Patch privacy

Your audio stays on your Mac.

Patch is an audio router for Mac, made by tonal.fm (“we”). This page covers what the app does with your data, and when it goes online.

Updated September 23, 2026

The short version

  • Patch never records or uploads your audio. It’s mixed on your Mac.
  • No account, no analytics, no telemetry.
  • Patch goes online for two things: your licence, with Lemon Squeezy, and update checks, with tonal.fm.
  • Captions are made on your Mac and never saved.
  • Deactivate or uninstall from Settings at any time.

What stays on your Mac

Patch mixes your microphone and the apps you choose into Patch Mix, a virtual microphone on your Mac. All of that processing happens on your Mac. Patch never records your audio and never sends it anywhere. Your call app, such as Zoom or Discord, sends what you share in the call, under its own privacy policy.

There’s no account and no sign-in, and Patch has no analytics or telemetry. It doesn’t track how you use it.

The free trial is counted on your Mac too. Without a licence, a session runs at full quality for 20 minutes from when it first goes Live, and that clock is never sent anywhere.

When Patch goes online

Patch itself goes online for two things, and neither carries audio. Both use HTTPS. Like any web request, each one shows the server your Mac’s public IP address.

Your licence

Patch talks to Lemon Squeezy (api.lemonsqueezy.com) only when you activate or deactivate a licence key in Settings, and to re-check an activated licence about once a week.

  • To activate, Patch sends your licence key and a random label such as “Patch on Mac (3f9a1c07)”. The label is new for each activation and says nothing about you or your Mac.
  • To re-check or deactivate, it sends the key and the id of that activation.
  • Activating can also deactivate one activation automatically, to give its slot back: a new one Patch can’t use, or this Mac’s previous one when the new one replaces it.
  • The re-check runs only while no session is open, so it never touches a call. If Lemon Squeezy can’t be reached, you stay licensed and Patch tries again later.
  • Only a clear answer that the key is no longer valid, for example after a refund, ends the licence. A session that’s already running is never cut.
  • Requests carry no Mac name, serial number, user name, cookies or analytics. macOS adds the standard headers it adds to any app’s request, such as a User-Agent naming Patch and its version, and your preferred language.

Update checks

Patch checks tonal.fm/patch/appcast.xml for a new version. The check is a plain request with no hardware or system profile attached; the server sees your IP address and a User-Agent naming Patch and its version. You can turn automatic checks off in Settings → Updates.

Patch doesn’t download or install an update unless you choose to, and it waits until you stop routing audio before it relaunches, so an update never interrupts a call.

Caption languages

The first time you use a caption language, macOS downloads that language’s speech model from Apple, the same way other on-device models download. Patch asks for it, but the download is Apple’s own system, not a server we run.

The “Buy a licence” and download links in Patch open in your web browser. Patch doesn’t contact those pages itself.

Buying a licence

Lemon Squeezy sells Patch for us as the merchant of record. It runs the checkout, takes payment, emails you your licence key and keeps your purchase details under its own privacy policy.

As the seller, we can see your order in Lemon Squeezy: details such as your name, email address, country, what you bought, and your licence key and its activations. We use them only to look after your licence, refunds and support. We never see your full card details.

What Patch saves

Activating a licence writes one file, ~/Library/Application Support/Patch/license.json, readable only by your macOS user account. It holds:

  • your licence key and the id of this activation
  • the name on the order, shown in Settings as “Licensed to …”
  • the date you activated and the date of the last successful re-check
  • if Lemon Squeezy later says the key is no longer valid, the reason it gave

It holds no email address and no payment details, and Patch never writes your key to a log. If the file is ever damaged, Patch renames it license.json.corrupt, keeps it for support and carries on with the trial. That copy may still contain your key.

Your scenes are kept in the same folder, and your settings in Patch’s preferences on your Mac. Captions are held in memory only while the captions panel is open, up to 50 lines, and erased when you turn captions off. They’re never written to disk; the only way caption text leaves Patch is if you copy it yourself.

Diagnostics reports

Patch writes a diagnostics report only when you click Save report… in Diagnostics, and only to the place you choose. Patch never sends one anywhere; attaching it to a support email is up to you.

A report includes the app, driver and macOS versions, your Mac’s model, your settings, each source’s type, status and levels, the bundle IDs (not names) of the apps you route, of your call app and of any other app reading Patch Mix, permission states, audio health counters, your licence status (one word: trial, licensed or invalid) and a short history of recent session changes.

It never includes audio, caption text, the names of your scenes or devices, a device’s unique ID, your email address, the name on your licence or your licence key.

Permissions and the driver

  • Microphone, so your voice can go into the mix you share with your call.
  • System Audio Recording, so Patch can capture the apps you add as sources. Patch asks when it first needs to capture an app.

Deny either and only the affected source goes silent. Patch tells you which one and how to fix it, and never asks again outside System Settings.

Patch installs a small audio driver that creates two virtual devices, Patch Mix and Patch Pass-Thru. It moves audio between those devices and your microphone and speakers on your Mac, and has no network access.

Removing your data

  • Settings → Deactivate on this Mac… frees the activation at Lemon Squeezy, then deletes license.json. If Lemon Squeezy can’t be reached, the file stays so you can try again. If there’s a license.json.corrupt, delete it yourself.
  • Settings → Uninstall Patch… removes the app, the audio driver, its two virtual devices and Patch’s caches. Tick “Also remove my scenes, settings and licence” to delete ~/Library/Application Support/Patch and your preferences as well; otherwise they’re kept in case you reinstall.
  • Uninstalling doesn’t tell Lemon Squeezy, so that activation keeps counting towards your key’s limit of Macs. Deactivate first to free it.

To see or delete what we hold about your purchase or your support emails, email contact@tonal.fm. Lemon Squeezy keeps its own purchase record under its own policy.

This website

The Patch pages are part of tonal.fm, so visits to them are covered by the tonal.fm privacy policy. The Patch pages show no ads.

Contact and changes

If you email us for support, we get your email address and whatever you send, including any report you attach. We use it only to answer you.

When Patch changes what it does with your data, we update this page and the date at the top. Questions go to contact@tonal.fm.