Legal

Privacy Policy

Effective date: September 9, 2026

Overview

macIIS is a macOS web server manager. Most operational data stays on the Mac running macIIS. When enabled, online activation, update checks, and the optional website account portal contact macIIS services. Optional public certificate issuance contacts Let's Encrypt.

Data stored locally on your Mac

Local operational data can include site and binding configuration, app-pool commands and environment variables, request and error logs, traffic metrics, configuration backups, certificates and private keys, app-pool history, and local diagnostic reports. This data remains under the server operator's control unless they choose to export or share it.

macIIS does not include a general cloud configuration store and does not upload hosted website content or local request logs to the macIIS account portal.

License activation

When online licensing is offered and the app activates or verifies a license, the activation service receives the license key, a Mac hardware identifier, app version, expected daemon version, request time, and basic network metadata such as the source IP address and request ID. The service stores license status, expiration, activation limit, current machine bindings, activation events, and administrator audit events.

This information is used to issue signed activation tokens, enforce activation limits, diagnose failed activation, support license resets, and prevent abuse. Activation denial messages shown to clients are intentionally generic; detailed reasons stay in server-side logs.

Website accounts

If the account portal is offered and you create or receive a macIIS website account, the service stores your email address, a salted password hash (never the plaintext password), role, account status, linked license ownership, sign-in time, and revocable session records. Session security records can include IP address and browser user-agent information.

Customers can view their linked licenses and activated Macs, link an eligible unclaimed key, change their password, and clear their own machine activations. Administrators can manage customer accounts and license ownership. These permissions are checked on the server; browser storage is not treated as proof of identity or authority.

Updates

When you ask macIIS to check for updates, it requests the update manifest from this website. The web server can log standard request information such as time, IP address, requested path, and user agent. A closed manifest contains no downloadable package. When distribution opens, the app will verify the downloaded package hash and Apple signature before opening the installer.

Let's Encrypt and ACME certificates

If you explicitly request a public TLS certificate, macIIS sends the requested hostname and, when provided, a contact email address to Let's Encrypt. Their handling of that data is covered by the Let's Encrypt privacy policy. Local CA use does not require a Let's Encrypt request.

Telemetry, sale, and sharing

macIIS does not include product-usage analytics or advertising tracking. Account and activation information is not sold. It is shared only with infrastructure providers as needed to operate the website and licensing service, when required by law, or when you explicitly direct us to disclose it.

Retention and security

Account and license records are kept while needed to provide licensing, customer support, security, and audit history. Expired or revoked browser sessions can be deleted as operational maintenance. Server operators are responsible for protecting local macIIS configuration, hosted content, logs, backups, and private keys.

The website uses encrypted HTTPS transport in production, salted password hashing, opaque server-side sessions, secure cookies, CSRF protection, role checks, rate limits, and administrator audit records. No system can guarantee absolute security.

Your choices

You may choose not to create a website account. A future online-licensed edition may require the licensing service for activation; the current private beta does not offer a public account or activation service. Contact us to ask about access, correction, or deletion of account information. Some license and audit records may be retained where reasonably necessary for security, fraud prevention, legal obligations, or transaction records.

Children's privacy

macIIS is a developer and server-administration tool intended for adults. It is not directed to children under 13.

Changes and contact

Material changes will be published here with a new effective date. Questions or privacy requests can be sent to allen.fluck@icloud.com.