terms and privacy policy.

If you use Check Delivery, Mich asks that same provider what became of messages you have already sent. It sends only the identifier the provider gave back when it accepted each message — no donor name, address or gift detail — and the answer is stored on your own computer alongside the receipt. This goes to your provider, not to us.

9. What we never do

The only third parties involved are the ones named in this policy, each doing a specific job: Stripe and Link for selling and taking payment, LicenseSeat for issuing and activating licenses, our web host, our email provider, and the optional services in section 8 that you switch on yourself.

10. How long we keep things

11. Security

Your Mich database is encrypted at rest with your own password. Backups carry the same encryption. All connections the application makes — activation, and any optional feature you enable — use HTTPS.

On our side, we keep the information we hold to the minimum described above, which is the most effective security measure available to us: information we never collect cannot be breached.

12. Where information goes

We are based in the United States, and the services we use — Stripe, LicenseSeat, our host — may process information in the United States or elsewhere. If you are outside the US, the limited information described in this policy may be transferred to and processed in the US.

13. Children

Mich is business software for organizations. It is not directed at children, and we do not knowingly collect information from anyone under 16.

14. Your rights

You may ask us what information we hold about you, ask us to correct it, or ask us to delete it. Email support@michmeansgift.com and we will respond.

Because we hold so little, these requests are usually simple: for most customers, everything we hold is a purchase record and possibly a support email thread.

If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR and UK GDPR, including access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. If you are a California resident, you have rights under the CCPA/CPRA — and note that we do not sell or share personal information, so there is nothing to opt out of.

15. Changes to this policy

If we change this policy we will update the date at the top of the page. If a change is significant — particularly if Mich ever begins collecting something it does not collect today — we will say so clearly rather than quietly editing the text.

16. Contact

Naughty Robot LLC, d/b/a Mich Software
Washington State, United States
support@michmeansgift.com