MagickMirror

MagickMirror Privacy Statement

Last updated: 2026-06-04

MagickMirror is made by a single independent developer (GooseberryFarm). This statement explains exactly what MagickMirror does -- and does not do -- with your information. It is written to match what the software actually does.


The short version


What leaves your device, and when

MagickMirror does not connect to the internet in the background to observe you. It makes network connections only for the specific purposes below, and -- except where noted -- only when you ask it to:

1. Purchasing a license. Checkout is handled by our payment and licensing provider, Polar. Payment details (such as your card) are entered with Polar and its payment processor, never with MagickMirror -- MagickMirror never sees or stores your payment information. Polar processes this data under its own privacy policy.

2. Activating and validating your license. To activate, MagickMirror contacts Polar and the MagickMirror licensing service. It sends your license key, a short label so you can recognize this device among your activations, and a one-way hash of a hardware identifier (see Device identification). This binds your license to one machine and enforces the activation limit. No browsing or usage data is sent.

3. Checking for and downloading MagickMirror updates. MagickMirror asks the MagickMirror update service whether a newer version exists and, if you choose to update, downloads it. Updates are cryptographically signed and verified before they are applied.

4. Downloading the streaming host you ask it to install. When you choose to install a streaming host, MagickMirror downloads that release from the project's own distributor and verifies its checksum before running the installer. MagickMirror supplies no games -- only the software you direct it to fetch.

5. Fetching cover art for the games you select. To give each published game a tile, MagickMirror looks that game's artwork up online. Some storefronts are asked directly; for others there is no usable first-party source, so the lookup goes to a public third-party game database and to Epic's public content CDN instead -- which means the title of a game you own can be sent to a party other than the store you bought it from. These requests name the game being looked up and nothing about you beyond what any web request reveals (your IP address and the app version). Steam artwork is never fetched -- it is copied from files already on your disk.

6. Sending feedback you choose to send. Feedback is never sent automatically. When you submit it, the contents are end-to-end encrypted before they leave your device (see Feedback).

Outside of these purposes, MagickMirror makes no network connections.


Personal information

In normal use, MagickMirror does not collect, store, or transmit personal information about you. The only personal data that ever leaves your device is the minimum required to (a) sell and validate your license and (b) carry any feedback you explicitly choose to send.

Device identification

To enforce the per-license activation limit, MagickMirror derives a device identifier and sends it during activation. This identifier is a one-way (SHA-256) hash -- the raw hardware value never leaves your device, and the hash cannot be reversed back into it. It is used only to recognize that the same machine is being activated.

Your license record

Your license, activation count, and the device label you see during activation are held by Polar so that you can manage your own activations. MagickMirror itself stores your signed license token locally, in your operating system's secure keychain.


Feedback

Sending feedback is entirely optional and is never triggered automatically. When you open the feedback panel you decide what to include, and you see every attachment before anything leaves your machine.

What a feedback report can contain:

End-to-end encryption. Your message and every attachment are encrypted on your device before the report is sent, using public-key encryption for which only the developer of MagickMirror holds the decryption key. The service that receives and stores feedback reports (running on Cloudflare) only ever holds the encrypted data and cannot read your feedback -- only the developer can decrypt it, on their own hardware.

How it's used, and how long it's kept. Any personal information in a feedback report is used solely to identify and follow up on the report you submitted -- never for advertising, marketing, solicitation, or any other purpose. A report is kept only as long as it is needed to resolve the issue you raised, and is then destroyed.

Because feedback is something you send to the developer (and never the reverse), there is no channel for anything to be sent back to your device through it.


Children

MagickMirror is not directed to children and does not knowingly collect information from children.


Changes to this statement

If MagickMirror's behavior changes, this statement is updated to match, and the version distributed with a given release describes that release. The "last updated" date above reflects the most recent change.


Questions about privacy may be directed to GooseberryFarm via the support channel listed on the MagickMirror product page, or through the in-app feedback panel.