Privacy
Privacy Policy
Last updated: August 7, 2026
EQBase is built to know as little about you as possible. There is no account to create, and the app works fully offline.
Your audio never leaves your Mac
EQBase processes system audio locally, in real time. No audio content, recordings, or information about what you listen to is ever collected, stored, or transmitted.
What the app sends, and when
- License activation and validation. If you buy Pro, activating your license sends the license key and your Mac's name (for example "Alex's MacBook Pro") to Lemon Squeezy's license service. The name exists only to label the activation, so you can recognize each Mac when managing your devices; after that, the app periodically revalidates the key with an anonymous per-device identifier. The service replies with the license status and the name and email tied to the purchase, which the app shows in its License window and stores only on your Mac. No usage data is ever attached to any of this.
- Update checks. The app fetches a version feed from updates.eqbase.app (via the standard Sparkle updater) to see if a newer build exists. The request carries the app's version and, if diagnostics sharing is enabled in Settings, three coarse anonymous facts that help us decide what to support: your macOS version (like "15.2"), whether the Mac is Apple Silicon or Intel, and roughly how long ago EQBase was installed (a bucket like "first week", never a date). During first-run setup the app also sends a few one-time anonymous progress signals (setup started, the audio permission allowed, setup completed, or which step failed), each a bare event name with no identifiers, so we can see where setup goes wrong for people and fix it. Nothing identifies you, and turning diagnostics off in Settings removes even these. We count these requests in anonymous, aggregate form to estimate how many installs are active: each request is recorded with a hashed identifier that rotates every day, so counts exist per day but can never be linked across days or traced back to you. We never store your IP address, and there is no profiling. (Like most of the internet, these requests travel over Cloudflare, our infrastructure provider, which processes connection data such as IP addresses transiently to deliver the response and block abuse.)
- Crash reports and reliability metrics. These are on by default and can be turned off at any time in Settings › Diagnostics. Reliability metrics (crash-free rate, audio-dropout counts) stay on your Mac and are only shared if you export a diagnostics bundle or report an issue. With automatic crash reports on, a crash produces a report containing a stack trace plus the app version, macOS version, and Mac model: no audio, no listening history, no license details. Usernames, home-folder paths, and email addresses are stripped on your Mac before the report leaves. Reports go to crash.eqbase.app, a relay we operate, which forwards them to Sentry, our crash-reporting processor (hosted in the United States). Turning the toggle off stops all collection and clears collected metrics.
Purchases
Payments are processed by Lemon Squeezy as the merchant of record. Your name, email, and billing details are handled by them under their privacy policy. EQBase receives your license status and the name and email tied to the license (to show who it's licensed to), never your payment details.
Permissions the app asks for
- System audio recording. This is the one permission setup asks for, and the only one most people will ever see. macOS lists it under Privacy & Security › Screen & System Audio Recording, and it is how EQBase receives the sound your apps play, so it can process it. Per-app volume and per-app EQ use the same permission, and so does Pro audio routing, which needs the one below as well. Everything is processed in real time, in memory, on your Mac: nothing is recorded, written to disk, or transmitted.
- Microphone. Not part of setup, and not asked for by default.
Three later situations do ask for it, each one starting from something you turned on:
- You pick a microphone or an instrument as an input in Audio Sources. This is the only case where EQBase reads a real microphone, because it is the one where you asked it to.
- You build a Pro routing device that carries audio. Every routing device has an input side, since that is what lets other apps record your mix, and macOS counts opening a device that has an input side as microphone access, virtual or not. EQBase asks from your own click in the Routing pane, never at launch, and a routing device with no sources and no monitors is left closed, so it never asks.
- The uncommon case where the system-audio path is unavailable and EQBase falls back to capturing through its own audio driver, which macOS also counts as an input device.
- Administrator approval. Only if you turn on Audiophile mode or Pro audio routing, which are the two features that use EQBase's virtual audio driver. Installing that driver is a one-time privileged step macOS asks you to approve, at the moment you turn the feature on and never during setup. No data is involved.
This website
eqbase.app is a static site. It sets no cookies and runs no trackers. Your light/dark theme choice is stored on your device (localStorage) and never sent anywhere. To count visits we use Cloudflare Web Analytics, a cookieless measurement tool that records page views without fingerprinting you, identifying you, or following you across sites. We also keep our own first-party count of page views and the place a visit arrived from (the referring site or a utm_source tag, e.g. a search engine or an AI assistant); it uses no cookies and the same anonymous scheme as everything else here. Downloads from dl.eqbase.app are counted the same anonymous way as update checks: a daily-rotating hashed identifier, no stored IP address, nothing linkable across days.
Legal bases & where data is processed
Where the GDPR, Türkiye's KVKK, or similar laws apply: we process license and purchase data because it's necessary to provide what you bought (performance of a contract); crash reports and the anonymous, aggregate counts described above under our legitimate interest in keeping EQBase reliable and secure, always minimized and redacted as described, with crash reporting switchable off at any time; and anything beyond that only with your consent. Crash reports are processed for us by Sentry in the United States under appropriate safeguards (the EU–US Data Privacy Framework and standard contractual clauses); our web services run on Cloudflare's global infrastructure.
Retention & your rights
We keep the little we collect only as long as it's useful: crash reports are retained by our crash-reporting processor for diagnosis and then expire (typically within 90 days); aggregate install and download counts contain nothing that identifies you, by construction. License and purchase records are kept by Lemon Squeezy for as long as your license is active and as required by tax and accounting law. If you email us, we keep the correspondence for as long as we need it to help you.
Depending on where you live (for example under the GDPR or Türkiye's KVKK) you may have rights to access, correct, or delete personal data, to object to or restrict processing, and to complain to your local data-protection authority. Write to us and we'll help, including passing requests to our processors where the data lives with them. EQBase is not directed at children, and we don't knowingly collect data about them.
Changes
If this policy changes materially, we'll note it here with a new date. We will never change it to start collecting audio or listening history. That isn't a policy choice, it's how the app is built.
Contact
EQBase is made and operated by Bold Biscuit, the data controller for the data described in this policy. Questions about privacy: [email protected].