Privacy Policy | Vigil
Last updated: August 5, 2026
This privacy policy applies to the Vigil macOS app, not the broschat-studios.com website.
Robin Broschat (Broschat Studios) operates the Vigil macOS app. This page explains how Vigil handles your data.
Principles (local first)
Vigil stores browsing, focus and statistics data locally on your Mac. No browsing history and no usage statistics are transmitted to Broschat Studios. There are no user accounts with us. The only exceptions are the outbound connections described below (Lemon Squeezy, optional Sparkle, manual crash emails).
Browser automation (focus enforcement)
Vigil uses macOS Automation (Apple Events / AppleScript) only in browsers you enable and explicitly allow in System Settings. When focus mode is active, Vigil reads the URLs of open tabs to compare them against your local blocklist and closes or redirects matching tabs. Vigil does not access your system calendar.
Passive tracking (local statistics only)
If "Passive Tracking" is enabled in Statistics (on by default), Vigil periodically reads tab URLs even when focus mode is off, only to estimate time spent on blocked domains. Aggregates are stored locally only; no full history is transmitted to Broschat Studios or third parties. You can turn it off at any time.
Notifications
If you enable them, Vigil shows local notifications (e.g. focus reminders or alerts when a blocked site was acted on). Content is generated on your device and is not sent to us.
Local storage
Settings, schedules, blocklists and statistics aggregates are stored locally via macOS UserDefaults and are not synced to any server. The licence key and device instance ID are stored exclusively in the local macOS Keychain on your Mac, not synced via iCloud.
macOS permissions
Vigil optionally requires Automation (Apple Events) permission in browsers you enable, and permission for local notifications. You grant these in macOS System Settings. They are used only for the described app features on your device.
Outbound connections
Vigil only makes the following network connections: (1) licence activation and periodic licence checks directly with the Lemon Squeezy API (api.lemonsqueezy.com); (2) an automatic update check via Sparkle, which contacts our own update server at updates.broschat-studios.com on launch. This only transmits the data typical of any web request (e.g. your IP address in server logs), no additional device or usage profile; (3) manual crash reports by email, only if you actively send them. There are no analytics or crash-reporting SDKs (e.g. Firebase, Crashlytics) and no usage or tracking telemetry. The update server runs on Broschat Studios' own infrastructure, but is used exclusively to deliver app updates, not for tracking.
Purchase & licence via Lemon Squeezy
The payment provider and merchant of record is Lemon Squeezy (Lemon Squeezy, LLC, USA). When you purchase and during licence validation, Lemon Squeezy processes payment and order data (e.g. name, email, payment details) and technical data for licence checks; payments are handled via Stripe. During activation, the app also sends the device name (computer name) you have set as an instance label, so Lemon Squeezy can match activations to your devices; a licence can be active on up to 3 Mac devices at the same time. After activation, Vigil automatically re-checks the licence with Lemon Squeezy every few days in the background, with an offline grace period of up to 14 days without an internet connection. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and/or Art. 6(1)(f) GDPR (legitimate interest in licence validation). This may involve transferring personal data to the USA (a third country). Lemon Squeezy and Stripe state that they use appropriate safeguards (e.g. EU Standard Contractual Clauses). That processing is governed by Lemon Squeezy's and Stripe's privacy policies. Via Lemon you may receive a licence key and access to your orders (e.g. My Orders).
Your rights (GDPR)
You may contact us at any time about this statement and about data we receive via support or manually sent crash emails (access, rectification, erasure, restriction, objection, portability where applicable). App data on your Mac is removed by uninstalling or using Reset App in settings. For Lemon Squeezy purchases you may also contact Lemon or rely on their privacy notices. You have the right to lodge a complaint with a supervisory authority (e.g. LfDI Rhineland-Palatinate).
Changes
We may update this privacy policy when the app changes or for legal reasons. The date above shows the current version. Material changes will be communicated via the app or this website.
Contact
Questions about this privacy policy or the app? Contact us: [email protected]