Legal
App Privacy Policy
MPE Insight desktop app for macOS and Windows
Last updated: 14 August 2026
MPE Insight collects no personal data. There is no analytics, no tracking, no advertising, no crash reporting service, no user account and no sign in of any kind.
Your playing, your images, your video and your camera feed are processed on your own computer, in the moment, and are never stored or transmitted by the app.
1. Scope
This policy describes the MPE Insight desktop application: the macOS version from the Mac App Store, and the Windows version from Steam or bought directly from this website.
The website you are reading this on is a separate matter with its own hosting logs and its own consent based analytics. Those are described in the Website Privacy Policy. Nothing on that page applies to the app.
2. What the app works with, and what happens to it
MPE Insight turns MIDI performance data into visuals. To do that it reads the following while it runs:
- MIDI input from the instruments and ports you enable, including note, velocity, pressure, pitch bend and controller data.
- Images and video files that you pick yourself in a file dialog, used as a visual source in the FORGE module.
- A live camera feed, but only in the FORGE module and only after you click the Webcam button.
All of this is processed in memory and drawn to the screen. None of it is written to disk, sent to a server or shared with anyone. The camera feed in particular is rendered and discarded frame by frame: it is never recorded.
Files leave the app only when you ask for them. Recordings, PNG stills, CSV data and MIDI files are written to the location you choose in a save dialog, and nowhere else.
3. What the app stores on your own computer
The app keeps a small amount of state so that it looks the way you left it. This data stays on your machine, is never transmitted, and is not personal data in any meaningful sense:
- Settings and layout, for example colours, module options, key range and which MIDI ports you enabled.
- Your snapshots and presets, including the file path of an image or video you selected as a FORGE source, so that the snapshot can find it again.
- A crash log, if the app ever fails. It is a plain text file holding an error message, a time stamp and the app version. It is never transmitted. The dialog you see after a crash only reveals the file on your disk, so that you can decide whether to send it in yourself.
- A licence activation file, in the version bought directly from this website only. See section 4.
You can delete all of it by removing the app's data folder:
- macOS:
~/Library/Application Support/de.christophek.mpe-insight - Windows:
%APPDATA%\de.christophek.mpe-insight
4. Network connections
What the app contacts depends entirely on where you got it. This is not a setting, it is a difference in the shipped program itself: the licensing and update code is compiled out of the store versions rather than merely switched off.
Mac App Store and Steam
These versions make no network requests at all. There is no licence check, no update check, and no device identifier is generated or transmitted. The App Store privacy label reads "Data Not Collected", and that is accurate.
Version bought directly from this website
This version contacts exactly two addresses, both only for the purpose named:
- Licence activation at
api.lemonsqueezy.com. When you activate, your licence key and a device fingerprint are sent so that the licence can be tied to one machine. The fingerprint is a 16 character value calculated from your computer name and your user name. The calculation runs in one direction only: the fingerprint is what leaves your computer, the names themselves never do. - Update check at
christophek.de, where the app reads a small file listing the current version number. It is an ordinary web request that transmits no usage data.
Neither request carries anything about what you play, what you load or how you use the app.
5. Permissions the app asks for on macOS
Under the macOS sandbox an app has to declare what it may do. Three declarations are visible in MPE Insight, and it is worth being precise about why each exists:
- Camera. Requested only when you click the Webcam button in FORGE, and used only as a live visual source. The app is fully usable without ever granting it.
- Files you select. The app can read only the files you pick in a dialog, and write only where you point a save dialog. It has no access to the rest of your disk.
- Network client. This one is purely technical and does not mean the app goes online. macOS renders the interface through WKWebView, and WKWebView loads every document, including the pages that ship inside the app itself, through its own networking helper process. The sandbox counts that as network access. Without the declaration the window simply stays blank. In the Mac App Store version, nothing in the product opens a connection.
6. On device processing, and no AI services
The FORGE module can estimate depth from an image to drive its three dimensional effects. The model that does this ships inside the app and runs on your own hardware, offline. No image is uploaded, and there is no cloud service behind any feature.
It is a computer vision utility rather than generative AI: it takes no prompt and produces no text, imagery, audio or music of its own.
7. Purchases, and what I learn from them
The app itself never handles payment. Purchases are made through the store you bought from, and each store is the seller of record for its own channel:
- Apple for the Mac App Store, Valve for Steam. From both I receive aggregated sales and usage statistics that cannot identify an individual. I do not receive your name, your email address or your payment details.
- Lemon Squeezy for direct purchases from this website. As seller of record they process the payment and issue the invoice. Their order record, which I can see, includes the buyer's email address and billing country, because that is how the licence key is delivered and how support requests can be matched to a purchase. I use it for that and for nothing else. It is never sold or passed on.
If you write to me for support, I keep the correspondence for as long as it takes to help you, and delete it when it is no longer needed.
Legal basis for handling a direct purchase and its support: Art. 6(1)(b) GDPR (performance of a contract).
8. Data Controller
Christophe Kalkau
Johannes-Drach-Str. 55A
97753 Karlstadt, Germany
Email: mail@christophek.de
9. Your Rights
Under the GDPR you have the following rights with regard to me as the data controller:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
In practice there is very little for me to act on, because the app sends me nothing. Anything the app stores is on your own computer and under your control, and you can remove it as described in section 3.
To exercise your rights, please contact: mail@christophek.de
You also have the right to lodge a complaint with the competent data protection supervisory authority. For Bavaria, this is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
10. Changes to This Policy
This policy may be updated if the app gains a feature that changes how data is handled, or if the applicable legal requirements change. The "Last updated" date above indicates the currently applicable version.