Privacy Policy
Last updated 19 September 2026.
Extra Cup is a free Mac app made by one person, Andrei Kozyakov, who is responsible for this page. It puts in one place what the app and this website send, who receives it, and how long it is kept.
The app
The app counts nothing. It has no account, no analytics and no crash reporting. It makes two kinds of request, and neither happens without your say-so; the only thing about your Mac either one carries is the macOS version in the feedback link below.
Check for Updates…
Extra Cup checks for updates with Sparkle. The second time it is opened, it asks whether to check automatically: say yes and it checks about once a day, say no and it checks only when you choose Check for Updates in its settings menu. A check asks https://updates.extracup.app/appcast.xml for the list of releases, and installing an update downloads it from the same host. Those requests carry what any web request carries: your IP address, and a user-agent naming the app, its version and Sparkle's. Sparkle's system profile, which would describe your Mac, is switched off, so nothing else goes with them. The update host is served by Cloudflare, and this website's counting does not run on it.
Send Feedback
Send Feedback in the settings menu opens the feedback form in your browser, with the app's version and your macOS version in the link so the form can fill them in. Opening it hands those versions to this website, served by Cloudflare, and your browser keeps the link in its history like any other. The website uses them only to fill in the form, where you can see them, change or clear them; it does not count the form as a page read, and nothing is sent to be kept until you press Send.
This website
Only to count visits. The app counts nothing, but this website counts how many people arrive, and how many press Download. The counting is done by PostHog on its European servers in Frankfurt. Each request sends the page asked for and the kind of request it was, the page you came from, your browser's user-agent string, whether the page was served or something went wrong, the reference number Cloudflare gives every request, and your IP address, which is turned into a country and then discarded without being stored. The country stays. PostHog is told not to build a profile of you from any of it. If the link you followed carried anything after a question mark, only the campaign tags are kept and the rest is dropped before the address is sent. Counts are kept for a year.
Nothing is stored on your device. This page runs no JavaScript, so there is no cookie, no local storage and no consent banner, because nothing is being kept for you to agree to. The counting happens on the server that hands you the page.
There is one thing that follows you between pages, and this is it: each request is given a visit number, so that somebody reading two pages is counted as one person rather than two. It is your address and your user-agent string hashed together with a secret this site keeps, so it stays the same while those do, and it links your visits to each other and to nothing else. Your address itself is never stored, there is no account and no cookie, and the number cannot be turned back into you - but it could be worked out again from the same address and the same browser, so if you asked us to find or delete what we hold, that is what there would be. It goes when the counts do, after a year.
The feedback form
It is kept apart from the counting. A message you send goes to the same PostHog project in Frankfurt as a survey response: the message, the kind you picked, your email address if you gave one, and the app and macOS versions in the form. It carries no visit number, no IP address and no location, and each message is given a new random number of its own, so it is not linked to your page reads or to any other message, and no profile is built from it. Opening the form is not counted as a page read either, so there is no read beside it to line it up with. Your IP address is used for one thing, a limit on how many messages one address can send in a minute, and is not stored. Messages are kept for a year. To have one deleted, send another message saying which one.
Who receives it
PostHog, on PostHog Cloud EU in Frankfurt, receives the visit counts and the feedback messages described above, and keeps them for a year. PostHog's privacy policy
Cloudflare serves this website, the feedback form and the update host. It receives every request, your IP address included, in order to deliver it, and it applies the limit on how many feedback messages one address can send in a minute. What Cloudflare keeps of its own is set out in its own policy. Cloudflare's privacy policy
Email you send to the contact address is received and kept by Google, through Gmail, for as long as it takes to answer you. Google's privacy policy
Nobody else receives what this page describes. None of it is sold or shared for advertising, and it is used only in the ways this page sets out: to deliver the website and updates, to fill in, limit and receive the feedback form, to count visits, to read feedback and use it to answer you and to improve Extra Cup, and to answer mail and requests like the ones below.
Why it is allowed
Delivering the website and updates, limiting the feedback form, and counting visits rest on a legitimate interest: running a free app and its website, keeping the form from being flooded, and knowing whether anybody reads the page, in ways that keep as little as this page describes. A feedback message, and an email, rest on your consent: you choose to send it, and it is used to read it and answer you. You can take back your consent at any time by writing to the address below, and the message is then deleted. Taking it back does not make what was done with the message before then unlawful.
Your right to object
You can object to the counting at any time by writing to the address below.
Asking about your data
To ask what is held about you, or to have it corrected or deleted, email the address below. To have a feedback message deleted, say roughly when you sent it and what it said, or send another message through the form saying which one. Visit counts carry no name and no stored address, so the only way to find yours is the visit number described above, worked out again from the IP address and browser you visited with. An email carries neither, so put both in it: the IP address, and your browser's user-agent, the line of text that names the browser and its version. Reads made from another address or another browser version carry a different number, and are found only if you give that address and version too.
You can also ask for the use of your data to be restricted while a request is dealt with, object to how it is used, or ask for a copy in a form a computer can read. If you think your data has been handled wrongly, you can complain to the data protection authority where you live or work, or where you think the rules were broken.
Contact: andrushkin3@gmail.com
If this page changes, the date at the top changes with it.