Privacy Policy — Hecate Viewer for Windows, macOS and Linux
Effective date: 2026-09-29 Developer: Matthias Morath
Hecate Viewer for the desktop shows, live, the assets that appear on your MQTT broker, as a list and on a map. It captures nothing and publishes nothing. There is no hosted backend operated by the developer and no third-party analytics or tracking. The one other network destination is the map service, described under "The map".
Desktop application (Windows, macOS, Linux)
This is the privacy policy of Hecate Viewer for Windows, macOS and Linux. There is no hosted backend of our own: the Viewer reads from the MQTT broker you enter, and whoever runs that broker is responsible for the data there.
What we collect
Nothing. The Viewer shows the assets that appear on your broker and sends nothing there itself. Which assets you hide or flag it remembers on this computer only. It reads no device location and collects no analytics or advertising identifiers.
Permissions
The Viewer asks for no permissions: no camera, no location, no Bluetooth, no access to your photos.
Where data goes
The Viewer reads from the MQTT broker you enter — encrypted with TLS, unless you switch TLS off yourself for a broker without encryption — and publishes nothing there. There is no Hecate backend, no licence check and no third-party analytics, advertising or tracking service. The second network destination is the map service, see "The map". An event log reaches Hecate only when you send it yourself from your e-mail program, after seeing it in full (see "Terms and privacy").
The map
The map shows assets with a location on vector tiles from OpenFreeMap, run by Hyperknot Software Kft. (Hungary, EU); Cloudflare may serve as its CDN. The Viewer asks OpenFreeMap for the current map version and for the tiles. Every tile request tells the map service the part of the map on screen, and so roughly where the assets are, and, like every request on the internet, your IP address. OpenFreeMap states that it logs no IP addresses, except for up to 30 days during security incidents. The request carries no identifier of this installation, only the application's name and version. If no asset on screen has a location, no tile is requested. "Open in browser" hands an asset's location to openstreetmap.org, and only when you choose it.
Storage & security
Settings, the cached profiles, the hidden and flagged assets and the event log are files in your user folder on this computer, the map tiles in the operating system's cache folder. The Viewer keeps the assets it receives in memory only. The broker password lives in the operating system's keyring — the macOS Keychain, the Windows Credential Manager or the Secret Service on Linux —, never in plain text in a file and never in the log. The event log stays on the computer until you save it and pass it on yourself; passwords and credentials are replaced when you do.
Retention & deletion
The assets received are gone when you close the Viewer. Hiding deletes nothing on the broker; you show hidden assets again in Settings. The event log keeps at most two files of about one megabyte each and overwrites the older one. The operating system may empty the tile cache at any time. What lies on your broker is kept there according to its configuration; the Viewer cannot delete anything there.
Third parties
The Viewer is built from open-source Rust libraries, among them rumqttc for the connection to the broker and walkers for the map; the full list with their licences and the credit for the map data are under "About". No analytics, advertising or tracking libraries are included. The only network destinations are the broker you enter and the map service OpenFreeMap.
Your rights
Because your data lives on your computer and on your broker, you can exercise most privacy rights directly — view and edit entries in the application, delete them from the computer, and manage retention on your broker (access, rectification, erasure). For anything else, contact the controller named below. Depending on where you live, you also have the right to lodge a complaint with a data-protection authority.
Controller & contact
Hecate is developed by MMM Software & Consulting. When you run Hecate against your own broker, you (or your organisation) act as the controller for the data you capture. Questions about this policy: by e-mail to info@hecateapps.com. Last updated: September 2026.
Children
Hecate is a professional/field utility and is not directed at children.
Changes to this policy
If the app's data handling changes, this page and the in-app Settings → Privacy screen will be updated together.