Superposer Privacy Policy
Last updated: 2026-10-08 (shared compatibility results, T8.8)
Controller: [Company legal name], [Address] · privacy contact: [email protected] [EU/UK representative, if required: name and address] · [Data protection officer: none appointed / name]
The short version
- Superposer works on your Mac. Your games, saves, Steam library and settings aren't uploaded to us.
- No telemetry unless you opt in. The app doesn't phone home with usage, crash or hardware data by default. [If you add opt-in telemetry later, list it here and in the app.]
- Compatibility reports are your choice, redacted, and public once you submit one.
- Sharing your results with other players is off unless you turn it on (section 4b). When on, each verdict you save goes, redacted, to our results server under a random ID for your Mac: no account, name or email. Everyone's results are merged and shown in the app as counts and short notes.
- Problem reports (logs and crash reports after a game fails) are opt-in and stay on your Mac: you see every item first, can leave items out, and Superposer never uploads one. It saves a zip on your Mac that you can email to us from your own mail app, copy or keep.
- We don't sell your personal data, and we don't share it for advertising.
- Payments are handled by Stripe, which is the seller (merchant of record) through Stripe Managed Payments. We never see your card details. Licence keys are checked by our own small licence server, which stores the key and an activation ID, not your name or email.
1. What stays on your Mac
Superposer reads your Steam installation and library locally (installed games, owned and played app IDs, Steam build IDs, launch settings, play history) to set games up, to show your library and to check compatibility. Game prefixes, profiles, the change journal, test screenshots, logs and problem reports live in ~/Library/Application Support/Superposer and the game folders; downloaded store images and trailer details are cached in ~/Library/Caches/Superposer. We don't receive any of it. Superposer's game profiles ship inside the app and change only when the app updates. Uninstalling removes what Superposer added.
2. Connections your Mac makes (not through us)
The app on your Mac contacts these services directly, with the app ID of the game involved. Some requests run in the background: after your library loads, Superposer looks up public facts for each installed Windows game that has no Mac version (at most once a week per game, one request at a time) to suggest settings, and the library shows store trailers and screenshots. Their own privacy policies apply, and they see your IP address:
| Service | Why |
|---|---|
| Steam store (store.steampowered.com) and Steam's content servers | Game details and the Steam Deck rating (to suggest settings); trailers and screenshots, only to display them. Library art comes from Steam's cache on your Mac. Trailers play with sound by default (turn it down or off in Settings › Appearance › Trailer sound, or with the speaker button in the toolbar); turning off Settings › Appearance › Play trailers stops all trailer requests, while game pages still fetch store screenshots |
| ProtonDB (protondb.com) | Compatibility summaries (ODbL; credited in the app) |
| PCGamingWiki (pcgamingwiki.com) | Technical facts such as graphics API and engine (CC BY-NC-SA; facts only, credited) |
| GitHub (raw.githubusercontent.com) | During the background lookup above, a check for a newer Superposer profile for that game in Superposer's repository. The repository isn't public yet, so this finds nothing and your settings come from the profiles inside the app |
| Microsoft (download.microsoft.com, download.visualstudio.microsoft.com, aka.ms) | Windows runtime installers a game needs (checksum-verified) |
| Valve's GitHub, llvm-mingw project | Source and tools to build the Steam bridge on your Mac, only when the included bridge doesn't match your runtime |
| Apple (developer.apple.com) | A link to Apple's Game Porting Toolkit, if you choose to import D3DMetal from your own download instead of the included copy |
These requests go from your Mac to those services. We run no server in the middle and don't receive copies. The app talks to three servers of ours: the licence server, only for licence checks and "Manage Subscription", the update feed on superposer.app (both in section 3), and, in builds that have it, the results server for shared compatibility results (section 4b). Links you click (the store, Apple's support pages, our website, a GitHub issue form) open in your browser.
3. Data we do collect
| Data | Why | Legal basis (GDPR) | Kept |
|---|---|---|---|
| Account and purchase data: name, email, country/billing address, subscription and payment status, tax data. Collected by Stripe at checkout; we can see it in Stripe's dashboard and use it for support and accounting | Provide Plus, support, accounting | Contract; legal obligation | While the subscription is active, then as the law requires (tax records typically [6–10] years) |
| Licence check: the app sends your licence key, a random activation ID for this Mac and the Superposer version to our licence server (license.superposer.app, hosted on Cloudflare); no hardware, device or user names (ADR 0015, 0016). The server stores the key, your Stripe customer and subscription IDs, the subscription status and dates, and per Mac the activation ID, app version and when it was activated and last checked: no name, email, IP address or payment details. Cloudflare sees your IP address in transit, as any web host does. Your Mac keeps the key, activation ID and status in its keychain. "Manage Subscription" asks the server for a one-time Stripe billing link | Confirm your subscription, limit activations, open your billing page | Contract; legitimate interest in preventing misuse | While the subscription exists, then [90] days; activations until you deactivate the Mac |
Lost licence key (only if you use "Lost your key?" in Settings › Subscription, or superposer license recover): the email address you type goes to our licence server, which asks Stripe for the customer with that address and, if there is a Superposer Plus subscription, emails its key there through our email provider [Resend: confirm]. The answer is the same whether or not the address is a customer. The address is not stored: only a keyed hash of it, to limit requests to [3] a day | Get your key back | Contract; legitimate interest in preventing abuse | Hash deleted after [2] days; the email provider keeps its delivery log [x] days |
| Problem reports (opt-in, section 4a): only if you email us a report zip from "Report a Problem" (or, in beta builds, one made with Export Report): the redacted logs, crash reports, compatibility facts, game settings and versions you left checked, and your note, plus your email address and whatever you add to the email | Fix the problem you reported | Consent (you choose each item and send the email yourself); legitimate interest in fixing bugs | Until the problem is fixed and [12] months after; ask us to delete it |
| Shared compatibility results (opt-in, section 4b): only while "Share my results to help others" is on, each verdict you save: the Steam app ID and game title, your verdict, runtime version, graphics backend, macOS version (major.minor), chip class (e.g. "M4 Max"), Superposer version, your notes after redaction and moderation, and a random install ID. Our results server ([compat.superposer.app], hosted on Cloudflare) keeps the latest result per install and game. No IP address, account, name, email, Steam ID, serial number or Mac model is stored; to limit abuse, a keyed hash of your IP address is kept for [2] days | Show every player how games run, by game | Consent (off until you turn it on; turn it off any time) | Results stop counting after [365] days and are then deleted; the published list holds only per-game counts, the newest runtime, backend, dates and up to three short notes, never install IDs |
Testers' list download (on by default in builds with a results server; Settings › Privacy › Show testers' results): a plain download of the signed list (compat-shared.json and its signature) once a week. Superposer adds no identifier; the host sees your IP address and the request as any web host does | Show testers' results in the app | Legitimate interest | [Logs deleted after x days] |
| Support messages to [email protected]: your email and what you send | Help you | Legitimate interest; contract | [24] months after the last message |
| Website [no analytics / cookieless analytics: decide] | Keep the site working | Legitimate interest [or consent for non-essential cookies] | [x] days |
Update checks: the app downloads the update feed (superposer.app/appcast.xml), the runtime list (runtimes.json and its signature) and, when there is an update, the signed app or runtime archive. These are plain downloads: Superposer adds no licence key, activation ID or other identifier, and Sparkle's optional system profile is off. The host sees your IP address and the request's user agent (for the app feed, Sparkle's, which names the app and its version). Automatic checks are on in release and beta builds (the runtime check runs shortly after launch, then daily) and can be turned off in Settings › Updates | Deliver updates | Contract; legitimate interest | [Logs deleted after x days] |
Our payment provider, Stripe (via Stripe Managed Payments; purchases show as "sold through Link"), is the seller and processes your card, billing details and tax. It is an independent controller for that data under its own privacy policy: https://stripe.com/privacy and https://link.com/privacy. [Confirm the exact selling entity and links from Stripe's Managed Payments terms.]
4. Compatibility reports (opt-in, public)
"Share report…" prepares a GitHub issue in your browser. It is filled in with: game name and Steam app ID; your verdict, areas and notes; and technical facts: Superposer, runtime, graphics backend, macOS, Mac model, chip, memory, display, Rosetta, D3DMetal version, changed settings, DRM/anti-cheat, and a launch error if any.
- Redacted: home folder paths, your user name and Steam IDs are removed before anything is shown. We never read your name, serial number or host name for it.
- You see it first and decide whether to submit. Nothing is sent until you submit it on GitHub.
- It becomes public on GitHub under your GitHub account and GitHub's terms, so don't put personal details in your notes. We use reports to improve compatibility, and may republish them in aggregate.
- To remove one, delete or edit your issue on GitHub, or write to us.
4a. Problem reports (opt-in)
After a game fails to launch, closes right away or crashes, or an automated test fails, Superposer offers "Send a report?" on the game's page. "Report a Problem…" is also on the game's page, its Logs tab and in the Help menu (about Superposer itself when no game is open).
- What it can contain: that launch's log lines, the Wine, compositor and capture logs of that launch, macOS crash reports of the game, Wine, Steam helpers or Superposer, the automated test result, the compatibility facts listed in section 4, your settings for that game and its profile, versions (macOS, Mac model, Superposer, runtime revision, graphics backends) and setup check results, plus a note if you write one.
- Redacted first: your home folder, user name, other users' folder names, Steam IDs and account folders, your Steam account and persona names, your computer's names, email addresses and crash reporter identifiers are removed before you see the preview.
- You see exactly what is sent, item by item, and can turn any item off. Nothing is packaged until you press Email Report…, Copy or Save Zip Only, and the zip holds only the items you left on and your note.
- Superposer never sends a report itself. There is no report server, and no report text is put into a web link. The zip is saved in Superposer's reports folder on your Mac (
~/Library/Application Support/Superposer/reports). Email Report… opens a new, unsent email in your mail app with the zip attached and the report's summary as its text; you address it (unless the build's feedback address is an email address), can read and change it, and it goes nowhere unless you press Send in your mail app. Copy puts the zip and summary on your clipboard for you to paste where you like. Save Zip Only shows the zip in Finder. We receive a report only if you send it to us. [If a report server replaces this, describe it, its host and retention here before release (ADR 0021).] - Beta builds also have Export Report, which saves a redacted zip for Superposer as a whole (setup check, versions, the compatibility log and recent crash reports of Superposer, Wine and Steam) in the same folder and shows it in Finder, and Send Feedback, which opens the build's feedback page in your browser: a GitHub issue form (public, under your GitHub account, as in section 4) or a new email. Nothing is attached or filled in for you.
4b. Shared compatibility results (opt-in)
In builds that have a results server, How did it run for you? (a game's Test & Reports tab) and Settings › Privacy have Share my results to help others. It is off by default.
- What is sent, only while it is on and only when you press Save Report: the game's Steam app ID and title, your verdict, the runtime version and graphics backend, the macOS version (like 26.0), the chip class (like M4 Max), the Superposer version, your notes, and a random ID created for this Mac when you turned sharing on. The toggle shows every field for the report you are writing before anything is sent.
- Redacted first: your home folder, user name, Steam IDs, links, email addresses and runs of seven or more digits are removed from your notes, which are cut to 280 characters. The server removes links, addresses and long numbers again and masks profanity. Games from other stores are never shared.
- No account: the random ID is not derived from you or your Mac. Turning sharing off deletes it on your Mac; turning it on again creates a new one. Results already sent stay counted until they expire; write to us to have the results of an ID removed (Settings › Privacy shows it while sharing is on).
- What others see: the server merges everyone's latest result per game into one list, signed by Superposer: per game the status, how many said what, a confidence level, the newest runtime and backend, dates and up to three short notes. It never contains install IDs.
- The list download (Show testers' results, on by default in those builds) fetches that list once a week and sends nothing about you. Turning it off deletes the downloaded list.
- Builds without a results server show none of this and contact no such server.
5. Sharing and transfers
We share personal data only with providers that help us run the service, under contracts that limit their use of it, and when the law requires:
| Provider | Role | Data |
|---|---|---|
| Stripe, Inc. (and Stripe's Link) | Seller of record and payments (independent controller); our processor for the subscription records we see | Purchase and billing data (section 3) |
| Cloudflare, Inc. | Hosts the licence server, the results server and their databases, and the website | Licence data and shared results (sections 3, 4b); IP addresses in transit |
| [Email provider for [email protected]] | Support mail | Your messages |
[Re-check this table against what is actually deployed.] If data leaves the EU/UK, we rely on [adequacy decisions / standard contractual clauses / the UK addendum]. We don't sell personal data or share it for cross-context advertising.
6. Your rights
EU/UK (GDPR): access, correction, deletion, restriction, objection, portability, withdrawing consent at any time, and complaining to your data protection authority (UK: ICO). California and other US states (CCPA/CPRA and similar): know, access, delete, correct, and opt out of sale or sharing. We don't sell or share, and won't discriminate against you for using your rights. We don't use automated decisions with legal effect.
To use these rights write to [email protected]. We reply within one month (45 days under CCPA). Authorised agents can act for you with proof of authority.
7. Security
Billing data is stored with Stripe and licence data with Cloudflare (D1, encrypted at rest); access is limited to us and encrypted in transit. Licence keys are long random values, not derived from you or your Mac. No system is perfectly secure; we'll tell you and regulators about a breach as the law requires.
8. Children
Superposer isn't directed to children under [13, or 16 in the EU] and we don't knowingly collect their data. If you think a child gave us data, write to us.
9. Changes
We'll post changes here and tell you in the app or by email before material changes apply. Past versions are available on request.
10. Contact
[email protected] · [Company legal name], [Address]