Privacy Policy
Your AI assistant, your machine, your control
Our Privacy Commitment
MoltenRock is built on a fundamental principle: your data belongs to you. We collect no telemetry and no analytics. MoltenView runs entirely on your Mac. MoltenMail connects only to your own email provider (IMAP) using credentials you enter, stored in the macOS Keychain - we never receive your mail or your password.
One deliberate exception is buying an optional paid license, such as MoltenMail Pro, MoltenRock Pro, or MoltenRock Connect Pro. Selling and delivering a license unavoidably involves a payment processor and an email, so we process a small, clearly defined set of data for that purpose alone. Exactly what we process, why, where it is stored, and for how long is set out under “Pro Licensing & Payments” below.
The others are entirely optional and happen on this website or humanqueue.com, never in the apps: signing up to hear when the Human Queue is ready, signing in to Human Queue Training, taking its certification exam, writing to us through humanqueue.com’s contact form, signing up for MoltenRock release notes, or sending us feedback. See “Human Queue updates”, “Human Queue Training accounts”, “Certification exam and certificate”, “Organisations”, “Contact form” and “Release notes and feedback” below. When you click a Download button we count the click, but nothing that identifies you; see “Download counts”.
What We Do Not Collect
In normal app use, no personal data is collected or transmitted to us, so no legal basis under GDPR art. 6 (or the Swiss FADP) is engaged. A legal basis applies only to a direct MoltenMail Pro or MoltenRock Pro purchase, described under “Pro Licensing & Payments” below, and to the optional website sign-ups, accounts, certification exam and feedback form described under “Human Queue updates”, “Human Queue Training accounts”, “Certification exam and certificate” and “Release notes and feedback”. Within the applications themselves:
- •No Personal Information: In normal app use we collect no names, email addresses, or personally identifiable information. The one exception is a direct MoltenMail Pro or MoltenRock Pro purchase - described under “Pro Licensing & Payments” below.
- •No Usage Analytics: We do not track how you use our applications, what features you access, or how often you use them.
- •No AI Interactions: We never receive your agent conversations. In MoltenView everything stays on your Mac; in MoltenMail, agents read your mail through a local, user-controlled socket - the content comes from your own mail server, never through us.
- •No Crash Reports: We do not collect crash reports or error logs automatically.
- •No Third-Party Services: We do not integrate any third-party analytics, advertising, or tracking services.
How Our Apps Work
MoltenRock applications are designed to keep your data yours. MoltenView works entirely on your local machine; MoltenMail connects only to your own email provider:
- •All processing happens on your Mac, using your local resources.
- •MoltenView needs no internet connection for core functionality; MoltenMail connects to your own email provider (IMAP).
- •Nothing is sent to us. MoltenMail talks only to your own email provider; MoltenView sends nothing anywhere.
- •We cannot access, view, or monitor your usage in any way.
Data Storage
Any data created or used by MoltenRock applications is stored locally on your Mac in standard application directories. You have complete control over this data and can delete it at any time by removing the application or clearing its data through macOS system settings.
Pro Licensing & Payments
MoltenMail, MoltenRock, and MoltenRock Connect offer optional paid upgrades — MoltenMail Pro, MoltenRock Pro, and MoltenRock Connect Pro (a MoltenRock Pro purchase also includes a complimentary MoltenMail Pro license, delivered as a separate key in the same email). Selling, delivering, and validating a license is the one part of MoltenRock that processes personal data on servers rather than only on your Mac. MoltenRock Connect Pro is processed identically to the other Pro purchases — the same Stripe payment, the same Cloudflare license database in the EU, the same Resend key email, the key stored only as a one-way hash, a per-device id, a five-device cap, and 24-month retention after the licence ends, with the same access, correction, and deletion rights described below. Your IMAP password, the contents of your mailbox, and the secrets stored in your MoltenRock vault are never part of this — they stay on your machine and are never sent to our licensing service or to any subprocessor.
- •Who is responsible: The data controller for Pro licensing is Goldcote Ltd (Switzerland).
- •What we process, and why: To fulfil your purchase and to deliver and validate your license — the legal basis being performance of our contract with you — we process your email address, a payment confirmation from our payment processor, your license key (stored only as a one-way hash, never in readable form), a random per-device identifier, and — for subscription plans — the subscription’s status and renewal/expiry date from our payment processor. Only if you tick the optional box at checkout do we also keep your email address to send occasional product tips and add-on offers; the legal basis for that is your consent, which you can withdraw at any time.
- •The services we rely on (subprocessors): Stripe (payment processing), Cloudflare (the licensing service and its database), and Resend (delivering your license-key email and any marketing you opt into). Each acts under a Data Processing Agreement, and any transfer of data outside Switzerland or the EU is covered by Standard Contractual Clauses or an equivalent adequacy safeguard.
- •Where it is stored: License records are held in a Cloudflare D1 database hosted in the European Union.
- •How long we keep it: We retain your license record for as long as the license is active and for 24 months after it ends, after which it is purged. If you opted in to marketing email, we keep your email address until you unsubscribe, at which point it is added to a suppression list so we do not contact you again.
- •Your rights: You can ask us to access, correct, delete, or export your data. Email support email and we will respond within 30 days. You can unsubscribe from marketing email at any time using the link in any such message.
- •If there is ever a data breach: Under the Swiss Federal Act on Data Protection (art. 24) we will notify the Federal Data Protection and Information Commissioner and any affected users as soon as possible. For users in the EU or EEA, under the GDPR (art. 33) we will notify the competent supervisory authority within 72 hours. Data-breach notifications can also be sent to us directly at support email.
Human Queue updates (website sign-up)
The Human Queue is part of MoltenRock Connect. If you enter your email address in the “Notify me” form on our home page, or “Join the queue” on humanqueue.com, we keep it so we can tell you when the Human Queue is ready and, now that it is live (for Stripe, since 29 September 2026), when it adds a platform, plus the odd update about it. If you pass a Human Queue Training module on humanqueue.com and ask for your gatekeeper pass, we keep your address to email you the pass (a MoltenRock Pro offer code) and to tell you about the Human Queue. Both are optional and separate from our apps: nothing in MoltenRock, MoltenMail, MoltenView, or MoltenRock Connect sends us anything.
- •Who is responsible: The data controller is Goldcote Ltd (Switzerland).
- •What we process, and why: Your email address, to email you when the Human Queue is ready and with the occasional update about it, and, if you asked for a gatekeeper pass, to send you the pass. The pass email also mentions the training module and score you passed with; we don't keep those anywhere else. The legal basis is your consent, which you can withdraw at any time.
- •The services we rely on (subprocessors): Cloudflare (which runs this website, humanqueue.com and their sign-up forms) and Resend (which keeps the list and sends the emails). Each acts under a Data Processing Agreement, and any transfer of data outside Switzerland or the EU is covered by Standard Contractual Clauses or an equivalent adequacy safeguard.
- •How long we keep it: Until you unsubscribe or ask us to delete it. When you unsubscribe, your address is added to a suppression list so we do not email you again.
- •Your rights: Every email has an unsubscribe link. You can also ask us to access, correct, or delete your address by emailing support email, and we will respond within 30 days.
Human Queue Training accounts (humanqueue.com)
Human Queue Training on humanqueue.com is open to everyone without an account. If you choose to sign in, we email you a one-time sign-in link (there are no passwords) and keep a small account, so your training progress follows you from device to device. The names you type into “Make it yours” (your company, team and customers) stay in your browser: we never receive them.
- •Who is responsible: The data controller is Goldcote Ltd (Switzerland).
- •What we process, and why: Your email address, to send you sign-in links and to tell your account apart; when your account was created and last used; and your training progress (your best score in each module, and which modules you have cleared). The legal basis is providing the account you asked for (GDPR art. 6(1)(b)). To keep sign-in safe and stop abuse, sign-in links, sessions and network (IP) addresses are stored only in a one-way, keyed form that can’t be turned back into the original (our legitimate interest, art. 6(1)(f)). We don’t use your account for marketing: signing in doesn’t add you to any mailing list.
- •Cookies: One strictly necessary cookie keeps you signed in on humanqueue.com for up to 30 days. It is only set when you sign in, and it isn’t used for tracking or advertising.
- •The services we rely on (subprocessors): Cloudflare (which runs humanqueue.com and stores the accounts) and Resend (which sends the sign-in emails). Each acts under a Data Processing Agreement, and any transfer of data outside Switzerland or the EU is covered by Standard Contractual Clauses or an equivalent adequacy safeguard.
- •How long we keep it: Your account and progress, until you delete them. Sign-in links stop working after 15 minutes, and we delete them, with the address each was sent to, after a day. Sessions end after 30 days, or when you sign out.
- •Your rights: “Delete my account” on humanqueue.com/account deletes your address, progress and sessions at once, along with any certification exam attempts and certificate (see below). You can also ask us to access, correct, or delete your data by emailing support email, and we will respond within 30 days.
Certification exam and certificate (humanqueue.com)
The certification exam (Certified AI Agent Supervisor) and its certificate are optional, and use your humanqueue.com account. The names you type into “Make it yours” still stay in your browser: we never receive them.
- •Who is responsible: The data controller is Goldcote Ltd (Switzerland).
- •What we process, and why: For the exam: which scenarios you were given, your answers, which details you looked at, when you started and finished, and your result (score, harmful slips, and score per area), so we can mark it, let you carry on later, and apply the wait before a retake. For the certificate: the name you type to go on it, its number and the date it was issued, so we can issue it and show it on its check page. For the $29 payment: your card details go only to Stripe, never to us; Stripe tells us the payment went through, with its reference, which we keep with your certificate. We email you the certificate once; we don’t use any of this for marketing. The legal basis is providing the exam and certificate you asked for (GDPR art. 6(1)(b)).
- •The check page is public, by design: anyone with your certificate’s link can see your name, the certificate and its date, which is how an employer can confirm it’s real. It isn’t listed in search engines, and nothing appears there until the certificate is paid for and issued.
- •The services we rely on (subprocessors): Cloudflare (which runs humanqueue.com and stores the exam and certificate records), Stripe (payment processing), and Resend (which sends the certificate email). Each acts under a Data Processing Agreement, and any transfer of data outside Switzerland or the EU is covered by Standard Contractual Clauses or an equivalent adequacy safeguard.
- •How long we keep it: Your exam attempts and your certificate stay with your account until you delete it; the certificate doesn’t expire. When you delete your account, they are deleted too, and the certificate’s check page stops working. Records of the payment itself are kept for as long as accounting law requires (in Switzerland, 10 years).
- •Your rights: “Delete my account” on humanqueue.com/account deletes your exam attempts and certificate with the rest of your account. To correct the name on an issued certificate, or to access or delete your data, email support email, and we will respond within 30 days.
Organisations on humanqueue.com (employers, RAV offices)
An organisation, such as your employer or a regional employment office, can give its people Human Queue Training and the certification exam, and pay for their certificates. You only become part of one by opening its join link and choosing to join, and the join page shows exactly what it will see before you do.
- •Who is responsible: The data controller is Goldcote Ltd (Switzerland). The organisation decides what it does with what its admins see.
- •What the organisation’s admins see: unless it sees totals only (below), your email address, when you joined, how many training modules you have cleared, whether you have started the exam, passed it or not passed yet (and the date you passed), and your certificate once it is issued. They never see your answers, your scores, or the names you use in “Make it yours”. The legal basis is providing the membership you chose (GDPR art. 6(1)(b)).
- •Organisations that see totals only: some organisations, such as RAV offices, are set up to see only totals for the whole group: how many people joined, started, passed the exam and got a certificate, all shown only once at least 5 people have joined. Their admins never see your name, your email address, your answers or a list of who did what. The join page tells you which applies before you join, and this setting can’t be switched off while people are members.
- •About admins: we keep each admin’s email address to let them sign in to the dashboard, and we email them once when they become an admin.
- •The services we rely on (subprocessors): Cloudflare (which runs humanqueue.com and stores the records) and Resend (which sends the emails), under Data Processing Agreements and Standard Contractual Clauses or an equivalent adequacy safeguard.
- •How long we keep it: your membership lasts until you leave, an admin removes you, or you delete your account; after that the organisation no longer sees your progress. Your account, progress and any certificate stay yours.
- •Your rights: leave the organisation any time on humanqueue.com/account. To access, correct, or delete your data, email support email, and we will respond within 30 days.
Contact form on humanqueue.com
The contact form on humanqueue.com’s page for employment offices and course providers (humanqueue.com/rav) lets you write to us without an email address on the page.
- •What we collect: the topic you pick, your name, your organisation (optional), your email address and your message, plus which page and language you wrote from.
- •Why and how: only to answer you. The form sends it to our inbox as an email through Resend (our email provider), with your address as the reply-to. We don’t add you to any list, and we never email anyone else from the form. The legal basis is answering your request (GDPR art. 6(1)(b) and (f)).
- •What the site keeps: nothing of your message. To stop abuse, it keeps a scrambled (hashed) form of your network address and the time of sending for one day.
- •How long we keep it: your email stays in our inbox for as long as we need it to deal with your request. To have it deleted, email support email.
Release notes and feedback (website)
After you click a Download button, in a sign-up form on this website, or on our feedback page, you can choose to give us your email address for release notes and the occasional question about how our apps work for you. The feedback page also lets you send us answers to a few short questions, with or without an email address. Both are optional and separate from our apps: nothing in MoltenRock, MoltenMail, MoltenView, or MoltenRock Connect sends us anything.
- •Who is responsible: The data controller is Goldcote Ltd (Switzerland).
- •What we process, and why: For the list, your email address and nothing else, to send release notes and the occasional question. For feedback, what you write, the apps you tick, and your email address if you give one, so we can read it and reply. The legal basis is your consent, which you can withdraw at any time.
- •The services we rely on (subprocessors): Cloudflare (which runs this website and its forms) and Resend (which keeps the list and delivers feedback to our support mailbox). Each acts under a Data Processing Agreement, and any transfer of data outside Switzerland or the EU is covered by Standard Contractual Clauses or an equivalent adequacy safeguard.
- •How long we keep it: List addresses until you unsubscribe or ask us to delete them; when you unsubscribe, your address is added to a suppression list so we do not email you again. Feedback stays in our support mailbox until you ask us to delete it.
- •Your rights: Every email has an unsubscribe link. You can also ask us to access, correct, or delete your data by emailing support email, and we will respond within 30 days.
Download counts
When you click a Download button on this website, or the download link in an app’s update check, we add one to a running count. For each click we record only: the date, which app, which page of this website the button was on (or that it came from an update check), whether the link was opened from this website, another website, or outside a web page, and the country Cloudflare reports for the request.
- •Nothing that identifies you: No IP address, cookie, device identifier, browser details, or referring address is stored, so no count can be linked to you or to your device. These are totals, not records of individual visits.
- •Where it is kept: In Cloudflare, which runs the download links.
Updates and Changes
If we ever need to change our privacy practices, we will update this policy and notify users through the App Store update notes. However, our core commitment to local-first, privacy-respecting software will never change.
Contact
If you have questions about our privacy practices, please contact us at support email
Data controller: Goldcote Ltd
Wickhams Cay 1, Road Town, Tortola, British Virgin Islands
Representative office in Zurich, Switzerland
Company details: Imprint · Data Processing Agreement
Last Updated: September 2026