Privacy
Privacy & installation
Last updated October 11, 2026
Short version: your startup setup never leaves your Mac. There’s no account, no analytics, and no tracking. The only things that talk to a server are the license check and the update check, and both are below in full.
On your Mac
LoginToggle saves the login items and launch agent labels it turns off in ~/.local/state/login-toggle, so it can restore them. Your license key and signed license token live in the same folder, readable only by your user account.
License check
When you activate, LoginToggle sends your license key and a SHA-256 hash of your Mac’s hardware UUID to the LoginToggle license service. The raw UUID is never sent. While it runs, the app renews its license about twice a day with the signed token and the same hash. The service confirms your purchase with Whop and stores the hash next to your order in Cloudflare Workers KV, so one key stays on one Mac. Between checks, the license is verified offline.
Updates
With automatic checks on, the app fetches a small version file about once a day. It never downloads or installs anything until you choose Update now. Update requests carry no identifier. Turn automatic checks off under ··· in the menu.
Purchase and email
Checkout runs on Whop. Whop handles payment and your customer account under its own privacy policy; LoginToggle never sees your card. After purchase, the license service reads your order from Whop to show your key and send you one welcome email with it. To make lost-key emails possible, it stores a one-way hash of your email address, not the address itself. You won’t get marketing email.
Website
This site is served by Cloudflare, which processes connection details such as your IP address to deliver and protect it. The site uses no cookies and no analytics.
What the installer does
The Terminal command downloads install.sh, which:
- downloads the release manifest and app over HTTPS from this site,
- checks the download against the manifest’s SHA-256 checksum,
- checks that the app’s code signature is intact and its bundle ID and version match,
- removes the macOS quarantine flag from that verified copy only, and
- moves it into
~/Applicationsand opens it.
It doesn’t need your password and doesn’t change any Gatekeeper setting. To be clear about the trade-off: LoginToggle is ad-hoc signed, not signed with an Apple Developer ID or notarized. The signature proves the app wasn’t altered after it was built, but it doesn’t identify the developer to Apple. Read the script before you run it if you like; it’s short.
Questions
Email kartik@kartikkabadi.com. See also the license terms.