Privacy Policy
Product: Neocodec (macOS video/GIF converter; internal repo codename vidconvert) Publisher / data controller: George Liu, Brisbane, Queensland, Australia Contact: https://neocodec.com/contact/privacy Effective date: 17 August 2026
Summary (plain English)
- Conversion stays on your Mac. Conversion source files and converted output are processed locally and are not uploaded as part of conversion.
- Transcription is the exception you control. It is off until you save your own OpenRouter API key and approve an upload. Depending on the selected model, Neocodec sends either extracted audio or the whole video to OpenRouter and the third-party model provider. Audio and video have separate approvals.
- No Neocodec app account. You do not create a Neocodec account to use the Mac app. Polar's checkout and customer portal separately use a buyer relationship and emailed sign-in flow.
- No analytics, telemetry, or tracking in the Mac app by default. We do not collect app-usage statistics, and there is no advertising or third-party tracking SDK in the app. Crash reporting is off by default; if you turn it on, reports are stored only on your Mac and are transmitted only when you explicitly choose to email one to us (Section 5).
- A sale-enabled app makes three kinds of routine automatic network request: (1) starting and refreshing the free trial, (2) paid-license activation/validation, and (3) checking for app updates. OpenRouter key verification/model refresh and transcription occur only after you configure or invoke transcription; media upload additionally requires the applicable approval. A crash or diagnostics report leaves only when you explicitly choose to email it.
- Your purchase and payment are handled by our reseller and merchant of record, Polar.
- The Neocodec website uses Cloudflare Web Analytics and Google Analytics 4 to understand page visits and improve the site. These services do not receive conversion media or app activity (Section 7B).
1. Scope
This policy covers the Neocodec website, macOS application, free-trial service, license activation, update checks, support, and the app's optional OpenRouter transcription integration. Cloudflare, Google, Polar, and OpenRouter/the selected model provider also process data under their own terms and policies; this policy does not replace them or cover unrelated third-party websites opened from external links.
2. Local conversion and the optional transcription exception
All video/GIF conversion is performed entirely on your device using bundled helper programs (FFmpeg/ffprobe and gifsicle). Your source files, their contents, filenames, and the converted output:
- are processed only on your Mac;
- are never transmitted to us or to any third party by the app as part of conversion; and
- are not accessible to us in any way.
Neocodec-operated conversion, trial, licensing, update, and support infrastructure does not receive conversion media automatically.
2A. Optional OpenRouter transcription uploads
Transcription is off until you save your own OpenRouter API key in the macOS login Keychain and explicitly approve an upload. Neocodec does not copy the key into preferences, logs, or diagnostic reports. It contacts OpenRouter to verify the key and refresh model information.
The selected model determines what an approved transcription sends:
- speech-to-text sends locally extracted 16 kHz mono AAC audio in one or more chunks;
- audio-chat sends the same extracted audio plus your instruction text; or
- video-chat sends the entire original video—including picture and sound—plus your instruction text.
Audio and whole-video uploads require separate, versioned approvals. Declining approval sends no media. Withdrawing approval blocks new uploads; cancel a running queue item to stop that item. Completed transcripts remain in the local destination you selected.
OpenRouter passes the request to the third-party provider operating the selected model. Every media request asks OpenRouter to route only to providers that do not retain the data. Neocodec cannot verify that a provider honours that request. If no qualifying provider is available, Neocodec refuses the transcription instead of silently falling back. OpenRouter and the selected provider necessarily receive the approved media/request, your IP address, and ordinary request metadata and process them under their own terms and privacy policies. Neocodec does not receive or store a copy.
3. License activation and validation (Polar)
To unlock the paid version, the app sends a small amount of data to our merchant of record, Polar (api.polar.sh), when you activate a license and periodically thereafter to keep the license valid.
Data sent for activation/validation:
- your license key;
- a hashed device identifier — a one-way SHA-256 hash of your Mac's hardware identifier (
IOPlatformUUID) combined with a fixed app-specific value. The raw hardware identifier is never transmitted; the hash is used only to bind a license to a device and to count and manage how many Macs a license is activated on. We do not use it to identify you personally or to track your activity; - a non-personal device label (sent only when you activate a Mac) — your Mac's hardware model plus a short code derived from the hashed device identifier (for example, "Mac16,8 (a3f9c1)"). It is shown back to you in the customer portal so you can tell your activated Macs apart and deactivate the right one. This label does not include your Mac's name or any name you may have given it;
- your Mac's operating-system version (including its build number) and the Neocodec application version (sent when you activate), plus the basic technical details needed to complete the request. A fixed, non-personal identifier for the Neocodec product is also included so Polar can route the request; it contains no information about you.
Periodic re-validation checks send less than activation: your license key, the product identifier, the activation id, and the hashed device identifier — but not the device label, operating-system version, or app version. As with any network request, contacting Polar (api.polar.sh) necessarily discloses your device's IP address and a basic user-agent string to Polar, exactly as any web request does (the same disclosure noted for update checks in Section 4); Polar's handling of this is governed by its privacy policy, linked below.
How it is used: solely to issue, validate, count, and (when you choose) deactivate license activations, and to prevent abuse such as sharing one key across unlimited machines. The app validates your license when you activate it, each time you launch the app, about once every 24 hours while it is running, and from the command-line tool when a licensed cached verdict is at least 24 hours old. Either path refreshes the same grace period. If you are offline, both the app and command-line tool keep working for up to 14 days from the last successful validation. Neither transmits your media, file names, command arguments, or usage as part of licensing.
Polar processes this data as part of providing the licensing service. See Polar's privacy policy: https://polar.sh/legal/privacy-policy.
3A. Free-trial validation (Neocodec and Cloudflare)
The full-feature free trial lasts exactly 14 × 24 hours. No account, name, email address, license key, or payment method is required to start it. Internet access is required at the first start. While the trial is active, the app normally refreshes a signed trial lease after 24 hours; a verified lease permits up to 72 hours offline but never extends the absolute trial end.
Data sent: the app sends a SHA-256 hash derived from the Mac's hardware identifier and a fixed Neocodec-specific value, plus the Neocodec product-major number. The raw hardware identifier is never sent. The trial request does not contain media, filenames, conversion settings, usage history, an account, a license key, a device name, an email address, or payment information.
Data retained by Neocodec: before writing anything to the trial database, the service applies a secret server-side HMAC to the submitted hash. It retains only that second, server-derived pseudonymous value, an opaque trial ID, the product major, the first-seen time, and the immutable original 14-day end. If support blocks or extends a trial, the service also stores the bounded override, time, reason, and authenticated admin email, plus an append-only before/after audit record. Admin reasons must not contain a customer's name, email, license key, raw/submitted device hash, media name, or other free-form personal details. A customer can quote the opaque trial ID for support without disclosing the device hash.
How it is used: only to return the same original trial after preference deletion or an ordinary reinstall, calculate and sign a short-lived lease, prevent repeated free trials on the same device for the same product major, investigate abuse, and perform audited support actions. It is not used for advertising, behavioral analytics, cross-product tracking, or profiling.
The trial service is hosted on the Cloudflare platform. As with any network service, Cloudflare necessarily processes connection metadata such as the IP address and request time to deliver and protect the request. Neocodec does not intentionally write IP addresses, request bodies, the submitted device hash, derived ledger keys, or signed leases to application logs. See Section 7 for the retention periods and rolling-backup delay that applies when data is deleted.
4. Software updates (Sparkle)
The app uses the open-source Sparkle framework to check for and deliver updates from neocodec.com. Sparkle tells the app when a new version is available and manages the update. Like any web request, an update check necessarily shares your IP address and a basic user-agent with the host. We do not use update checks to build user profiles.
5. No accounts, analytics, or advertising — and optional local crash reporting
- The app does not require or offer an account.
- The app contains no analytics or telemetry SDK, no advertising, and no third-party tracking. There is no telemetry by default.
- Optional, opt-in crash reporting (off by default). In Settings ▸ About you can turn on "Collect crash reports on this Mac." When it is on, macOS's built-in MetricKit framework hands the app diagnostic reports (app crashes, hangs, CPU exceptions, and disk-write exceptions). These reports are:
- generated on your device by Apple's MetricKit — Neocodec adds no third-party crash-reporting SDK;
- stored only on your Mac, in
~/Library/Application Support/Neocodec/Diagnostics/(only the most recent reports are kept); and - never uploaded automatically. A report leaves your Mac only if you explicitly click "Send to Support…", which opens a pre-addressed message in your own email app with the report attached — you choose whether to send it.
- What a report contains: Apple MetricKit diagnostic JSON — program call stacks and technical metadata (such as your macOS version, the app version and build, and exception/ signal codes). It does not contain your file names, your media, or the contents of any file you converted.
- You can delete stored reports at any time from the same screen ("Delete All").
- You do not have to enable this to use the app, and turning it off stops all collection.
5a. Diagnostics you copy and send us
Separately from crash reporting above, Settings ▸ About has "Copy Diagnostics" and "Email Support…". These build a plain-text support report only when you press the button. There is no background collection, and the report never leaves your Mac unless you paste or send it. Because you send it yourself, you can read and edit it first.
Unlike the crash reports described above, this report can include the names of files you converted. Specifically it contains:
- the app version and build, your macOS version, and your Mac's architecture;
- Quick Action registration state (which Finder actions are enabled and active);
- bundled helper tool versions and checksums, and the app's own file layout;
- migration flags, update settings, and whether notifications are allowed;
- licensing state, including your license key in masked form (never in full);
- a short tail of recent conversion errors, which may include the names — but never the contents — of files you converted; and
- a recent excerpt of the app's own technical log entries (see below).
You can wipe the stored error tail at any time with "Clear recent errors" on the same screen.
Technical breadcrumbs in the macOS log. Neocodec writes technical breadcrumbs — version numbers, preset names, counts, durations, and error codes — to the standard macOS unified log, which is how Mac software records diagnostics. These are designed to contain no file names and no file contents. Note that the macOS log is shared system-wide: an administrator of your Mac can read it, which matters on a managed work Mac or a shared computer.
What we do with a report you send. We use it only to answer your request, we do not add it to any profile, and we delete it when your request is closed. We do not paste its contents into third-party services.
6. Purchases and payments (merchant of record)
Your purchase is sold and processed by Polar, acting as the merchant of record. Polar (and its underlying payment processors) collects and processes the personal and payment information needed to complete your purchase — such as your name, email address, billing/country information for tax, and payment-card details — and issues your receipt. We do not receive or store your full payment-card details. Your license key is issued and emailed to you by Polar; we may receive limited order information (such as your email address and the fact of a purchase) to provide support and manage your license entitlement. Polar's collection and use of purchase data is governed by Polar's own privacy policy: https://polar.sh/legal/privacy-policy.
7. What we store, and for how long
- Conversion media: none — never received by Neocodec-operated infrastructure (Section 2).
- Approved transcription media: sent directly to OpenRouter and the selected model provider, not stored by Neocodec. Each request asks for a non-retaining provider, but Neocodec cannot verify provider compliance; their terms and policies govern their processing (Section 2A).
- Activation records (license key, hashed machine fingerprint, activation/validation events): retained by Polar and by us for the life of the license and for 24 months afterwards, or as required for tax, refund, and anti-fraud records.
- Free-trial ledger and support/audit records: the server-derived pseudonymous device value, trial ID and timestamps, any support override, and its admin audit record are retained while that product major's free trial remains available, then deleted within 90 days after Neocodec stops offering new trials for that major. Keeping the ledger while the trial is offered is necessary to return the original end rather than granting a new trial after reinstall or local data deletion. This is not a 90-day or 365-day timer from an individual's trial start: either timer would grant the same device another trial when its row aged out. The submitted device hash itself is not retained. The authenticated operator identity appears only in internal support/audit records and follows the same retention period; the admin login address is deliberately not published in this customer-facing policy.
- Trial backups: a private, non-public Cloudflare R2 backup is made daily and configured with a 90-day object-lifecycle expiration. Cloudflare may complete lifecycle deletion within roughly 24 hours after an object's expiration. D1 Time Travel also retains a rolling recovery window of 7 days on Workers Free or 30 days on Workers Paid. Consequently, a record deleted from the live database can remain in a protected rolling backup until that backup expires, but it is not restored except for documented disaster recovery. Backup buckets have no public development URL or custom domain and are not used for analytics.
- Support correspondence: retained for 24 months after the last contact on the matter to handle your request and any follow-up.
- Update-check server logs (IP, timestamp, user-agent): retained by the update host for up to 30 days (Cloudflare operational logs) for security and operational purposes.
7A. Website contact forms
When you use a Neocodec support or privacy form, we process the name you provide, your email address, subject, and message so we can respond. Cloudflare processes network and anti-abuse information, including your IP address, to deliver the form and verify that it was submitted by a person. Support and privacy messages enter the same Zoho Desk support workflow; fixed subject prefixes distinguish privacy requests from general support.
The website does not keep a separate form-submission database. Correspondence follows the 24-month support-retention period above unless a legal hold, transaction record, active dispute, or privacy-request record requires a different period. Do not submit passwords, full licence keys, API keys, or media files.
7B. Website analytics
The Neocodec website uses Cloudflare Web Analytics and Google Analytics 4 (measurement ID G-8SZ48NN4FD) to understand which pages are visited, basic referral and campaign information, approximate device/browser characteristics, and aggregated site interactions. The website does not send conversion media, licence keys, contact-form message contents, or Mac-app activity to these analytics services.
Cloudflare processes connection information needed to provide and measure the site. Google Analytics can process the page URL, referrer, IP address and browser/device information, and may use cookies or similar identifiers according to the visitor's browser and applicable consent settings. Cloudflare's Google tag gateway may deliver the Google tag and measurement requests through a first-party path on neocodec.com; this changes the network delivery path but Google remains an analytics recipient. Analytics records are retained according to the configured Cloudflare and Google Analytics property settings. You can limit this processing using browser privacy controls, content blockers, or the controls made available by Google.
8. Your rights
Depending on where you live (for example under the Australian Privacy Act / Australian Privacy Principles, or the EU/UK GDPR), you may have rights to access, correct, delete, or restrict the processing of your personal information, and to complain to a regulator. Contact the secure privacy form at https://neocodec.com/contact/privacy with enough information for us to identify the relevant record without sending a full license key or media. We will acknowledge the request, investigate it, and respond; if you remain dissatisfied you may complain to the Office of the Australian Information Commissioner or the regulator available in your jurisdiction. For data held independently by Polar, OpenRouter, or a model provider, you may also need to contact that provider directly.
9. Children
The app has no Neocodec account and is not directed at children. Trial/licensing services process the technical identifiers described above, and optional transcription sends user-approved content to OpenRouter/model providers. We do not knowingly seek children's personal information; a parent or guardian can use https://neocodec.com/contact/privacy about a concern.
10. International transfers
Website analytics is processed by Cloudflare and Google; license-activation data is processed by Polar and its infrastructure providers; free-trial data is processed by Cloudflare and its infrastructure; and approved transcription data is processed by OpenRouter and the selected model provider. These providers may be located outside your country, including the United States, the European Union, and other locations selected by them. The exact model provider can vary with your selection and current OpenRouter routing. Where personal information is transferred internationally, the safeguards required by applicable law apply.
11. Changes to this policy
We may update this policy as the app evolves (for example, if consent-based diagnostics are introduced). We will post the updated policy at https://neocodec.com/privacy and update the effective date above.
12. Contact
George Liu, Brisbane, Queensland, Australia https://neocodec.com/contact/privacy