MCM CodeGuard — Privacy Policy
Version 1.1 — 23 September 2026 © 2026 MCM Labs. All rights reserved.
MCM CodeGuard is a desktop application. It analyses your code on your own computer. This policy describes every case in which it makes a network request, what leaves your machine when it does, and the little personal data MCM Labs holds about customers.
Who we are
MCM Labs is the business name under which Michael Maher, of Egypt, publishes MCM CodeGuard. For the personal data described under "What MCM Labs holds", MCM Labs is the controller. Contact: privacy@mcmlabs.org.
The short version
Your source code stays on your computer, except when you explicitly ask for an AI fix, explanation, or review — and then it goes only to the AI provider you configured yourself. MCM Labs never receives it. There is no analytics, no telemetry, and no crash reporting.
What MCM Labs holds
Nothing about your code, ever. MCM Labs operates no server that your code could reach.
If you buy a licence, the purchase is made through Lemon Squeezy, which acts as merchant of record. Lemon Squeezy collects your payment details, billing address, and tax information as an independent controller, under its own privacy policy, and never gives us your card details. It shares with us your name, email address, country, and your order, subscription, and licence-key records.
If you email us, we hold your message and address.
| Data | Why we use it | Legal basis | Kept for |
|---|---|---|---|
| Order, subscription, and licence records; name; email; country | To supply the licence, handle renewals and refunds, and meet tax and accounting duties | Performing our contract with you; legal obligation | While your subscription is active, then as long as tax and accounting law requires |
| Support emails | To answer you | Our legitimate interest in supporting customers | Up to two years after the conversation ends |
We do not sell personal data, use it for advertising, or share it with anyone beyond Lemon Squeezy and the provider that hosts our email. Those providers may process it outside your country — including in the United States — under their own safeguards for international transfers.
Every network request the app makes
| When | Where to | What is sent |
|---|---|---|
| You activate, or the app revalidates, a licence | Lemon Squeezy | The licence key, and a device name made of your Mac's computer name plus the first 8 characters of its hardware UUID |
| About once a day, unless you turn off Check for Updates Automatically in the app menu | mcmlabs.org, to check for updates | A request for the update feed, which reveals your IP address and app version to our website host |
| You install an update | mcmlabs.org | A download request |
| You ask for an AI fix, explanation, or review | The AI provider you configured | The relevant source code, and the finding |
| You sign in to a code host | That host | Standard OAuth exchange |
| You browse, clone, or review | That host | Your request; your host credential |
The app makes no other outbound request. The update check sends nothing about your projects or your use of the app.
Your computer name is set in System Settings → General → Sharing, and often contains your own name. It appears in the device list on your licence so you can tell your devices apart when deactivating one.
AI providers are your choice
MCM CodeGuard has no AI service of its own and resells no tokens. You supply the AI provider: your Claude CLI seat, your Anthropic key, or any OpenAI-compatible endpoint — including a model running locally on your own machine, in which case your source code never leaves it at all.
When code is sent, it is sent to that endpoint and no other. What happens to it there is between you and that provider.
What is stored on your computer
- Licence state, usage counts, and your acceptance of the licence, in Application Support
- Host credentials, in a file there readable only by your user account
- AI provider API keys, in your macOS Keychain
- Backups of files the app changed, in Application Support, each deleted after 30 days
- Scan caches and baselines; baselines and rules live in
.codeguard/in your project
All of it is local. Deleting the app's Application Support folder removes your licence state, host credentials, and backups; AI provider keys are removed in the app or in Keychain Access.
No analytics
There is no usage tracking, no event collection, no session recording, and no third-party analytics SDK. Crash reports are never sent without your explicit consent, and none is collected today.
Your rights
Depending on where you live — including under the GDPR, the UK GDPR, the CCPA, and Egypt's Personal Data Protection Law — you may have the right to access the personal data we hold about you, to correct or delete it, to object to or restrict its use, and to receive a copy of it. Write to privacy@mcmlabs.org and we will respond within 30 days. We may keep what tax or accounting law requires us to keep.
You may also complain to the data protection authority where you live.
MCM CodeGuard is a tool for software developers and is not directed at children.
Changes
Material changes to this policy will be published with a new version number and date, and shown in the app on the next launch.
Contact: MCM Labs — privacy@mcmlabs.org