Privacy

Privacy & installation

Last updated October 11, 2026

Short version: your startup setup never leaves your Mac. There’s no account, no analytics, and no tracking. The only things that talk to a server are the license check and the update check, and both are below in full.

On your Mac

LoginToggle saves the login items and launch agent labels it turns off in ~/.local/state/login-toggle, so it can restore them. Your license key and signed license token live in the same folder, readable only by your user account.

License check

When you activate, LoginToggle sends your license key and a SHA-256 hash of your Mac’s hardware UUID to the LoginToggle license service. The raw UUID is never sent. While it runs, the app renews its license about twice a day with the signed token and the same hash. The service confirms your purchase with Whop and stores the hash next to your order in Cloudflare Workers KV, so one key stays on one Mac. Between checks, the license is verified offline.

Updates

With automatic checks on, the app fetches a small version file about once a day. It never downloads or installs anything until you choose Update now. Update requests carry no identifier. Turn automatic checks off under ··· in the menu.

Purchase and email

Checkout runs on Whop. Whop handles payment and your customer account under its own privacy policy; LoginToggle never sees your card. After purchase, the license service reads your order from Whop to show your key and send you one welcome email with it. To make lost-key emails possible, it stores a one-way hash of your email address, not the address itself. You won’t get marketing email.

Website

This site is served by Cloudflare, which processes connection details such as your IP address to deliver and protect it. The site uses no cookies and no analytics.

What the installer does

The Terminal command downloads install.sh, which:

It doesn’t need your password and doesn’t change any Gatekeeper setting. To be clear about the trade-off: LoginToggle is ad-hoc signed, not signed with an Apple Developer ID or notarized. The signature proves the app wasn’t altered after it was built, but it doesn’t identify the developer to Apple. Read the script before you run it if you like; it’s short.

Questions

Email kartik@kartikkabadi.com. See also the license terms.