Privacy
Last updated: 26 September 2026
Short version
M8Thor runs on your Mac. Your backups, songs, samples and settings stay on your Mac and on your M8's SD card; we never receive them. The app has no account, no tracking and no ads. The website sets no cookies.
Who is responsible
KIMIKON e.U., Amalienstraße 29/1/6, 1130 Vienna, Austria.
Privacy questions: privacy@kimikon.cc. Full company details: Imprint.
The app
M8Thor makes two kinds of network request. First, it checks for app updates: Once a day, and when you choose Check for Updates, it downloads https://m8thor.cc/updates/appcast.xml; updates are downloaded from the same place. (Versions up to 0.2.0 check kimikon.cc/m8backup/appcast.xml, served by the same Cloudflare Worker.) Like any web request, this transmits your IP address and a user agent with the app's name and version and the Sparkle version. M8Thor does not send a system profile. The requests are handled by Cloudflare, as described under Hosting. You can turn automatic checks off in Settings › Updates.
Second, from version 0.3.0, it checks for M8 firmware — only after an M8 has been connected to your Mac. At most once a day it asks GitHub (api.github.com and raw.githubusercontent.com, operated by GitHub, Inc.) for the latest release in Dirtywave's public repository github.com/Dirtywave/M8Firmware; when you choose GET FIRMWARE and accept Dirtywave's EULA, it downloads the firmware from there. Like any web request this transmits your IP address; the requests carry a user agent with the app's name and version, the language "en" (not your system's) and the standard headers a download needs (Host, Accept, Accept-Encoding, Connection, and on the daily check the tag GitHub sent last time). They contain nothing about you or your M8. You can turn this off in Settings › Updates (Check for M8 firmware). See GitHub's privacy statement.
To offer the right firmware, M8Thor keeps a small file on your Mac (Application Support/M8Thor/firmware.json): each M8's USB serial number, model and reported firmware version and when it was last seen, the IDs of the SD cards seen in it, the firmware it downloaded, which firmware files it put on which card, and whether you accepted Dirtywave's EULA. None of this leaves your Mac.
REMOTE, from version 0.3.0, shows your M8's screen on your Mac and plays its USB audio there. macOS treats the M8's USB audio as a microphone, so M8Thor asks for permission to use audio input; it listens only to the M8. The audio is played on your Mac, never recorded, and never sent anywhere. The serial connection that mirrors the M8's screen and sends it your key presses runs over the USB cable between your Mac and the M8 and stays there. You can deny or withdraw the permission in System Settings › Privacy & Security › Microphone; the screen and the keys work without it.
Everything else — detecting and identifying your M8, backups, restores, browsing, the sample editor, REMOTE and copying firmware to your card — happens on your Mac.
We use this data to deliver updates and keep the service secure. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the app up to date and secure.
The website
Hosting. m8thor.cc and the update feed are served by Cloudflare Workers. When you open a page or download a file, Cloudflare processes your IP address, the time, the requested address and technical browser and connection information to deliver the content, detect errors and fend off abuse. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a secure, reachable website.
Settings in your browser. If you change the language, colour or light/dark mode, the page remembers your choice in your browser's local storage. It is not sent to us. You can delete it through your browser's website data.
Cloudflare may process data outside the EEA, in particular in the USA. See Cloudflare's privacy policy and Data Processing Addendum. We keep technical data only as long as operation, security, error analysis or legal obligations require.
Contact and bug reports
If you email us, we process your address, your message and any attachments to answer you (Art. 6(1)(b) GDPR for questions about a contract, otherwise Art. 6(1)(f)). Incoming mail is forwarded through Cloudflare Email Routing to our mailbox at Google (Gmail). We keep messages only as long as needed for your request or as required by law.
Bug reports go to GitHub (github.com/kimikonapps/M8Thor-issues). What you post there is public and GitHub's privacy statement applies.
Your rights
Where the legal requirements are met, you have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests. Contact: privacy@kimikon.cc. You can also complain to the Austrian Data Protection Authority or another competent supervisory authority.