Privacy Policy
Sections
- Information we do not collect
- Information we collect
- Connections the app makes
- How we use information
- Optional analytics and crash reports
- Third-party services we use
- Retention
- Your rights and choices
- Children’s privacy
- Security
- Location of processing
- Notice to individuals in the EU and UK
- Notice to California residents
- The companion apps
- Changes to this policy
- Contact
Ethoseen LLC (“Ethoseen,” “we,” “us”), an Oregon limited liability company, publishes Sightline. This policy describes what personal information we collect, how we use it, and who we share it with. It applies to the Sightline desktop application, the iOS and watchOS companion apps, and the sightlinebehavior.com website. It is part of the Terms of Service.
1. Information we do not collect
Sightline stores your observation data on your device. This includes students, sessions, observations, notes, audio recordings, exports, and generated reports (together, “Your Content”).
We do not collect, receive, store, or have access to Your Content. We operate no cloud storage of Your Content, no synchronization service, and no database of student records. Using Sightline transmits none of it to us, and we cannot view, recover, export, or delete it.
All AI features run on your device. Text you enter and audio you record are processed locally and are not transmitted to us or to any third-party AI service.
Because Your Content never reaches us, we do not receive, collect, or maintain education records or personally identifiable information from education records.
2. Information we collect
We collect the following categories of personal information:
- Billing information, if you purchase a subscription: your email address, and transaction records. Card details go to our payment processor and are not received by us.
- License records: license key, subscription tier, billing email address, a machine fingerprint, and activation history.
- A hashed device identifier, if you start a free trial. It is a salted, one-way hash of a hardware identifier. It identifies a device and cannot be reversed into your identity or any of Your Content.
- Correspondence, if you contact support or submit feedback: the text you send, and your email address if you provide one.
- An installation identifier, if you enable analytics. It is a random value generated on first run and stored on your device. It is not derived from your hardware and is not the trial identifier described above.
- Optional analytics and crash reports, only if you enable them. These carry your app version and subscription tier along with the events described in Section 5.
- Your email address and signup source, if you join the pre-launch notification list on the website. We store the address, which page you submitted it from, and the date you submitted it. We use it only to tell you when Sightline is available to download, and every message carries an unsubscribe link.
Apart from that notification list, we do not collect information from you through the website beyond what your browser sends with any request. The website sets no advertising or analytics cookies. The notification form uses Cloudflare Turnstile to block automated signups; the check reads your IP address and browser signals, and we do not retain them.
3. Connections the app makes
The application is not fully offline. It connects to the network for licensing, software updates, model downloads, feedback you submit, and the two optional reports described in Section 5. The table below describes each of those connections.
| Connection | Who receives it | What it sends | When |
|---|---|---|---|
| License validation | Keygen | License key, machine fingerprint | Activation and periodic revalidation |
| Trial issuance | Ethoseen | Hashed device identifier, app version | When you start a free trial |
| License heartbeat | Ethoseen | License key, machine fingerprint, app version, first-activation date | Each launch of a licensed copy |
| Update check | Ethoseen | App version, platform, subscription tier; a license key, or an updater token and machine fingerprint | Periodically |
| Model download | Hugging Face, Ethoseen | A file request; for licensed models, your license key | When you download or update a model, at your direction |
| Feedback | Ethoseen | The text you enter, and your email address if provided | When you submit the feedback form |
| Usage analytics | PostHog | Allowlisted screen and feature events | Only if you enable analytics |
| Crash reports | Sentry (US region) | Stack traces, allowlisted error-class names | Only if you enable crash reporting |
None of these connections transmits Your Content. Feedback is the only one that transmits text you author, and it sends only what you enter in the form, when you submit it.
The base model download is a file request to Hugging Face, a third party whose servers receive your IP address as any web server would.
The specific hostnames these connections use, for firewall allowlisting, are listed at sightlinebehavior.com/security.
4. How we use information
We use the information in Section 2 for the following purposes:
- To validate licenses, enforce activation limits, and issue and limit free trials.
- To process payments, provide receipts, and administer subscriptions.
- To deliver software updates and licensed model files.
- To update aggregate installation and update-activity counters. We do not retain device identifiers or per-device activity histories for analytics.
- To respond to support requests and feedback.
- To diagnose crashes and understand feature usage, where you have enabled those reports.
- To comply with tax, accounting, and other legal obligations.
We do not use this information for advertising, profiling, or automated decision-making, and we do not use it to train machine-learning models.
5. Optional analytics and crash reports
Usage analytics (PostHog) and crash reporting (Sentry) are disabled by default. The application asks once during first-run setup, and you can change either setting at any time in Settings. The application’s features do not depend on either setting.
When analytics are enabled, the application records which screens and features are used. Events are filtered through a fixed allowlist of properties that excludes names, notes, and observation content, and a second filter rejects values that look like credentials.
Those events are associated with the installation identifier described in Section 2, and carry your app version and your subscription tier (free, starter, or pro). They do not carry your name, email address, or license key.
When crash reporting is enabled, a crash or error sends a stack trace and an allowlisted error-class name. Breadcrumbs, session replay, and request bodies are disabled in the SDK configuration.
Do Not Track. The website performs no cross-site tracking and sets no advertising or analytics cookies, so a Do Not Track signal has no corresponding behavior to disable. We do not alter our practices in response to Do Not Track headers.
6. Third-party services we use
We share the information in Section 2 with the following service providers, each for the purpose stated and under contractual terms requiring them to protect it and to use it only to provide that service:
| Provider | Purpose | What it receives |
|---|---|---|
| Stripe | Payment processing | Card details, billing email, transaction records |
| Keygen | License management | License key, tier, billing email, machine fingerprint, activation history |
| PostHog | Usage analytics, if enabled | Allowlisted product events, installation identifier, app version, subscription tier |
| Sentry | Crash reporting, if enabled | Stack traces, error-class names |
| Hugging Face | Base model distribution | A file request, including your IP address |
| Cloudflare | Website and service hosting, notification-list storage, signup bot check | Request metadata, including IP address; notification-list addresses and signup source |
| Resend | Email delivery for the notification list | Your email address |
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We have not done either in the preceding twelve months.
We may disclose information if required by law, and to a successor entity in connection with a merger, acquisition, or sale of assets.
7. Retention
We retain license and billing records for as long as your license exists, and afterward only as long as tax, accounting, and fraud-prevention obligations require.
We retain the hashed device identifier described in Section 2 indefinitely. Its purpose is to prevent repeated trials on the same machine, which requires that the record persist.
We retain support correspondence for as long as needed to resolve the matter and to maintain a record of support history.
We retain notification-list addresses until you unsubscribe or ask us to remove yours, or until we retire the list, whichever comes first. Removing an address deletes it from both our own store and our email provider.
Analytics and crash-report data are retained according to the default retention periods of PostHog and Sentry.
8. Your rights and choices
- Analytics and crash reporting can be enabled or disabled at any time in Settings.
- Devices can be deactivated from within the application to release a license activation.
- Access, correction, and deletion: email support@sightlinebehavior.com to request a copy of the license and billing records we hold, to correct them, or to delete them. We will confirm when the request is complete. We may retain what tax, accounting, and fraud-prevention obligations require.
- The notification list: every message we send includes an unsubscribe link, and you can email us at any time to have your address removed.
- Your Content is not subject to these requests, because we do not hold it. It is stored on your device and you delete it there.
We do not charge for these requests and do not deny service or provide a different level of service to anyone who makes one. We honor requests from all users, regardless of which privacy law applies to them.
9. Children’s privacy
Sightline is a professional tool licensed to adults for use in their professional capacity. It is not directed to children, and we do not knowingly collect personal information from anyone under 13.
Observation records concern students, including children. Those records remain on your device and are not transmitted to us, so we hold no information from or about any child.
10. Security
Your Content is protected by the security of your device: your operating system account, and any full-disk encryption you enable. We recommend enabling FileVault on macOS or BitLocker on Windows. On the companion app, observation data is encrypted at rest while the device is powered off or before its first unlock after restart.
For the information we hold, we use established service providers, restrict internal access to what operating the business requires, and use encrypted transport for the connections listed in Section 3. If a breach affects your personal information, we will notify you as required by applicable law.
11. Location of processing
We are located in the United States and the services listed in Section 6 process information in the United States. If you use Sightline from outside the United States, the information described in Section 2 is transferred to and processed in the United States.
12. Notice to individuals in the EU and UK
This section applies if you are in the European Union or the United Kingdom. It adds to the rights and disclosures elsewhere in this policy; it does not replace them.
Controller. Ethoseen LLC is the data controller for the personal information described in Section 2. You can reach us at the address in Section 16.
Legal bases for processing. We process your personal information on the following bases:
- Performance of a contract: validating licenses, enforcing activation limits, delivering software updates, checking model entitlements, processing payments, administering subscriptions, and responding to support requests.
- Legitimate interests: maintaining the hashed device identifier described in Section 2 to prevent repeated free trials on the same machine, and keeping our services secure. You can object to processing based on legitimate interests, as described below.
- Consent: usage analytics and crash reports, and the email address you choose to attach to feedback. You can withdraw consent at any time using the Settings toggles described in Section 5, or by asking us to remove an email address you provided.
International transfers. We are located in the United States and process your personal information there, as described in Section 11. Our service providers each maintain their own approved safeguards for transfers out of the EU and UK, such as Standard Contractual Clauses or Data Privacy Framework certification.
Your rights. In addition to the choices in Section 8, you have the right to access the personal information we hold about you, to correct it, to have it erased, to receive it in a portable form, to restrict our processing of it, to object to processing based on our legitimate interests, and to withdraw consent at any time. To exercise any of these rights, email support@sightlinebehavior.com using the mechanism described in Section 8; we will respond within one month. Withdrawing consent or objecting does not affect processing we carried out before you did so. For the hashed device identifier, Section 7 explains why we generally retain it even after an objection.
Automated decisions. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Complaints. If you believe we have handled your personal information unlawfully, you can lodge a complaint with your local data protection authority. We would appreciate the chance to address your concern first.
Representative. We have not appointed a representative in the EU or UK. Our processing of EU and UK personal information is occasional and low risk at our current scale, which is exempt from the representative requirement. We treat UK personal information the same way.
13. Notice to California residents
The categories of personal information we collect are listed in Section 2, the purposes for which we use them in Section 4, and the categories of third parties who receive them in Section 6. Retention is described in Section 7 and your rights in Section 8.
We do not sell personal information and do not share it for cross-context behavioral advertising.
Under California Civil Code section 1789.3, California residents may contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.
14. The companion apps
The iPhone and Apple Watch companion applications have no accounts, no backend, and no analytics. Observation data recorded on the phone is stored there until it transfers to your desktop over the paired Bluetooth link, and the phone deletes its copy after the desktop confirms receipt. During an untethered observation, that data may remain on the phone for an extended period.
A supplement to this policy covering App Store and TestFlight specifics is at sightlinebehavior.com/privacy/companion.
15. Changes to this policy
We may update this policy. Changes that materially affect how personal information is handled are treated as material changes to the Terms of Service: we give at least 30 days’ notice, and the updated policy is presented in the application and accepted there before continued use. The version number and effective date appear at the top of this document.
16. Contact
Ethoseen LLC 1538 E 25th Avenue Eugene, OR 97403 United States