PungoExplore Pungo
Back to Pungo

Privacy, in plain words.

How Pungo handles your collection, license activation, screen capture, and support requests.

Updated 6 October 2026

Operator and contact

Pungo’s website is operated by Terrapixel — Wolfgang Wachelhofer. See the legal notice for contact and business details.

For privacy questions, email [email protected].

Your cursor collection stays on your Mac

Pungo stores imported packs, favorites, settings, and cursor recovery data locally. It does not upload your collection or include third-party analytics. You control your local collection through the app.

License activation

Pungo uses Polar to activate, validate, and deactivate paid licenses. Requests include your license key, activation identifier, and a Pungo-specific hash derived from your Mac’s device identifier. The raw device identifier and your cursor collection are not sent. As with other HTTPS connections, Polar receives connection information such as your IP address.

The license and activation receipt stay in macOS Keychain. Pungo and its background helper periodically check access with Polar. A successful validation provides up to seven days of offline use. Device activation records are used to enforce the two-Mac license limit. You can deactivate a Mac in Settings or through Polar’s customer portal.

See Polar’s privacy policy for its data handling and retention.

Presentation and your screen

The magnifier uses macOS Screen Recording permission for a live enlarged view. Captured frames stay in memory; Pungo does not save a video or record audio. Capture stops when you open Presentation settings, end the session, or the app receives sleep or user-session deactivation notifications.

Global shortcuts listen for specific tool combinations. Single-key shortcuts work while you give the toolbar keyboard control. Pungo does not record text typed in other apps.

Keep Awake and AI connections

Keep Awake uses local macOS power controls. It does not simulate mouse or keyboard input. Sessions and connected AI activity are not uploaded.

If you connect Codex, Cursor, or Claude Code, Pungo adds local hooks to that tool’s configuration and keeps a local backup of the existing configuration. Its hook handler receives event data, extracts the event type and hashes the session and turn identifiers. It does not store or forward prompt text, transcripts, file paths, code, or tool output. Disconnecting removes Pungo’s hook entries and preserves other hooks.

In-app updates

From version 0.5.0, checking for an installable update sends your license key, activation identifier, and Pungo-specific device identifier to Pungo’s update service over HTTPS. The service verifies activation with Polar and returns a short-lived download token. These credentials are not placed in download URLs. Signed updates are installed with your confirmation.

Optional cursor pack purchases

Buying, restoring, or downloading packs from Discover sends your license key, activation identifier, Pungo-specific device hash, and requested pack identifier to Pungo’s store service over HTTPS. The service validates your license with Polar, checks paid orders for the customer linked to that license, and creates checkout sessions or delivers packs you own. It does not upload your cursor collection or send these credentials in checkout URLs. Payment and order records remain with Polar; the store does not maintain a separate purchase database.

This website

The website saves appearance and sound preferences in your browser. Its demos use local browser data and do not change your Mac’s system cursors. Clear site data in your browser to remove saved preferences.

Cloudflare Web Analytics measures aggregate traffic and real-user performance. Cloudflare Turnstile protects the support form from automated abuse by processing the technical browser and network signals needed to distinguish people from bots; it does not receive your support-form entries. See Cloudflare’s privacy policy and Turnstile Privacy Addendum.

PostHog EU Cloud measures page views and the steps that matter to the Pungo release: starting checkout, starting a download, and successfully sending the support form. Pungo does not send form contents, email addresses, URL query strings, or user profiles to PostHog. Tracking runs without cookies or browser storage; PostHog creates a privacy-preserving identifier from technical connection data and strips the IP address before analytics transformations. Session replay, broad click autocapture, surveys, feature flags, and error recording are disabled. See PostHog’s privacy notice.

Your browser sends connection information, including an IP address and requested page, to the host serving the website.

Hosting provider: Contabo. Provider privacy information.

Hosting log retention: kept only as long as needed to operate and secure the website, then deleted. Longer retention occurs only where legally required.

Payments

Polar’s hosted checkout processes payment and billing information under Polar’s privacy policy. Pungo does not receive or store your full payment-card details.

Support

When you email us, we use your email address and message to answer your request. If the website’s support form is available, it sends the same information and any app versions you enter to our server for email delivery. The website has no support-message database or attachment upload.

For abuse prevention, the form uses temporary hashes of connection addresses in server memory. Per-connection counters expire after 15 minutes and are cleared on a later request or server restart; a separate counter limits hourly submissions. Messages are delivered to the support inbox.

Support email provider: SpaceMail.

Support message retention: kept while we handle your request and for up to 24 months afterwards, then deleted.

Please leave passwords, payment-card details, and full license keys out of support messages.

Your privacy requests

Contact us to request access, correction, or deletion of personal data we handle, or to ask about applicable privacy rights. Some transaction records may need to be retained under legal obligations. Requests about Polar’s own payment records can also be addressed to Polar.