Privacy
Last updated 9 October 2026
This page says what RibbonKeys reads and sends, what is kept about a purchase and about the managers of a team licence, who else handles it and for how long. RibbonKeys is made and sold by Tss Studio, a sole proprietorship based in the Netherlands, which is responsible for the data described here.
The app
RibbonKeys needs the Accessibility permission of macOS. This is everything it does with it, and everything it sends.
- Your files stay on your Mac. RibbonKeys does not read the cells of a sheet or the text of a document or slide, and nothing about your files is sent anywhere.
- Keys. While it runs, macOS passes key presses and mouse clicks to RibbonKeys; that is how it notices the tap on ⌥. It acts on them only in Excel, Word and PowerPoint: on the tap on ⌥, or ⌥ held with a letter, that starts a sequence, and on the letters and Escape of the sequence, which it keeps from the app; in Excel on Ctrl+U outside a sequence, which it hands on as Command+U so that it underlines, unless that is switched off in its menu; and on an Escape that closes a dropdown a sequence left open, after which it puts the keyboard back in the document. Every other key goes to the app untouched. It does not record them and does not send them.
- The ribbon, the menus and dialogs. It reads the names and positions of the ribbon's tabs, buttons and menu items, and in Excel also of the menu bar and of dialog controls, to know where to draw the letters and what to press. Along the way it sees the titles of the windows, which include the file's name, and in Excel the text in the boxes of an open dialog. It keeps none of this and sends none of it.
- Licence check. About once an hour, and when you open its settings, it asks RevenueCat, the service that handles the purchase of a single licence, whether its licence code has been paid for. Once a day it also tells the seller's own licence service, at licence.ribbonkeys.com, that the code is in use, sending the code alone. A copy that has a licence, bought or given free of charge, also sends the licence code there together with a second code that stands for your Mac and the name of your Mac, and gets back the confirmation that the licence is in use on this Mac: when it is opened, about once a week, when what is paid for changes, as after a purchase or a renewal, and, while it still waits for that confirmation, at each licence check, about once an hour. The same two codes go with the request when you enter a licence code, when you remove this Mac from the licence, and when you choose Manage Subscription…, which asks the service where the subscription is managed. A copy in its trial sends only the daily code. The code of a single licence and the code that stands for your Mac are made from your Mac's hardware identifier in a way that cannot be turned back; the identifier itself is not sent. The code of a team licence is random. A Mac that has a seat of a team licence asks the licence service alone; RevenueCat is asked about a team's code once, when it is entered with Enter Licence Code….
- Updates. About once a day it fetches one small file from this site, which lists the newest version. When there is a newer one and you choose to install it, it downloads the update from this site. The request carries the version of RibbonKeys you have and nothing about you. It passes through the licence service, which adds one to that day's count of updates, by the country Cloudflare names, and keeps nothing else about the request; neither your address nor anything that identifies you.
Buying a single licence
You pay in your browser on a checkout page hosted by RevenueCat, completed in Stripe Checkout and sold through Link. Stripe processes the payment and issues the invoice. Your e-mail address and payment details go to them, not to the app. They keep the record of your purchase: your e-mail address, what you bought and when, and the licence code. The seller can see that record, and uses it to answer you and for the bookkeeping the law requires.
The seller also keeps a list of licences, stored with Cloudflare: the licence code, the e-mail address of the purchase, what is paid until when, when the code was first and last seen, the code that stands for the Mac the licence is on, the name of that Mac and when it last confirmed the licence, when the licence was moved, and a note of whose licence it is.
Team licences
A Mac uses a team licence with the licence's code alone, without an account. Buying a team licence and managing its seats happen on the team page, team.ribbonkeys.com, which is part of the licence service, and need an account there.
- Signing in. You sign in with a Microsoft or Google account. The team page sends your browser to the one you choose and gets back an identifier that stands for that account, your name and your e-mail address. Microsoft or Google learns that you signed in to RibbonKeys, and nothing about your licences. Your password stays with them: the team page never sees it and stores none.
- Your account. The first sign-in makes an account at the licence service, stored with Cloudflare. It holds which of the two you signed in with and that identifier, your name and e-mail address as they were given, which are brought up to date each time you sign in, and when the account was made. If you add a second way to sign in, that one and its identifier are kept too.
- Managers and invitations. For each team licence the service keeps which accounts manage it, since when, and which of them was invited. The other manager of a licence sees your name, or your e-mail address if there is no name. Of an invitation code only a form that cannot be turned back is kept, with the licence it is for and when it stops working.
- The Macs. For each Mac that holds a seat the service keeps the code that stands for that Mac, the name of the Mac, the order in which the Macs took their seats and when the Mac last confirmed its seat. The managers see the names of the Macs and those dates on the team page, not the codes. When a seat is released, the service remembers the code that stands for that Mac, so that the Mac does not take the seat straight back.
- Payment. You pay in Stripe Checkout, which the team page sends you to. Stripe processes the payment, works out the VAT and issues the invoices. Your e-mail address, the billing address, the company's name and VAT number and the payment details go to Stripe, not to the licence service, and Stripe keeps the record of the purchase. The seller can see that record, and uses it to answer you and for the bookkeeping the law requires. The licence service keeps the e-mail address entered at checkout, on its list of licences, with the licence code, what is paid until when and for how many seats, Stripe's own identifiers of the checkout, the subscription and the customer, and which account bought. The invoices on the team page are read from Stripe each time the page opens and are not stored by the service. RevenueCat has no part in the purchase of a team licence.
- Cookies. The team page sets two cookies, both needed to sign you in and used for nothing else: one for the trip to Microsoft or Google and back, which lasts at most ten minutes, and one that keeps you signed in for 12 hours or until you sign out. The service keeps each signed-in visit in a form that cannot be turned back into the cookie, with its account and when it ends. The team page loads no script, image or font from anywhere else and has no analytics.
This site
Until you play the Excel demo video, ribbonkeys.com sets no cookies and loads nothing from other sites. The Word and PowerPoint demo videos are files on ribbonkeys.com itself. Playing the Excel video loads YouTube's privacy-enhanced player, so YouTube receives the information your browser sends with that request, including your IP address. The Download button leads through the licence service, which adds one to that day's count of downloads, by the country Cloudflare names and the site the link was on, and then sends your browser to the file; it keeps nothing else about you, neither your address nor anything that identifies you.
Who else handles it
- Cloudflare serves this site, and runs the licence service with the team page and stores its data. It sees your IP address when you load a page, as any web server does, and the IP address of a copy of the app that contacts the service. The service counts the requests of an address for a minute, to stop a flood, and does not store the address.
- RevenueCat hosts the checkout of a single licence, keeps the record of that purchase and answers the app's licence check.
- Stripe processes the payments and issues the invoices, for single licences sold through Link and for team licences, whose subscriptions and customer portal it also holds.
- Microsoft or Google signs in the manager of a team licence, whichever of the two that manager chooses. Google also receives your browser's request if you play the Excel demo video on this site, which is on YouTube.
No tracking, in the app, on this site or on the team page, and no analytics beyond the counts of downloads and updates, by country and by the site the link was on. Nothing is sold.
How long it is kept
- A sign-in on its way. Until you are back from Microsoft or Google, or ten minutes.
- A signed-in visit. Until you sign out, or 12 hours.
- An invitation. Until it is used or replaced, or 7 days.
- A price shown for a change of seats. 20 minutes: the service remembers what it showed you, so that confirming charges exactly that.
- What has run out. Any of those four that has run out is deleted the next time the team page is opened.
- A Mac. Its name and the code that stands for it are kept while it holds a licence or a seat: until the licence is moved or the seat released, or until that Mac has not confirmed it for 60 days. After a seat of a team licence is released, the code that stands for that Mac stays, without its name, until the Mac takes a seat again.
- An account. The service sets no end to an account, its ways of signing in and the licences it manages. They are kept until you ask for them to be deleted. A second manager's part in a licence also ends when the first manager removes it.
- The list of licences. The service sets no end to a licence's line, or to Stripe's identifiers of a team purchase with the account that made it. The seller deletes them when asked.
- The record of a purchase and its invoices. Kept by RevenueCat and Stripe, and by the seller for as long as the bookkeeping the law requires.
Asking about your data
To see what is held about you, or to have it corrected or deleted, write to [email protected]. If this page changes, the date at the top changes with it.