Privacy policy

Last updated: 5 October 2026

StallScope is an always-on tool that records how Windows is behaving, once per second. Those recordings include the names of running programs and the ports they are listening on. This page states what is recorded, where it is kept, and where it does not go.

This policy covers how StallScope, provided by tanmen (“we” or “us”), handles data specifically. Anything it does not cover is governed by the tanmen.work privacy policy.

What is recorded

Windows performance counters (CPU, memory, disk, network, page faults and others), kept per core and per drive. Alongside them, for the processes using the most resources: the executable name, the process ID, and CPU, memory, disk I/O and GPU usage. For networking: TCP connection state, the local port, the remote port, and the owning process ID. The process name of whichever window was in the foreground is also recorded, once per second.

What is not recorded

No remote IP addresses, keystrokes, screen contents, file contents, names of open files, browsing history or account information. For processes, only the executable name and resource usage are recorded — command-line arguments are not.

Window titles are not recorded. For the foreground application only the process name is kept, so what you had open in it does not appear anywhere.

Where it is kept

Everything is written as files inside a folder you choose. The default retention is 14 days (28 for the stall log), after which older data is deleted automatically. You can change the location at any time from the settings window, and deleting the folder leaves nothing behind.

One exception: the one-line-per-day summary (that day’s stall count and representative values) is kept without a time limit, in the same folder. It is a local file too, and it does not leave the device.

Network

Nothing recorded ever leaves the device. There is no path by which collected data is transmitted, and there is no telemetry and no analytics.

StallScope contacts the outside world in exactly two situations. One is update checking, where Windows asks the Microsoft Store whether a newer version exists; no user data is carried in that request.

The other is the licence check, if you are using Pro. The licence key and an identifier for this device are sent to our licence server, which returns a certificate carrying an expiry date. Those two things are all that is sent — no collected data, no usage information, nothing else about the device. It happens when you activate a key and once a day after that. With no licence configured, this request never occurs at all.

The device identifier is a 32-digit hash of the machine ID that Windows assigns to each device. It cannot be turned back into that ID, and it differs from the value our other products would compute, so use cannot be matched across products. It is never stored on the device; it is recomputed each time it is sent.

Purchases and licences

Payment for Pro is handled by Stripe. Card details never pass through StallScope: the purchase happens on Stripe’s own pages, opened in your default browser, and we neither receive nor store a card number.

What we do hold as a result of a purchase: the licence key, the plan (monthly or yearly), the subscription status and expiry, the customer and subscription IDs issued by Stripe, the email address the licence key is sent to, and for each device registered on that key its identifier (the hash above) and when it was first and last seen. These are stored on our licence server (hosted on Cloudflare and shared with our other products) and used only to verify licences, re-send keys, manage device registrations, and support cancellation. The email that delivers the licence key is sent through Resend.

In addition, the licence server uses the IP address a request comes from to limit requests repeated within a short time. For licence checks and similar requests it is only passed to Cloudflare’s rate-limiting feature to be counted and is not recorded; for requests to re-send a licence key, only a hash made from the IP address with a secret key is recorded, to count requests per hour, and entries whose hour has passed are deleted by a clean-up that runs once a day (because the key is kept separately from the records, the original IP address cannot be recovered from the recorded values).

A licence key can be registered on a limited number of devices at once (currently 3). You can release a device at any time from “Release this device” in the settings window, which deletes its record from the server. A device not seen for more than 30 days is removed automatically by a clean-up the server runs once a day.

You can cancel at any time from “Manage subscription” in the settings window.

Third parties

Collected monitoring data is never shared with anyone.

To provide Pro we rely on three processors: Stripe, Inc. for payment and subscription management, Cloudflare, Inc. for the licence server and its storage, and Plus Five Five, Inc. (Resend) for the email that delivers keys. Stripe receives your email address and payment details (the latter never passing through us); Cloudflare holds the licence key, subscription status, email address and device identifiers (the hash above); Resend receives the email address and the licence key. On the free tier none of them is involved.

Contact

Questions about this policy can be sent through the form on the support page. What you enter into that form is handled as set out in the tanmen.work privacy policy below.

https://tanmen.work/en/supports/stallscope/

Anything this policy does not cover

What is collected through the contact form, how long it is kept, and requests for disclosure, correction or deletion are handled the same way across tanmen.work, as set out in the privacy policy below. Where the two differ, this policy governs for StallScope.

https://tanmen.work/en/legal/privacy/

Home