On this page
- The short version
- iPhone Meter, Account, and Buddy Log
- Information the app handles locally
- Local storage and security
- Mac beta access, codes, installations, seats, and offline grace
- Software update checks
- Diagnostics and support
- Exports and sidecars
- How we use information
- Disclosure, sale, sharing, and tracking
- Retention and deletion on your Mac
- Your privacy rights
- Children
- Changes to this policy
- Contact
- Website and support data
Version 1.7 — Effective August 22, 2026
Official online copy: https://filmbuddyapp.com/privacy
This Privacy Policy explains how Film Buddy LLC ("Film Buddy," "we," "us," or "our") handles information in the Film Buddy iPhone and macOS applications, the shared Film Buddy account, Buddy Log synchronization, and information you choose to send for support. The Website and support data section of the official online copy separately describes the public website's audited hosting, forms, storage technologies, and service providers.
The short version
On iPhone, the reflected-light Meter is available without creating an account or signing in. Camera preview frames are processed locally to estimate reflected light; Film Buddy does not capture, retain, or upload them. Buddy Log and Account are optional account-backed features. Buddy Log writes locally to SwiftData first and synchronizes private roll and frame records to Film Buddy's Supabase project for a signed-in account. Every confirmed Film Buddy account can use Buddy Log; Mac beta approval and Mac seats do not control iPhone or website Buddy Log access.
On Mac, Film Buddy uses an online account-and-seat gate. It sends account credentials and the limited account, installation, session, and seat information described below to Supabase to sign you in, verify approved beta access, and authorize one of the account's two current server seats. An approved beta status or valid login alone does not unlock the gated Mac interface. Film Buddy does not transmit or cloud-sync imported photographs, RAW files, filenames, paths, metadata, edits, recipes, ratings, exports, diagnostics, or editor usage activity. Core image processing and library storage occur on your Mac.
The current apps have no advertising SDK, cross-app or behavioral tracking, general-purpose third-party analytics SDK, cloud image processing, or automatic crash-reporting SDK. A bundled proprietary camera SDK may collect the limited SDK usage information described below under its provider's terms; Film Buddy does not use that information for advertising or cross-app tracking.
Film Buddy automatically checks the Film Buddy update feed for new beta versions. It does not download or install an update until you choose to do so, and it does not attach your photographs, library data, usage activity, or a system profile to the request. As with an ordinary website request, the update host may receive connection information such as an IP address, request time, and standard HTTP headers needed to deliver the feed or update file.
Optional camera tethering may communicate directly with a supported camera over USB or your local IP network through a bundled camera SDK. This is local device communication, not an upload to a Film Buddy service. A proprietary camera SDK may perform operations that Film Buddy cannot independently inspect; the app does not configure an external Film Buddy endpoint for it. Canon states that its camera SDK may collect usage information and statistics, including an IP address, SDK version, tools or services used, and how they are used, under Canon's privacy statement. Film Buddy does not receive that Canon-collected information.
If you choose a command that opens separate camera companion software, that software runs independently and is governed by its provider's own terms and privacy practices.
Film Buddy receives diagnostics, photographs, sidecars, or other attachments only when you deliberately export them and send them through a separate support channel.
iPhone Meter, Account, and Buddy Log
Features available without an account
The iPhone Meter tab does not require a Film Buddy account. It stores only device-local preferences such as film ISO, meter settings, and a calibration offset; Film Buddy does not synchronize those preferences.
The Meter requests camera access only to show the live reflected-light view. AVFoundation supplies preview and exposure information, and the App calculates estimated EV and exposure recommendations on the iPhone. It does not take a photograph, retain preview frames, perform face recognition, or send the live image to Film Buddy or Supabase. If camera permission is denied, live metering does not operate, but Account and legal controls remain available.
Account creation and access
The iPhone, Mac, and website use the same Supabase Auth identity. Anyone may create an account at filmbuddyapp.com and confirm the email address without an access code. Creating an account does not submit a beta application or place the account in a review queue. The pending account receives coming-soon information and may redeem an administrator-issued, single-use beta access code. A valid code changes the shared entitlement used for Mac beta downloads and the gated Mac app; pending or revoked accounts cannot use those Mac beta features. Existing approved beta accounts keep their approved entitlement when the seat system is introduced, but each Mac installation and authenticated session must hold one of the account's two current Mac server seats to use the gated Mac app. The account-free iPhone Meter remains available without approval or a seat, and any signed-in account can use Buddy Log without beta approval or a seat.
When a user signs in, the iPhone App sends the entered email address and password over TLS to Supabase Auth and does not persist the password. Supabase returns a user ID and rotating session credentials. The App requests the account email, optional name, role, and access status from the protected profile table. For signed-in Buddy Log, the current Auth session and user ID establish ownership; beta status and Mac seats do not participate. The Supabase iOS client stores its session in app-specific, non-synchronizing Keychain storage. The account's local Buddy Log remains available offline for that signed-in account and synchronizes when a valid connection and session are available.
On sign-out, Film Buddy removes the local iPhone session and locks account-backed features. Signing out does not delete the account or local Buddy Log data and does not release or alter any Mac beta seat.
Information stored on the iPhone
Depending on the features used, the iPhone App can store:
- account ID, email, optional name, role, Mac beta-access status for display, and the Keychain session used for account-backed features;
- roll details such as film stock, rated ISO, camera, lens, format, status, load and finish dates, development notes, and general notes;
- frame details such as frame number, aperture, shutter, meter EV, exposure compensation, focal length, capture time, notes, tags, and favorite state;
- client-generated IDs, ownership IDs, timestamps, deletion tombstones, and synchronization state used for safe offline merging;
- meter preferences and device-specific calibration; and
- cached catalog suggestions and ordinary app preferences.
The current mobile app does not request Location Services and does not populate or transmit the latitude and longitude fields reserved in its data model. Film Buddy will update the permission prompt, App Privacy disclosure, privacy manifest, and this Policy before enabling location capture.
Buddy Log synchronization and catalog searches
Buddy Log is an optional account-backed, offline-first roll and frame notebook. For any signed-in Film Buddy account, it synchronizes that account's private roll and frame records to Supabase, including the roll, gear, exposure, timing, note, tag, favorite, development, catalog-reference, timestamp, deletion, and version fields described above. The App writes to SwiftData before attempting transfer; a failed sync does not erase local Buddy Log data.
Cloud Buddy Log tables use authenticated user IDs, foreign keys, and ownership-scoped row-level security. The iPhone App contains only the public publishable key, never a secret or service-role key. Deleted records can remain as synchronization tombstones until processed, and operational backups can remain for a limited disaster-recovery rotation period.
Camera, lens, and film-stock search text can be sent to Supabase catalog-search functions with ordinary connection information and, when signed in, the current session context. Catalog selections allow a custom fallback. A custom Buddy Log value remains private user content and does not become a public catalog entry.
iPhone service providers, purchases, retention, and deletion
Supabase and its infrastructure subprocessors process authentication, session, profile, catalog-query, Buddy Log, security-log, and connection information. Apple may independently process App Store downloads, purchases, diagnostics, and analytics under Apple's terms and the user's settings. Film Buddy offers the mobile App as a free App Store download. Optional Apple In-App Purchases may be added later, but no purchase is currently required to use the account-free Meter. If optional paid features are offered, Apple processes the transaction and supplies transaction and entitlement information; Film Buddy does not receive the full payment-card number.
Local Meter preferences remain until changed, reset, or removed with the App. Local Buddy Log records remain until deleted in the App, removed through account deletion, or removed with the App. Cloud account and Buddy Log records remain while the account is active, subject to the other retention terms here.
An authenticated non-administrator customer can choose Film Buddy account website → Settings → Delete account and online data or Film Buddy iPhone app → Account → Delete Account and Buddy Log. After password or session verification and typed confirmation, the selected flow calls an authenticated server function that derives the customer ID from the bearer session and never accepts an arbitrary target user ID or privileged key. Successful deletion permanently removes the Auth account, profile, sessions, associated cloud Buddy Log rows, beta-code attempt-window row, and account-linked installation and seat records. Access-control and agreement records are removed or de-identified through the same deletion process except for the narrowly required security, agreement, legal, or rotated-backup records described below. The iPhone flow then removes that account's local session, access record, rolls, and frames from that iPhone; the website cannot erase data stored only on another device. The action cannot be undone. Ordinary customers do not need to email support or file a ticket.
Administrator accounts are refused by this customer flow and may require separate transfer and retention procedures for immutable release and security audit records. Narrowly required fraud-prevention, security, agreement, legal, or rotated backup records may remain where permitted. These procedures do not limit customer account deletion.
Information the app handles locally
To provide the features you request, Film Buddy may read, generate, and store the following on your Mac:
- photographs and camera RAW or TIFF files you select, drop, or capture into a tether folder;
- source filenames and absolute paths, file size and modification date, file type, orientation and other decode metadata, and local file fingerprints;
- roll and session names, local image and job identifiers, frame numbers, ratings, color labels, favorites, and trash state;
- develop recipes, crops, rotations, film-base samples, color measurements, conversion and calibration data, approvals, and export history;
- generated previews, decoded or normalized working files, histograms, analysis files, and regenerable render caches;
- app preferences, cache-location choices, performance information, and local event or system logs;
- a device-only account session and cached seat lease, cached account identity and entitlement, a persistent random installation UUID, the current Auth session binding, reported platform, device label, app version and build, operating-system version, seat number and generation, access-check time, offline-access fence, and the account identifier to which the local library is bound; and
- for optional tethering, a camera model, connection type, SDK device identifier, command state, and capture destination. For a camera connected by local IP, the SDK identifier may be derived from the camera's MAC address.
These are operational identifiers used inside your local library. Film Buddy does not use them as advertising identifiers or to track you across apps or websites.
The app does not request access to Contacts, Calendars, Location Services, the microphone, or the Mac's webcam. Tethered-camera access is separate from webcam access. Film Buddy uses the files, folders, and connected camera you choose for the requested import, edit, export, cache, diagnostics, or tether operation.
Local storage and security
The default library location is:
~/Library/Application Support/Film Buddy/FilmBuddyLibrary
You can choose a different location for regenerable cache files. Originals may remain at the external paths you selected because Film Buddy currently references originals instead of copying them into the library.
Catalogs, recipes, logs, previews, decoded files, exports, and sidecars are ordinary local files and are not encrypted by Film Buddy. Their protection depends on macOS file permissions and security features you enable, such as device login security and disk encryption. No storage or transmission method can be guaranteed completely secure.
Mac beta access, codes, installations, seats, and offline grace
When you sign in on Mac, the app sends the email address and password you enter over an encrypted TLS connection to Supabase Auth. The app does not save your password. Supabase returns a user UUID, email address, optional name, and rotating access and refresh tokens. The app then checks the account's role, beta-access status, approval time, and current seat assignment.
A valid login or approved beta status alone does not unlock the gated Mac app. The current Mac installation and authenticated session must also hold one of the account's two current Mac server seats. The iPhone app, Buddy Log, the Film Buddy account website, and the act of downloading an updated Mac beta do not consume a seat. Administrator accounts use the same Mac seat limit. Existing approved beta accounts remain approved and eligible to claim either Mac seat when the seat system is introduced.
Installation and seat information
When the Mac app requests or checks a seat, Film Buddy sends a random installation UUID, platform, a device label reported by the operating system or app, Film Buddy app version and build, operating-system version, and the current authenticated session context to Supabase. The reported device label may be generic. The account owner may supply a separate optional custom label. The server derives the account and Auth session identifier from the signed request; a device label, custom label, or installation identifier alone does not authorize access.
The random installation UUID is generated for that Film Buddy installation. It is not a hardware fingerprint, Apple advertising identifier, or cross-app tracking identifier. It is stored separately from the account session in a non-synchronizing, device-only Keychain item and ordinarily remains on the installation after sign-out so the same installation can be recognized when an account signs in again.
Film Buddy stores the account-linked installation record; the reported device label and optional custom label; reported platform, app version and build, and operating-system version; current Auth session binding; current and historical seat number, assignment, and generation; activation, last-check, deactivation, archive, restore, and replacement information; and successful access-control audit events. Film Buddy retains seat and device audit history so a later assignment cannot be mistaken for an earlier one.
Database constraints and serialized account changes enforce no more than two active server seats for an account at a time. An account can use Film Buddy's controls to review, rename, disable, re-enable, archive, restore, or replace a saved installation. A stale browser action must match the current assignment generation before it can change that assignment. The account may retain up to 32 unarchived installation identities and 256 lifetime installation identities as abuse and operational-safety limits.
Inactive installations may be archived to free saved-device space. Archiving is not deletion: Film Buddy retains the installation row and its seat and audit history so later assignments keep the correct meaning. These device, seat, and access-event records are retained while the account exists and are removed or de-identified through ordinary customer account deletion, subject to narrowly required security, agreement, legal, and rotated-backup records that may remain for a permitted period. Film Buddy does not delete or rewrite existing seat history merely because a seat is switched to another installation.
If the exact Supabase Auth session bound to a seat no longer exists, Film Buddy may deactivate that assignment during a later serialized seat operation. It does not deactivate a seat merely because an access token expired, a device has not checked in recently, or the device is offline. The account owner can disable or replace a seat through the website when a device or session is unavailable.
Access codes and failed-attempt controls
New beta codes contain 80 random bits displayed as 16 Crockford Base32 symbols,
typically grouped as FB-XXXX-XXXX-XXXX-XXXX. Legacy codes remain accepted so
an unused code is not destroyed by the format change. Film Buddy normalizes and
hashes the entered code and stores only its SHA-256 digest, together with
ordinary code issuance, intended-email restriction, expiry, redemption, and
revocation records. The plaintext is displayed only when an administrator
generates the code and is not recoverable from the admin page after refresh.
For failed access-code attempts, Film Buddy stores one private, bounded per-account attempt-window row containing the window start, count, most recent attempt time, and any temporary block-until time. It does not store the plaintext attempted code. Expected failures receive a generic result so the response does not reveal whether a particular code exists. The attempt-window row is removed through account deletion subject to the narrow exceptions described in this Policy.
Cached seat lease and offline overlap
The seat-aware Mac app uses a seven-day (168-hour) cached account-and-seat lease and reevaluate it on lifecycle and gated-access events. The lease is bound to the account, installation UUID, Auth session, device, assignment, seat number, and assignment generation. An online server seat is made available immediately when disabled or replaced, but a deactivated or replaced installation that is already offline may temporarily keep cached local access. Local app use can therefore temporarily overlap the account's two current server assignments until the offline installation reconnects or its seven-day (168-hour) lease expires.
Film Buddy keeps a non-secret, installation-wide wall-clock high-water mark and offline-access fence outside the account session. A backward, corrupt, or regressing clock observation fails closed and remains fenced until a fresh online account-and-seat check succeeds. While the app remains running, a continuous system clock that includes sleep prevents a frozen wall clock from extending the lease. These measures limit casual rollback attempts but do not promise perfect remote enforcement on a device whose owner controls the operating system, local storage, executable, clock, and network connection while it remains offline.
On sign-out, Film Buddy first asks the server to deactivate the seat bound to the current authenticated session, then removes the local account session and cached lease even if the network request cannot be confirmed. The account website remains available to disable or replace the seat. Sign-out does not delete the random installation identity, local library, server-side account, Buddy Log stored on another device, or server-side device, seat, or audit history.
Version 1.7 notice and agreement records
Film Buddy will provide notice of version 1.7 by publishing the current Privacy Policy and Terms & EULA on the website, including them in the native Legal Center, and identifying the camera-tethering and camera-SDK changes in the applicable Mac release information. Version 1.7 does not add a separate native click-through or acceptance record. The website download flow requires acceptance of the then-current EULA and records its version, effective date, checksum, account, build, and acceptance time when a gated Mac download is issued.
Authentication, seat, and entitlement requests do not contain photographs, library or image identifiers, filenames, file paths, recipes, ratings, edits, exports, diagnostics, or editor usage activity. Like other Internet requests, they disclose an IP address, request time, user-agent string, and ordinary transport headers to Supabase and its infrastructure. Supabase may retain those details in account, session, security, and authentication audit logs.
Software update checks
While Film Buddy is running, it periodically requests the signed beta update
feed at https://filmbuddyapp.com/updates/beta/appcast.xml. The app also lets
you start a check from the application menu. If an update is available, Film
Buddy shows its version and release notes and waits for you to choose whether
and when to download, install, and relaunch.
Update requests do not include photographs, filenames, library identifiers, recipes, diagnostics, usage analytics, or the optional Sparkle system-profile parameters. Automatic update download and installation are disabled. The update host and its infrastructure providers may process an IP address, request timestamp, requested file, and ordinary HTTP headers for delivery, security, abuse prevention, and operational logs. Their applicable retention and provider details are published with the website disclosures in the online copy of this policy.
The app stores update preferences and update-check timing in the local macOS
preferences domain for com.filmbuddy.app. You can postpone or skip an offered
beta version. Disabling network access prevents update checks but does not
change the local image-processing pipeline. It can prevent account verification
and therefore block the app after the seven-day (168-hour) offline grace period.
Diagnostics and support
Film Buddy writes local event logs and uses Apple's local unified logging and performance-signpost systems. Log entries can include image identifiers, filenames, absolute file paths, export activity, settings hashes, timing data, and error messages.
From Preferences, you can create a diagnostics ZIP in a location you choose. The ZIP contains the app's local logs and a text file with the generation time, app version, macOS version, and Mac chip model. Creating the ZIP does not send it anywhere. Review it before sharing because filenames and paths can reveal a Mac account name, folder layout, project names, or other personal information.
If you contact support, we may receive your contact details, message, and any files you voluntarily attach. We use that information to respond, troubleshoot, protect the service, and keep an appropriate support record. Support messages are retained for 30 days after receipt. Diagnostic archives and other technical attachments are retained for 90 days after receipt, then deleted or de-identified unless a longer period is required to resolve the matter, protect legal rights, or comply with law.
Providing support information is optional. Without a usable reply address and enough detail to understand the problem, we may be unable to respond or resolve it.
Support processing is mapped as follows:
- Contact details and communications come directly from you; they are used to respond and administer the support relationship under contract or pre-contract steps and our legitimate interest in reliable support. They are available to authorized Film Buddy personnel and Google Workspace and its subprocessors, and retained for 30 days after receipt.
- Technical attachments and diagnostics come directly from files you choose to send; they are used to reproduce, secure, and fix the reported issue under contract and our legitimate interest in product security and reliability. They are available to the same authorized recipients and retained for 90 days after receipt.
- Support processing may occur in the United States and other countries where Google Workspace and its disclosed subprocessors operate. Where a legally recognized transfer safeguard is required, Google Workspace's applicable data-processing terms and Standard Contractual Clauses, or another legally recognized transfer mechanism, apply.
Do not send photographs, diagnostics, or sidecars that you are not authorized to share. Remove sensitive files or information that support does not need.
Exports and sidecars
Film Buddy does not intentionally copy source EXIF, IPTC, or GPS metadata into the exported TIFF or JPEG. Every export contains output information such as an ICC color profile, and no software can promise that a file contains no metadata of any kind.
Optional export sidecars are enabled by default and are named after the full
export filename with .filmbuddy.json appended. A sidecar can contain the local
image ID, a source-file hash, absolute source and export paths, recipe and
render settings, crop and analysis values, output details, and export history.
Sharing a sidecar can therefore reveal a Mac username, folder layout, edit
history, and a persistent fingerprint of the source file. Disable the sidecar
option before export, or inspect and redact the JSON, when you do not want to
share that information.
How we use information
Local information is used only on your Mac to perform the app functions you request, maintain your library and preferences, render previews and exports, verify outputs, communicate with a local camera, and diagnose local errors. Film Buddy does not receive or control that local information.
Account, Mac installation, session, seat, code-attempt, and access-audit information is used to authenticate you, verify approved Mac beta access, authorize and manage the account's two current Mac server seats, bind the local library to the correct account on that macOS user, restore the same account session and installation, provide the seven-day (168-hour) cached seat lease, secure the account service, prevent abuse, support account owners, resolve access problems, and show limited account and device status in the app and account portal. It is not used for advertising, cross-context behavioral advertising, analytics, profiling, or tracking across other companies' apps or websites. We process it to provide the App and account relationship you request and for our legitimate interests in preventing unauthorized access and abuse.
The separate update request is used to determine whether a newer signed Film Buddy release exists and, only after your choice, to deliver that release. It is not used for advertising, profiling, analytics, or tracking.
If you voluntarily contact us, we process the information we receive to:
- perform our contract with you or take steps you request before a contract, including providing support;
- pursue our legitimate interests in securing, debugging, and improving Film Buddy without overriding your rights; and
- comply with legal obligations or establish, exercise, or defend legal claims.
We do not use automated decision-making that produces legal or similarly significant effects about you. Film Buddy's deterministic image-analysis tools do not perform face recognition or biometric identification. Local approval and calibration records are not transmitted for model training.
Disclosure, sale, sharing, and tracking
The app does not automatically disclose local library content to us, data brokers, advertisers, or analytics providers. We do not sell personal information, share it for cross-context behavioral advertising, or track app users across third-party apps or websites.
Local processing may involve Apple operating-system frameworks and bundled decode or camera components identified in Third-Party Notices. They operate as part of the local app workflow. As disclosed above, Canon states that its camera SDK may separately collect limited SDK usage information and statistics; Film Buddy does not receive that information. The support providers named above are required to protect support information consistently with this policy and applicable law.
Supabase processes account credentials, user identity and profile fields, sessions, entitlement and seat requests, installation and reported device information, failed-code attempt windows, access-control audit events, and related connection and authentication-log information for Film Buddy. We do not permit Supabase to use Film Buddy account information for advertising or cross-context behavioral tracking. Account processing may occur where Supabase and its subprocessors operate, subject to the applicable data-processing and transfer terms described in the online provider inventory.
Apple may independently process App Store purchases, downloads, crash reports, or app analytics under your device and App Store settings. Apple controls that processing; consult Apple's privacy information and your device settings. We will update this policy if we enable receipt of Apple-provided diagnostic or analytics reports.
We may disclose support information if reasonably necessary to comply with law, protect rights or safety, investigate abuse, complete a corporate transaction subject to appropriate safeguards, or work with a provider that helps us deliver support, including the providers identified in the support-processing section above.
Retention and deletion on your Mac
Local library data remains until you remove it. Moving a frame to Film Buddy's Trash marks it as trashed but does not erase it. Removing a frame from the library deletes Film Buddy's catalog rows, recipes, analysis, previews, and cache for that frame while preserving the referenced original. Clearing the cache deletes regenerable previews and decoded masters. For film negatives it also deletes saved develop-recipe rows and recipe sidecars, negative analysis, film-base and manual-base defaults, and resets every film-negative frame to Import. White balance, crop, Convert, and saved edits for those negatives must then be redone. It does not delete referenced originals or external exports.
Regenerable preview and decode caches may also be evicted automatically when configured memory, disk, or cache budgets require it. Other source-of-truth catalog data remains until you remove it or delete the library, subject to the destructive Clear Cache behavior described above.
Exports, sidecars, diagnostics ZIPs, macOS unified logs, preferences, and files outside the library must be removed separately. Uninstalling the app may leave Application Support data and preferences behind. See the bundled Local Data & Diagnostics Guide for exact locations and deletion steps.
Signing out immediately locks Film Buddy on this Mac, asks the server to deactivate the seat bound to the current authenticated session, and clears the local account session and cached seat lease. If the request cannot be confirmed, the account website remains available to disable or replace the seat. This local action does not guarantee immediate provider-side session invalidation. It does not delete the random installation identity, server-side account, device, seat, agreement, or audit records, the local library, backups, exports, or the library's binding to the first approved account. Removing the app or deleting its preferences does not by itself guarantee removal of Keychain items.
Online account, profile, entitlement, session, installation, seat, failed-code attempt-window, access-audit, agreement, and security records are retained for as long as needed to provide and secure the account, preserve assignment history, satisfy applicable recordkeeping or legal requirements, and resolve disputes. Authentication audit records may include IP address and user agent. Ordinary customers delete the shared online account and cloud Buddy Log through the account website or the Film Buddy iPhone app as described above; the privacy contact remains available for other rights requests. Some security, fraud-prevention, legal, or backup records may remain for a permitted period after closure.
Because we cannot access your local library, a privacy request sent to us cannot retrieve or erase data that never left your Mac. You control that data with the app, Finder, your backups, and macOS account tools.
Your privacy rights
Depending on where you live and whether we hold account or support information about you, you may have rights to request access, correction, deletion, restriction, portability, or an objection; to withdraw consent where consent is the basis; and to complain to your local data-protection authority. California residents may also have rights to know, correct, or delete covered information and to be free from discrimination for exercising privacy rights. We do not sell or share covered personal information for behavioral advertising.
Submit a request to hello@filmbuddyapp.com. We may need proportionate information to verify the request. These rights can be limited by applicable law. If we do not hold information about you, we will say so.
International account and support transfers use the providers and safeguards identified above and in the online provider inventory.
Children
Film Buddy is a general-audience creative tool and is not directed to children under 13. The app does not send local image content to us. We do not knowingly allow children under 13 to create Film Buddy accounts or knowingly collect their personal information online. If we learn that a child submitted personal information through an account, support, or the website, we will delete it as required and may ask a parent or guardian to contact us.
Changes to this policy
We may update this policy to reflect a changed app, website, law, or service provider. We will change the effective date, publish the current version on the Film Buddy privacy page, and provide additional notice when required. Material changes will not retroactively reduce your rights without a valid legal basis.
Contact
- Controller: Film Buddy LLC
- Privacy: hello@filmbuddyapp.com
- Support: hello@filmbuddyapp.com
- Website: https://filmbuddyapp.com
Website and support data
This section covers information that Film Buddy LLC receives through
https://filmbuddyapp.com, historical early-access waitlist and beta-application
records, beta accounts, beta-code redemption, native installation and seat
management, beta downloads, and support. Film Buddy no longer accepts waitlist
submissions or beta-access applications. The former submission endpoint is
retired, and creating a Film Buddy ID does not place an account into a review
queue. Pending accounts receive coming-soon information and can redeem a valid
beta access code. It is separate from the app data described above: Film
Buddy cannot see a local Film Buddy library, photographs, recipes, or exports
unless you deliberately send material through a separate support channel.
The current invitation-only beta is offered and targeted only in the United States. It is not offered or targeted to users in the European Union or United Kingdom.
Website delivery and request logs
The website is a Next.js site deployed on Vercel. Production server functions
are configured for Vercel's iad1 region. GoDaddy provides authoritative DNS,
and the deployed site uses a Let's Encrypt TLS certificate. When a browser
requests a page or asset, Vercel and the site's delivery infrastructure
necessarily receive request information such as the IP address, date and time,
requested URL, response status, referrer when supplied, and browser or device
headers.
Film Buddy uses this information to deliver the site, maintain availability,
diagnose errors, and protect the site from abuse. The EU/UK legal basis is Film
Buddy's legitimate interest in operating and securing the website.
Vercel is the hosting, deployment, edge-delivery, and request-log provider; GoDaddy is the DNS provider. The current Vercel Pro plan retains runtime logs for one day. Build logs remain attached to deployments for the project's configured or otherwise applicable deployment-retention period. Film Buddy has not configured a separate log drain or backup archive. Vercel's primary processing facilities are in the United States, while Vercel and its subprocessors may process data in the United States and other countries where they operate. Where an international transfer safeguard is required, Vercel's applicable terms provide the EU Standard Contractual Clauses and UK transfer terms. See Vercel's runtime-log retention documentation and Data Processing Addendum.
Retired early-access waitlist and beta applications
Film Buddy no longer accepts waitlist submissions or beta-access applications. Before intake was retired, the early-access form asked for name, email address, scanning workflow, source format, approximate monthly roll volume, an optional note, and an affirmative choice to receive early-access updates. A submission also recorded its time, the page referrer when the browser supplied one, browser user-agent string, and an internal status. A hidden anti-spam field could be evaluated and discarded.
The former waitlist endpoint required same-origin browser submissions, limited request size, and applied a best-effort bound of five attempts per ten minutes on each running server instance. For that bound, it held only an HMAC-SHA256 digest of the forwarded IP address in ephemeral process memory for the remainder of the ten-minute window; this code did not persist the raw IP or send that digest to the Google Sheet. Because Vercel could run multiple instances, the bound was not a global rate-limit guarantee. Normal hosting request logs remain governed by the separate Vercel disclosure above.
The production website sent accepted submissions from Vercel through a private
Google Apps Script endpoint into the Film Buddy Waitlist Google Sheet. That
linkage was operationally verified from accepted submissions originating at
filmbuddyapp.com. Film Buddy used those submissions to manage early access,
understand whether the beta fit the requested workflow, and send requested
updates. The EU/UK legal bases were consent for requested email updates and Film
Buddy's legitimate interest in administering the beta. A person may withdraw
from remaining requested updates at any time by emailing
hello@filmbuddyapp.com.
Closing the forms did not erase historical waitlist or application records. Those records remain subject to the same approved retention and deletion rules: until 12 months after the person's last interaction with Film Buddy or the end of the beta, whichever is later, unless the person requests earlier deletion where applicable. Google remains the Apps Script and Sheets provider for the historical records. Google may store or process data in the United States and other countries where Google or its subprocessors maintain facilities. Google's applicable Cloud Data Processing Addendum provides the EU Standard Contractual Clauses and other legally recognized transfer mechanisms where required.
Beta accounts, access codes, and downloads
Supabase provides authentication, database, and private build storage for the
beta portal from a primary project region in U.S. West (us-west-2). Account
records include an email address, optional name, Supabase user identifier,
account and update timestamps, role, beta status, and beta approval metadata.
Supabase handles password credentials and authentication email flows and may
retain authentication-session IP address and user-agent information in its
Auth systems. Supabase Auth sends account-confirmation and password-reset
messages through Resend SMTP, operated by Plus Five Five, Inc. The verified
filmbuddyapp.com sending domain uses Resend's North Virginia (us-east-1)
region. Resend stores account data, email metadata, logs, and API records in the
United States and documents a 30-day email-data retention period for standard
plans. Open and click tracking are disabled for the domain. Film Buddy has not
configured Resend receiving, templates, or webhooks. Resend's Data Processing
Addendum, Privacy
Policy, and region
documentation describe its
processing, subprocessors, and applicable transfer safeguards.
Anyone may create a Film Buddy ID and confirm an email address without a beta access code while registration is available. Creating an account does not submit a beta application or place the account in a review queue. The account remains pending for Mac beta access and receives coming-soon information, but can use account-backed Buddy Log. An approved account can access Mac downloads and build information without consuming a seat; the Mac app requires a current Mac server seat. The iPhone app, Buddy Log, website, and downloads do not consume seats.
New beta codes contain 80 random bits displayed as 16 Crockford Base32 symbols,
typically grouped as FB-XXXX-XXXX-XXXX-XXXX. Legacy codes remain accepted so
an unused code is not destroyed by the format change. Film Buddy stores only a
SHA-256 digest of each normalized code, never the plaintext, together with an
optional admin label, optional lowercased intended-email restriction, optional
expiration, creation time and administrator identifier, and any use or
revocation time and user or administrator identifier. The account action
normalizes and hashes a submitted code before sending it to Supabase. The
database redeems it atomically and records which code granted the shared beta
entitlement. Expected failures receive a generic result that does not reveal
whether a code exists. The plaintext is shown once to the generating
administrator and is not recoverable from the admin page after refresh.
For failed access-code attempts, Supabase stores one private bounded attempt-window row per account, including the window start, count, most recent attempt time, and any temporary block-until time. The row does not store the plaintext attempted code and is not exposed through the browser Data API. It is used only to slow guessing and protect beta access. Successful code redemption and seat mutations append the access-control events described in the Film Buddy Privacy Policy.
Mac installations, seats, and account-portal controls
The Film Buddy server authorizes no more than two active Mac server seats for an approved beta account. The iPhone app, Buddy Log, account website, and the act of downloading an updated Mac beta do not consume a seat. Administrator accounts use the same Mac server seat limit. Existing approved beta accounts keep their approved status when the seat system is introduced, but a valid login or approved status alone does not unlock the gated Mac app: the current Mac installation and authenticated session must also hold a seat.
When the Mac app requests or checks a seat, it sends a random installation UUID, platform, a device label reported by the operating system or app, Film Buddy app version and build, operating-system version, and current authenticated session context. The reported device label may be generic. The account owner may supply a separate optional custom label. The server derives the account and private Auth session identifier from the signed request; a device label, custom label, or installation identifier alone does not authorize access. The random installation UUID is not a hardware fingerprint, Apple advertising identifier, or cross-app tracking identifier.
Supabase stores the account-linked installation row; reported and optional custom labels; platform, app version and build, and operating-system version; private Auth session binding; current and historical seat number, assignment, and generation; activation, last-check, deactivation, archive, restore, and replacement information; and successful access-control audit events. The account may retain up to 32 unarchived installation identities and 256 lifetime installation identities as abuse and operational-safety limits.
The account portal lets the account owner review, rename, disable, re-enable, archive, restore, or replace saved installations and the two current server seats. Portal lists are bounded and paginated. Seat changes use account locks and assignment-generation checks so an old browser tab cannot silently change a newer assignment. The website never displays a seat's private Auth session identifier or an access-code digest.
Archiving an inactive installation frees saved-device space but is not deletion. Film Buddy retains the installation row and its seat and audit history so later assignments continue to have the correct meaning. These device, seat, and access-event records remain while the account exists and are removed or de-identified through ordinary account deletion, subject to narrowly required security, agreement, legal, and rotated-backup records that may remain for a permitted period.
If the exact Supabase Auth session bound to a seat no longer exists, Film Buddy may deactivate that assignment during a later serialized seat operation. It does not deactivate a seat merely because an access token expired, a device has not checked in recently, or the device is offline. An account owner can disable or replace a seat through the website if a device or session is unavailable.
The seat-aware Mac app uses a seven-day (168-hour) cached account-and-seat lease. A disabled or replaced seat is available on the server immediately, but an already offline installation may temporarily continue using its cached lease. Local app use can therefore temporarily overlap the two current server assignments until the offline Mac installation reconnects or its seven-day (168-hour) lease expires.
Every authenticated account may use its private Buddy Log. For the Buddy Log
summary and insert-only frame-note form, the
server-only website module derives requireUser().user.id and passes only that
exact ID to narrowly scoped broker functions using the server-only service
credential. The broker returns bounded pages of the exact target account's
non-deleted rolls and frames and rejects a frame insert when the selected
non-deleted roll does not belong to that target account. The service credential
is never sent to the browser, and browser portal use does not claim a native
seat.
Cloudflare Turnstile protects signup, sign-in, password-reset, and destructive
account actions from automated abuse. The managed widget loads code and an
iframe from challenges.cloudflare.com, evaluates browser and interaction
signals, and produces a short-lived, single-use token. Film Buddy's
Vercel-hosted server sends that token directly to Cloudflare's Siteverify API
and requires a successful result bound to the expected form action and an
approved website hostname before continuing.
For account creation only, a successful check causes the website server to generate a random 256-bit, email-bound authorization. Supabase stores its SHA-256 digest, the lowercased email address, creation time, and five-minute expiration; it does not store the plaintext authorization in that table. The plaintext is passed once with the immediately following Auth signup request. The database consumes the matching authorization atomically and removes both it and any legacy signup access-code hash from Auth user and identity metadata. Unused authorizations expire after five minutes and are removed on use, after a failed request when possible, or during later signup housekeeping.
Film Buddy does not use Turnstile for advertising or product analytics and does not enable Turnstile pre-clearance. Cloudflare may process the visitor's IP address, browser and device signals, challenge outcome, token, request time, and ordinary connection information under its Turnstile Privacy Addendum. Turnstile analytics retain aggregate challenge information according to Cloudflare's service settings.
The portal records allowed and denied download attempts with the user identifier, event type and time, IP address, browser user-agent string, and limited details such as a denial reason. It includes the build identifier when a candidate build has been identified. Before an allowed download, it also records App EULA acceptance, including the EULA version and effective date and checksum; the user and build identifiers; the build version, filename, storage path, byte size, and SHA-256 checksum; the timestamp and transaction identifier; the Storage object and version identifiers; the IP address; and the browser user-agent string.
Film Buddy will provide notice of version 1.7 by publishing the current Privacy Policy and Terms & EULA on the website, including them in the native Legal Center, and identifying the camera-tethering and camera-SDK changes in applicable app release information. Version 1.7 does not add a separate native click-through or acceptance record. The website download flow requires acceptance of the then-current EULA and records the applicable agreement metadata. The app file remains in a private Supabase Storage bucket and an approved account receives a short-lived signed download URL only while those immutable object identifiers still match.
Film Buddy uses account, entitlement, code-attempt, installation, seat, access-audit, EULA-acceptance, and download records to authenticate users, administer and secure Mac beta access, enforce the two-current-Mac-seat limit, support account owners, resolve access problems, deliver requested builds, document the applicable agreement, investigate abuse, and maintain appropriate access and release records. It does not use installation, seat, session, code-attempt, or audit information for advertising, cross-context behavioral advertising, analytics, profiling, or tracking across other companies' apps or websites. The EU/UK legal bases are contract or steps taken at the user's request before contract, compliance with legal obligations where applicable, and Film Buddy's legitimate interests in access control, software security, and agreement records.
Account, entitlement, installation, seat, and access-event records are retained
while the account is active. Inactive installation archiving does not erase seat
or device audit history. After an account-deletion request, the Auth account,
profile, sessions, Buddy Log rows, beta-code attempt-window row, and
account-linked installation and seat records are deleted or de-identified
through the customer deletion process. Ordinary residual account information is
deleted within 30 days, except for narrowly required security, agreement, legal,
or rotated-backup records governed by a longer permitted period. Access-code
records are retained for 12 months after the code is used, expires, or is
revoked. EULA-acceptance and download-event records are retained for three years
after the associated beta download or account closure, whichever is later. Supabase is the
authentication, database, and storage provider. The Film Buddy project and its
database are hosted in AWS U.S. West (Oregon), us-west-2. Supabase and its
infrastructure and support subprocessors may also process limited service data
in the United States and other countries where they operate. Where required,
Supabase's Data Processing Addendum provides the EU Standard Contractual
Clauses, UK transfer terms, and other applicable lawful transfer mechanisms.
Native app update delivery
Film Buddy for macOS checks the public, signed beta update feed at
https://filmbuddyapp.com/updates/beta/appcast.xml. Automatic download and
installation are disabled. A check requests the feed only; it does not send
photographs, filenames, library data or identifiers, recipes, diagnostics,
usage analytics, or Sparkle's optional system-profile parameters. If a person
chooses an offered update, the app separately requests the versioned ZIP and
release-notes files identified by that signed feed.
Update delivery is public and separate from beta account access. It does not
require an access code, account, authentication cookie, or expiring signed
Storage URL. Vercel serves the stable website paths and the small appcast
route. Immutable versioned files are stored and delivered through Supabase
Storage. The audited Supabase organization is on the Pro plan, its project and
Storage origin are in AWS U.S. West (Oregon), us-west-2, and Supabase's edge
request logs include Cloudflare delivery metadata. Vercel, Supabase, Amazon Web
Services, and Cloudflare therefore participate in the hosting, storage, or
edge-delivery chain for these requests.
The public update paths do not require a cookie. Supabase's Cloudflare delivery
edge may nevertheless return a short-lived __cf_bm bot-management cookie on
a Storage response. It is an infrastructure security control, not a Film Buddy
account, advertising, or analytics identifier, and the feed and files remain
publicly retrievable when a client presents no cookie.
Ordinary delivery and security logs may contain the IP address, request time, requested file, response status, and standard HTTP headers such as user agent, referrer when supplied, range, host, and forwarding headers. Film Buddy uses that information only to deliver updates, diagnose failures, protect the download service, and investigate abuse. It is not used for advertising, profiling, product analytics, or cross-site tracking.
The current Vercel Pro plan retains runtime logs for the appcast function for one day. The current Supabase Pro plan retains API and Storage logs for seven days. Film Buddy has not added an update-specific log archive or analytics system. Signed appcasts, versioned update artifacts, hashes, and administrator publication records are release-integrity records rather than usage analytics; the immutable release files are retained for the duration of distribution so installed copies can verify and retrieve the release they were offered.
Support and privacy requests
The public website does not currently provide a support upload or contact form. Domain mail records route the support mailbox through Google. If you email Film Buddy, we receive the reply address, message, email-routing metadata, and anything you choose to attach. Do not send photographs, diagnostics, sidecars, credentials, or other sensitive material unless it is necessary and you are authorized to share it. Creating a diagnostics ZIP in Film Buddy does not upload it.
Support messages are retained for 30 days after receipt; diagnostics and technical attachments are retained for 90 days after receipt. Google Workspace and its subprocessors provide the support mailbox. Processing occurs in the United States and other countries where Google Workspace and its disclosed subprocessors operate. Transfers use Google Workspace's applicable data-processing terms and Standard Contractual Clauses, or another legally recognized transfer mechanism.
Film Buddy cannot retrieve, correct, or erase a Film Buddy library that never left a user's Mac. A request can cover only the website, account, historical waitlist or application, beta-code, installation, seat, access-audit, download, EULA, or support information Film Buddy and its providers actually hold.
Audited website provider inventory
| Function | Provider or technology | Verified status | Unresolved publication facts |
|---|---|---|---|
| Hosting, deployment, CDN, request logs | Vercel | Project and deployment verified; Pro plan confirmed; Pro runtime logs retained one day; build logs remain attached to deployments for configured or applicable retention; no Film Buddy log drain or backup archive | U.S. primary processing with subprocessors in other operating countries; applicable SCC and UK transfer terms |
| DNS | GoDaddy | Authoritative DNS verified | Provider retention and subprocessors |
| TLS certificate | Let's Encrypt | Deployed certificate verified | Not used as a marketing or analytics service |
| Authentication, database, private build storage, public update storage and CDN | Supabase, with AWS U.S. West (us-west-2) origin infrastructure and Cloudflare edge metadata | Healthy Pro-plan project verified; API and Storage logs retained seven days; public update files require no account or signed URL | U.S. primary hosting with limited processing by subprocessors elsewhere; applicable SCC and UK transfer terms |
| Native beta update routing and appcast delivery | Vercel | Stable filmbuddyapp.com routes; Pro appcast-function logs retained one day; no update analytics or update-specific archive | Vercel subprocessors may process requests in their operating countries under applicable transfer terms |
| Historical waitlist transport and storage; intake retired | Google Apps Script and Google Sheets | Former production submissions from filmbuddyapp.com were verified in the Film Buddy Waitlist sheet; no new waitlist or beta-application intake; historical-record retention remains 12 months after last interaction or beta end, whichever is later | Google may process retained historical records in countries where it and its subprocessors operate under applicable transfer terms |
| Support mailbox | Google mail infrastructure | Domain MX route verified | Mailbox retention, backups, full provider chain, countries, transfer safeguard |
| Authentication email SMTP | Resend (Plus Five Five, Inc.) | Verified domain in North Virginia; confirmation and reset messages delivered through Supabase Auth; tracking, receiving, templates, and webhooks disabled or unused | Resend documents U.S. data storage, 30-day email-data retention for standard plans, and DPA transfer safeguards |
| Bot and automated-abuse verification | Cloudflare Turnstile | Managed widgets on authentication and destructive account forms; direct server-side Siteverify validation by the Vercel-hosted website; pre-clearance disabled | Cloudflare may process browser, device, interaction, IP, token, challenge, and connection signals under its Turnstile Privacy Addendum |
| Fonts and media | Same-origin website assets | Browser delivery verified | No remote font or embedded-media vendor in audited launch code |
Payments, analytics, advertising, and embedded services
The audited launch code does not contain a checkout or payment processor. It does not load third-party analytics, advertising, chat, remote browser fonts, maps, videos, or social-media embeds. Cloudflare Turnstile is used only for bot and automated-abuse verification on sensitive forms. It does not use behavioral profiling or automated decision-making that produces legal or similarly significant effects.
Film Buddy does not sell personal information, share it for cross-context behavioral advertising, or use website data for targeted advertising. The site does not respond differently to browser Do Not Track signals because it does not perform the nonessential tracking those signals are intended to control. The same is true for legally recognized opt-out preference signals in the current no-sale, no-share configuration. If that configuration changes, Film Buddy must update this notice and implement any required choice before the new technology loads.
Cookies and browser storage
The public marketing and legal pages do not set nonessential cookies or local storage in the audited launch code. A clean signed-out audit of the homepage, login, and signup routes found no cookies, local storage, session storage, IndexedDB, Cache Storage, or service worker. Supabase authentication uses strictly necessary session and verification cookies on authentication and account flows. They keep a user signed in, complete email-link flows, rotate sessions, and protect gated routes. See the Cookie and storage notice for the current inventory and controls. No consent banner is shown while only strictly necessary technology is used.
Native Film Buddy update checks and public update downloads do not use the beta portal's cookies, access codes, or browser storage.
Recipients, international transfers, and security
Website information is available only to authorized Film Buddy personnel and the providers identified above for the stated purposes. It may also be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a business transaction subject to appropriate safeguards.
Film Buddy uses access controls, private build storage, short-lived download links, encrypted transport, server-side authorization checks, and provider security controls appropriate to the website's current role. No system can be guaranteed completely secure. The countries, retention periods, and transfer mechanisms still shown as double-brace release markers must be approved before production publication.
Rights and requests
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive covered personal information; object to processing; withdraw consent where consent is the basis; and appeal a denied request or complain to a data-protection authority. Film Buddy accepts privacy requests from any user without requiring a California eligibility determination. The business has not represented that it meets California statutory threshold tests, and it does not sell or share covered information for behavioral advertising.
Email hello@filmbuddyapp.com with enough detail to identify the relevant account, historical waitlist or application entry, installation or seat record, download, or support record. Film Buddy may request proportionate verification and will explain any lawful limitation or appeal route that applies. Withdrawing consent for any remaining early-access email does not affect processing already performed lawfully and does not require deleting a security, agreement, seat-history, or access-audit record that must be retained on another legal basis.
General audience and policy changes
The website and beta portal are general-audience services and are not directed to children under 13. Film Buddy does not knowingly collect online personal information from children under 13. If it learns that a child submitted personal information, it will delete it and may ask a parent or guardian to contact Film Buddy.
Material changes to website practices will be reflected here with a revised version and effective date, and additional notice or renewed agreement will be provided when required.