Website & licensing privacy.
This policy covers sarcomereapps.com and its device-activation and software-download services, operated by Sarcomere. Individual apps have separate privacy information.
Visiting the website
You can browse the app catalog without creating an account. Our hosting provider processes connection information such as IP address, browser information, requested addresses, and timestamps to deliver the website and protect it from abuse. Hosting is provided directly through Cloudflare.
We have not added advertising trackers or visitor-analytics scripts to the website. Hosting and security logs are separate from advertising or cross-site tracking.
Device activation and license restoration
When Leopard Control contacts our licensing service, we store the device and installation codes, the installation’s public verification key, hashed device and app-signing identifiers, app versions, activation and license status, and related timestamps. Supported versions also send a hashed Android-derived device identifier so an approved device can be recognized after reinstalling. This is a persistent identifier, not anonymous data.
We also keep approval or revocation decisions, support notes entered during review, signed-entitlement issuance records, and security audit history. We use these records to verify access, restore approved installations, provide support, and prevent unauthorized activation. A displayed device code alone is not proof of ownership.
Someone who has a device’s activation link can view its limited activation status. Keep your activation links and codes private. The licensing requests described here do not include messages, contacts, passwords typed into other apps, or mouse and keyboard input.
Essential cookies and abuse protection
The administrator area uses an essential sign-in cookie. It expires after at most 12 hours, with a 30-minute inactivity limit enforced by the server. Administrator passwords and session tokens are stored as hashes, not readable passwords or raw session tokens. Hosting providers may also use essential security cookies.
Our application uses keyed hashes of network addresses and request counts to limit abusive traffic. This does not prevent the hosting providers from processing IP addresses in their own infrastructure. We do not use these records for advertising.
App availability reporting
Supported Leopard Control and Leopard Remote versions include availability reporting enabled by default. You can turn it off under Privacy policy in the app’s update settings; an existing choice to disable it is preserved. When enabled, the app sends its app/version identifiers, an app-scoped hashed device identifier, a public verification key and signed active/inactive reports approximately every two minutes while the app is in use. Remote may also report while its hosting service is running. We do not collect names, contacts, vehicle identification numbers, location, phone details, typed text, clipboard contents or screen content through this feature.
The website administrator sees registered-device totals and an approximate online count based on reports received within five minutes. Device counts are not unique people. Older versions, offline devices and people who opt out may be missing from online counts; losing the connection can leave a device counted online briefly. Remote totals include only devices that registered through reporting. Leopard Control totals can also include existing verified licensing registrations.
You can disable availability reporting in the app without changing its functionality or license. This stops periodic reports and attempts one signed disabled report; if that cannot be delivered, online status expires after five minutes. A previous pseudonymous registration remains in the known-device total. We retain the latest state, version and server timestamps per verification key to provide these counts, rather than a historical activity timeline. App-scoped hashes allow supported reinstalls to be grouped, but a reset or unavailable device identifier can create a separate identity. Contact us if you want to request removal of a registration.
Support, downloads, and payments
If you email us, we receive your email address, message, and any information or attachments you choose to send. Device-support links may include your device code in a draft email. Support email is handled through Gmail. Please do not send passwords or full payment-card details.
Software downloads generate ordinary hosting requests. Release records contain the software version, file checksum, signing information, release notes, and publication history. Downloading an APK does not automatically activate a device.
If a service offers a payment link, the linked payment provider handles payment details under its own privacy terms. App Store and Google Play purchases are handled by the respective store. Our website does not provide a payment-card entry form.
For direct Leopard Control checkout, Moyasar processes payment details on its hosted checkout. We retain an order linked to the device and installation, the amount and currency, provider invoice and payment references, payment or refund status, and timestamps. We use these records to verify payment, grant the correct access period, prevent duplicate activation, reconcile interrupted payments, and handle refunds or disputes. We do not store full card numbers, security codes, or Apple Pay credentials.
Access, providers, and retention
Access to private licensing and administration records is restricted to authorized administration and the providers operating these services. Hosting, infrastructure, and email providers may process information outside your country. Their processing is also governed by their respective policies.
Licensing and audit records are retained to maintain access, restore approved devices, investigate support issues, and prevent abuse. They are not automatically erased when an app is reinstalled or a device is revoked or removed from the management list; revocation markers and history may remain. Expired verification challenges not needed for licensing history and expired request-limit records are cleaned up as the service runs.
We review requests to access, correct, or delete information in light of the service’s operational needs and applicable legal obligations. Contact us to make a request; we may need enough information to verify that it relates to your device or correspondence. We do not promise that removing a device from the interface erases every associated record.
Contact and changes
For privacy questions or requests, email sarcomerestore@gmail.com. We will update this page when these practices change and show the revision date above.