Skip to content
BrewMDM Open source · self-hostable

Privacy policy

Last updated 21 August 2026.

BrewMDM is made by M7KNI Ltd. This policy covers this website — the launch-notification form on it, and the analytics that count visits. BrewMDM itself is self-hosted: you run it on your own infrastructure, and nothing it manages reaches us.

The short version

  • We store your email address only if you type it in and confirm it, and only to tell you once, when BrewMDM launches.
  • Analytics runs only if you agree. Say no and nothing about the site stops working.
  • We do not sell, rent or share personal data for anyone else's marketing, and we run no advertising tags.

Who is responsible

M7KNI Ltd is the data controller. We are registered in England and Wales, company number 17385187, at Unit 13 Freeland Park, Wareham Road, Lytchett Matravers, Poole, England, BH16 6FA.

Reach us at hello@brewmdm.app, or through the contact form on m7kni.com. Both reach the same people, and the contact page lists every route including the one for security reports. We are not required to appoint a Data Protection Officer and have not appointed one — those addresses reach the people who would answer to one. Messages sent through the m7kni.com form are covered by the m7kni.com privacy policy.

The software collects nothing

BrewMDM is a control plane you host yourself. It has no telemetry, no phone-home and no licence check, so we never see your fleet, your Macs, or what is installed on them. There is no data from the software for this notice to describe, because none of it reaches us. Everything below is about the website.

What the launch list stores

  • The email address you enter.
  • When you signed up, when you confirmed, and when you unsubscribed.
  • A consent version, which records the wording that was next to the button on the day you agreed to it.
  • Where the signup came from, so we know which page was doing the work.
  • The hashes of your confirmation and unsubscribe links. The links themselves are never stored — they exist only in the email we sent you — so a copy of the database does not let anyone confirm or unsubscribe an address they do not control.

Your address is not on the list until you open the link in the confirmation email. If you never open it, the row expires unused and nothing is ever sent to you again.

What we use it for, and why we are allowed to

One email, when BrewMDM launches. We do not sell, share or rent the list, we do not send anything else to it, and we do not use it to build a profile of you.

The lawful basis is your consent, under Article 6(1)(a) of the UK GDPR. You gave it by entering your address and confirming it, and you can withdraw it at any time. Withdrawing does not affect anything we did while the consent stood.

Analytics and cookies

This site uses Google Analytics 4 to count visits and see which pages get read. It is loaded through Cloudflare Zaraz, and it does not run until you have agreed to it. The first time you arrive you are asked; if you decline, the tag is never loaded.

What is stored in your browser, and why:

  • Your consent choice, in a cookie named zaraz-consent. This one is set whatever you choose, because refusing analytics is itself a decision we have to remember — without it you would be asked again on every page.
  • An analytics identifier, but only if you agreed. It is a random value that lets Google count two visits by you as one visitor rather than two.
  • A Turnstile token, briefly, while the bot check on the form runs. Turnstile looks at your IP address and browser signals to decide whether a request is automated. It is there so a public form cannot be used to send mail to people who did not ask for it.
  • A Cloudflare cookie that distinguishes real visitors from automated traffic. This is part of serving the site securely and is set regardless of your analytics choice.

If you agree to analytics, this is what is sent to Google about the visit:

  • Which page you are on — the full address, including any campaign tags — and the page you arrived from, including when that is somebody else's site.
  • Your device and browser, in broad terms — whether you are on a phone or a computer, which browser and operating system, your screen and window size, the language your browser asks for, and your time zone. The identifying detail is deliberately stripped on the way out: no device make or model, no exact browser or operating-system version, and no list of what is installed.
  • Roughly where you are, worked out from your IP address. The address is trimmed before it reaches Google, so this is a general area rather than your connection.
  • The random visitor ID above, so two visits by you count as one visitor.

None of Google's advertising features are switched on. Google Signals, remarketing and ads personalisation are all off on the analytics property, so a visit here is never associated with your Google account and is never used to build an advertising profile of you. There are no advertising cookies and no tracking pixels. The fonts are served from this site rather than a font provider, so loading a page does not tell anyone else that you visited.

Who else handles it

The site runs entirely on Cloudflare, which acts as our processor. Cloudflare hosts the page, stores the list in a database in its network, sends the confirmation and unsubscribe emails, and provides the Turnstile bot check on the form.

Google receives website analytics data, and only if you agreed to it. Google is a separate controller for that data and handles it under its own terms.

Both are bound by contract to protect your data to at least the standard set out in this policy and required by UK data protection law. Nobody else has access.

Where it goes

The list and the emails stay within Cloudflare's network. Analytics data, if you agreed to it, is transferred to Google in the United States. That transfer relies on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses. Declining analytics means no transfer happens.

How long we keep it

  • The launch list: until BrewMDM launches and that email has gone out, or until you unsubscribe, whichever comes first. After the launch email the list has done its job and is deleted.
  • Unconfirmed signups: the row expires unused if you never open the confirmation link, and is deleted.
  • Analytics: Google keeps event data for 2 months and user-level data for 14 months, after which it is deleted.
  • Your consent choice: stored in your browser until you clear it or it expires.

Your rights

Over the personal data we hold about you, you have the right to:

  • be told what we hold and get a copy of it;
  • have it corrected if it is wrong;
  • have it deleted;
  • restrict or object to what we are doing with it;
  • receive it in a portable form, or have it sent to someone else;
  • withdraw your consent at any time, for both the list and analytics.

For the list, deletion and withdrawal are the same thing and they are instant: every email we send carries an unsubscribe link, and one click is enough — you do not have to reply, log in or explain. For analytics, use the Manage cookies button above. For anything else, email hello@brewmdm.app or use the contact form. We will respond within one month and we do not charge for it.

Decisions, and what you have to give us

We do not make automated decisions about you and we do not profile you. Nothing here is required by law or by a contract: joining the list is entirely optional, and so is agreeing to analytics. The only consequence of giving us nothing is that we cannot tell you when BrewMDM launches.

Changes to this policy

If we change what we do with personal data, we will update this page and move the date at the top. If the change is significant and you are on the list, we will tell you by email before it takes effect.

Complaining

If you think we have handled your data badly, you can complain to the Information Commissioner's Office, the UK's data protection regulator. We would rather you told us first, but you do not have to.