On this page
- The short version
- iPhone Meter, Account, and Buddy Log
- Information the app handles locally
- Local storage and security
- Account access, entitlement checks, and offline grace
- Software update checks
- Diagnostics and support
- Exports and sidecars
- How we use information
- Disclosure, sale, sharing, and tracking
- Retention and deletion on your Mac
- Your privacy rights
- Children
- Changes to this policy
- Contact
- Website and support data
Version 1.3 — Effective July 12, 2026
Official online copy: https://filmbuddyapp.com/privacy
This Privacy Policy explains how Film Buddy LLC ("Film Buddy," "we," "us," or "our") handles information in the Film Buddy iPhone and macOS applications, the shared Film Buddy account, Buddy Log synchronization, and information you choose to send for support. The Website and support data section of the official online copy separately describes the public website's audited hosting, forms, storage technologies, and service providers.
The short version
On iPhone, the reflected-light Meter is available without creating an account or signing in. Camera preview frames are processed locally to estimate reflected light; Film Buddy does not capture, retain, or upload them. Buddy Log and Account are optional account-backed features. Buddy Log writes locally to SwiftData first and synchronizes private roll and frame records to Film Buddy's Supabase project for an approved signed-in account.
On Mac, Film Buddy uses an online account-access gate. It sends account credentials and limited account information to Supabase to sign you in and verify approved beta access. It does not transmit or cloud-sync imported photographs, RAW files, filenames, paths, metadata, edits, recipes, ratings, exports, diagnostics, or editor usage activity. Core image processing and library storage occur on your Mac.
The current apps have no advertising SDK, cross-app or behavioral tracking, third-party analytics SDK, cloud image processing, or automatic crash-reporting SDK.
Film Buddy automatically checks the Film Buddy update feed for new beta versions. It does not download or install an update until you choose to do so, and it does not attach your photographs, library data, usage activity, or a system profile to the request. As with an ordinary website request, the update host may receive connection information such as an IP address, request time, and standard HTTP headers needed to deliver the feed or update file.
Optional camera tethering may communicate directly with a supported camera over USB or your local IP network through a bundled camera SDK. This is local device communication, not an upload to a Film Buddy service. A proprietary camera SDK may perform operations that Film Buddy cannot independently inspect; the app does not configure an external Film Buddy endpoint for it.
If you choose a command that opens separate camera companion software, that software runs independently and is governed by its provider's own terms and privacy practices.
Film Buddy receives diagnostics, photographs, sidecars, or other attachments only when you deliberately export them and send them through a separate support channel.
iPhone Meter, Account, and Buddy Log
Features available without an account
The iPhone Meter tab does not require a Film Buddy account. It stores only device-local preferences such as film ISO, meter settings, and a calibration offset; Film Buddy does not synchronize those preferences.
The Meter requests camera access only to show the live reflected-light view. AVFoundation supplies preview and exposure information, and the App calculates estimated EV and exposure recommendations on the iPhone. It does not take a photograph, retain preview frames, perform face recognition, or send the live image to Film Buddy or Supabase. If camera permission is denied, live metering does not operate, but Account and legal controls remain available.
Account creation and access
The iPhone, Mac, and website use the same Supabase Auth identity. Account creation currently occurs at filmbuddyapp.com and requires an administrator-issued, single-use access code, email confirmation, and Film Buddy approval. The access code is hashed before submission and removed from persistent Auth metadata after redemption. A new customer account remains pending until approved.
When a user signs in, the iPhone App sends the entered email address and password over TLS to Supabase Auth and does not persist the password. Supabase returns a user ID and rotating session credentials. The App requests the account email, optional name, role, and access status from the protected profile table. The Supabase iOS client stores its session in an app-specific Keychain item. Film Buddy also stores a non-secret approved-user ID and last successful verification time in local preferences. After an online approval check, that account can open Buddy Log offline for up to seven days; a pending, revoked, missing, expired, or different account does not qualify.
Signing out removes the iPhone session and offline approval record. It does not delete the account or local Buddy Log data.
Information stored on the iPhone
Depending on the features used, the iPhone App can store:
- account ID, email, optional name, role, access status, Keychain session, and last successful access-verification time;
- roll details such as film stock, rated ISO, camera, lens, format, status, load and finish dates, development notes, and general notes;
- frame details such as frame number, aperture, shutter, meter EV, exposure compensation, focal length, capture time, notes, tags, and favorite state;
- client-generated IDs, ownership IDs, timestamps, deletion tombstones, and synchronization state used for safe offline merging;
- meter preferences and device-specific calibration; and
- cached catalog suggestions and ordinary app preferences.
The current mobile app does not request Location Services and does not populate or transmit the latitude and longitude fields reserved in its data model. Film Buddy will update the permission prompt, App Privacy disclosure, privacy manifest, and this Policy before enabling location capture.
Buddy Log synchronization and catalog searches
Buddy Log is an optional account-backed, offline-first roll and frame notebook. For an approved signed-in account, it synchronizes private roll and frame records to Supabase, including the roll, gear, exposure, timing, note, tag, favorite, development, catalog-reference, timestamp, deletion, and version fields described above. The App writes to SwiftData before attempting transfer; a failed sync does not erase local Buddy Log data.
Cloud Buddy Log tables use authenticated user IDs, foreign keys, and ownership-scoped row-level security. The iPhone App contains only the public publishable key, never a secret or service-role key. Deleted records can remain as synchronization tombstones until processed, and operational backups can remain for a limited disaster-recovery rotation period.
Camera, lens, and film-stock search text can be sent to Supabase catalog-search functions with ordinary connection information and, when signed in, the current session context. Catalog selections allow a custom fallback. A custom Buddy Log value remains private user content and does not become a public catalog entry.
iPhone service providers, purchases, retention, and deletion
Supabase and its infrastructure subprocessors process authentication, session, profile, catalog-query, Buddy Log, security-log, and connection information. Apple may independently process App Store downloads, purchases, diagnostics, and analytics under Apple's terms and the user's settings. Film Buddy plans to offer the mobile App as a free App Store download. Optional Apple In-App Purchases may be added later, but no purchase is currently required to use the account-free Meter. If optional paid features are offered, Apple processes the transaction and supplies transaction and entitlement information; Film Buddy does not receive the full payment-card number.
Local Meter preferences remain until changed, reset, or removed with the App. Local Buddy Log records remain until deleted in the App, removed through account deletion, or removed with the App. Cloud account and Buddy Log records remain while the account is active, subject to the other retention terms here.
An authenticated non-administrator customer can choose Film Buddy iPhone app → Account → Delete Account and Buddy Log. After typed confirmation, the App calls an authenticated server function that derives the customer ID from the bearer session and never accepts an arbitrary target user ID or privileged key. Successful deletion permanently removes the Auth account, profile, sessions, and associated cloud Buddy Log rows before the App removes that account's local session, access record, rolls, and frames from the iPhone. The action cannot be undone. Ordinary customers do not need to email support or file a ticket.
Administrator accounts are refused by this customer flow and may require separate transfer and retention procedures for immutable release and security audit records. Narrowly required fraud-prevention, security, agreement, legal, or rotated backup records may remain where permitted. These procedures do not limit customer account deletion.
Information the app handles locally
To provide the features you request, Film Buddy may read, generate, and store the following on your Mac:
- photographs and camera RAW or TIFF files you select, drop, or capture into a tether folder;
- source filenames and absolute paths, file size and modification date, file type, orientation and other decode metadata, and local file fingerprints;
- roll and session names, local image and job identifiers, frame numbers, ratings, color labels, favorites, and trash state;
- develop recipes, crops, rotations, film-base samples, color measurements, conversion and calibration data, approvals, and export history;
- generated previews, decoded or normalized working files, histograms, analysis files, and regenerable render caches;
- app preferences, cache-location choices, performance information, and local event or system logs;
- a device-only account session, cached account identity and entitlement, the time access was last verified, and the account identifier to which the local library is bound; and
- for optional tethering, a camera model, connection type, SDK device identifier, command state, and capture destination. For a camera connected by local IP, the SDK identifier may be derived from the camera's MAC address.
These are operational identifiers used inside your local library. Film Buddy does not use them as advertising identifiers or to track you across apps or websites.
The app does not request access to Contacts, Calendars, Location Services, the microphone, or the Mac's webcam. Tethered-camera access is separate from webcam access. Film Buddy uses the files, folders, and connected camera you choose for the requested import, edit, export, cache, diagnostics, or tether operation.
Local storage and security
The default library location is:
~/Library/Application Support/Film Buddy/FilmBuddyLibrary
You can choose a different location for regenerable cache files. Originals may remain at the external paths you selected because Film Buddy currently references originals instead of copying them into the library.
Catalogs, recipes, logs, previews, decoded files, exports, and sidecars are ordinary local files and are not encrypted by Film Buddy. Their protection depends on macOS file permissions and security features you enable, such as device login security and disk encryption. No storage or transmission method can be guaranteed completely secure.
Account access, entitlement checks, and offline grace
When you sign in, the app sends the email address and password you enter over an encrypted TLS connection to Supabase Auth. The app does not save your password. Supabase returns a user UUID, email address, optional name, and rotating access and refresh tokens. The app then calls an authenticated entitlement endpoint, which returns the account's role, beta-access status, and approval time. A valid login alone is not enough: Film Buddy unlocks only when the server reports that beta access is approved.
Authentication and entitlement requests do not contain photographs, library or image identifiers, filenames, file paths, recipes, ratings, edits, exports, diagnostics, or editor usage activity. Like other Internet requests, they disclose an IP address, request time, user-agent string, and ordinary transport headers to Supabase and its infrastructure. Supabase may retain those details in account, session, security, and authentication audit logs.
The app stores the rotating session tokens, cached account UUID, email and optional name, entitlement status, and last successful verification time in a non-synchronizing, device-only macOS Keychain item. These credentials are not placed in iCloud Keychain or synchronized to another device by Film Buddy. If Keychain account state cannot be safely replaced or removed, Film Buddy also stores a non-secret offline-access fence in local app preferences. The fence contains no account identifier; it prevents a stale approval from qualifying for offline grace until a fresh online approval is saved successfully.
An Internet connection is required for the first successful verification. After an approved account has been verified online, the same account may continue to unlock that bound local library while offline for up to seven days from the last successful verification. This grace period can temporarily rely on a status that changed after the last successful check. The app checks again when it can; a revoked, pending, missing, or otherwise unapproved entitlement locks access, and the offline grace ends after seven days without a successful check.
The existing local library is bound to the first approved Film Buddy account used by that macOS user. Signing into a different Film Buddy account does not automatically transfer, merge, upload, or reveal that library. Signing out immediately locks the Mac app and removes its saved device credential. Film Buddy also makes a best-effort request to revoke that Mac session with the authentication provider; a network failure does not restore local access, but provider-side session data may remain valid until normal expiry or separate revocation. Signing out does not sign out other devices, delete the online account, delete the local library, or remove its account binding.
Software update checks
While Film Buddy is running, it periodically requests the signed beta update
feed at https://filmbuddyapp.com/updates/beta/appcast.xml. The app also lets
you start a check from the application menu. If an update is available, Film
Buddy shows its version and release notes and waits for you to choose whether
and when to download, install, and relaunch.
Update requests do not include photographs, filenames, library identifiers, recipes, diagnostics, usage analytics, or the optional Sparkle system-profile parameters. Automatic update download and installation are disabled. The update host and its infrastructure providers may process an IP address, request timestamp, requested file, and ordinary HTTP headers for delivery, security, abuse prevention, and operational logs. Their applicable retention and provider details are published with the website disclosures in the online copy of this policy.
The app stores update preferences and update-check timing in the local macOS
preferences domain for com.filmbuddy.app. You can postpone or skip an offered
beta version. Disabling network access prevents update checks but does not
change the local image-processing pipeline. It can prevent account verification
and therefore block the app after the seven-day offline grace period.
Diagnostics and support
Film Buddy writes local event logs and uses Apple's local unified logging and performance-signpost systems. Log entries can include image identifiers, filenames, absolute file paths, export activity, settings hashes, timing data, and error messages.
From Preferences, you can create a diagnostics ZIP in a location you choose. The ZIP contains the app's local logs and a text file with the generation time, app version, macOS version, and Mac chip model. Creating the ZIP does not send it anywhere. Review it before sharing because filenames and paths can reveal a Mac account name, folder layout, project names, or other personal information.
If you contact support, we may receive your contact details, message, and any files you voluntarily attach. We use that information to respond, troubleshoot, protect the service, and keep an appropriate support record. Support messages are retained for 30 days after receipt. Diagnostic archives and other technical attachments are retained for 90 days after receipt, then deleted or de-identified unless a longer period is required to resolve the matter, protect legal rights, or comply with law.
Providing support information is optional. Without a usable reply address and enough detail to understand the problem, we may be unable to respond or resolve it.
Support processing is mapped as follows:
- Contact details and communications come directly from you; they are used to respond and administer the support relationship under contract or pre-contract steps and our legitimate interest in reliable support. They are available to authorized Film Buddy personnel and Google Workspace and its subprocessors, and retained for 30 days after receipt.
- Technical attachments and diagnostics come directly from files you choose to send; they are used to reproduce, secure, and fix the reported issue under contract and our legitimate interest in product security and reliability. They are available to the same authorized recipients and retained for 90 days after receipt.
- Support processing may occur in the United States and other countries where Google Workspace and its disclosed subprocessors operate. Where a legally recognized transfer safeguard is required, Google Workspace's applicable data-processing terms and Standard Contractual Clauses, or another legally recognized transfer mechanism, apply.
Do not send photographs, diagnostics, or sidecars that you are not authorized to share. Remove sensitive files or information that support does not need.
Exports and sidecars
Film Buddy does not intentionally copy source EXIF, IPTC, or GPS metadata into the exported TIFF or JPEG. Every export contains output information such as an ICC color profile, and no software can promise that a file contains no metadata of any kind.
Optional export sidecars are enabled by default and are named after the full
export filename with .filmbuddy.json appended. A sidecar can contain the local
image ID, a source-file hash, absolute source and export paths, recipe and
render settings, crop and analysis values, output details, and export history.
Sharing a sidecar can therefore reveal a Mac username, folder layout, edit
history, and a persistent fingerprint of the source file. Disable the sidecar
option before export, or inspect and redact the JSON, when you do not want to
share that information.
How we use information
Local information is used only on your Mac to perform the app functions you request, maintain your library and preferences, render previews and exports, verify outputs, communicate with a local camera, and diagnose local errors. Film Buddy does not receive or control that local information.
Account information is used to authenticate you, verify approved beta access, bind the local library to the correct account on that macOS user, restore the same account session, provide the seven-day offline grace period, secure the account service, and show your limited account identity and status in the app. We process it to provide the App and account relationship you request and for our legitimate interests in preventing unauthorized access and abuse.
The separate update request is used to determine whether a newer signed Film Buddy release exists and, only after your choice, to deliver that release. It is not used for advertising, profiling, analytics, or tracking.
If you voluntarily contact us, we process the information we receive to:
- perform our contract with you or take steps you request before a contract, including providing support;
- pursue our legitimate interests in securing, debugging, and improving Film Buddy without overriding your rights; and
- comply with legal obligations or establish, exercise, or defend legal claims.
We do not use automated decision-making that produces legal or similarly significant effects about you. Film Buddy's deterministic image-analysis tools do not perform face recognition or biometric identification. Local approval and calibration records are not transmitted for model training.
Disclosure, sale, sharing, and tracking
The app does not automatically disclose local library content to us, data brokers, advertisers, or analytics providers. We do not sell personal information, share it for cross-context behavioral advertising, or track app users across third-party apps or websites.
Local processing may involve Apple operating-system frameworks and bundled decode or camera components identified in Third-Party Notices. They operate as part of the local app workflow. The support providers named above are required to protect support information consistently with this policy and applicable law.
Supabase processes account credentials, user identity and profile fields, sessions, entitlement requests, and related connection and authentication-log information for Film Buddy. We do not permit Supabase to use Film Buddy account information for advertising or cross-context behavioral tracking. Account processing may occur where Supabase and its subprocessors operate, subject to the applicable data-processing and transfer terms described in the online provider inventory.
Apple may independently process App Store purchases, downloads, crash reports, or app analytics under your device and App Store settings. Apple controls that processing; consult Apple's privacy information and your device settings. We will update this policy if we enable receipt of Apple-provided diagnostic or analytics reports.
We may disclose support information if reasonably necessary to comply with law, protect rights or safety, investigate abuse, complete a corporate transaction subject to appropriate safeguards, or work with a provider that helps us deliver support, including the providers identified in the support-processing section above.
Retention and deletion on your Mac
Local library data remains until you remove it. Moving a frame to Film Buddy's Trash marks it as trashed but does not erase it. Removing a frame from the library deletes Film Buddy's catalog rows, recipes, analysis, previews, and cache for that frame while preserving the referenced original. Clearing the cache deletes regenerable previews and decoded masters. For film negatives it also deletes saved develop-recipe rows and recipe sidecars, negative analysis, film-base and manual-base defaults, and resets every film-negative frame to Import. White balance, crop, Convert, and saved edits for those negatives must then be redone. It does not delete referenced originals or external exports.
Regenerable preview and decode caches may also be evicted automatically when configured memory, disk, or cache budgets require it. Other source-of-truth catalog data remains until you remove it or delete the library, subject to the destructive Clear Cache behavior described above.
Exports, sidecars, diagnostics ZIPs, macOS unified logs, preferences, and files outside the library must be removed separately. Uninstalling the app may leave Application Support data and preferences behind. See the bundled Local Data & Diagnostics Guide for exact locations and deletion steps.
Signing out immediately locks Film Buddy on this Mac and clears its saved device session credential. This local action does not guarantee immediate server-side session invalidation if the provider revocation request cannot be completed. It does not delete the server-side account or authentication audit records, the local library, backups, exports, or the library's binding to the first approved account. Removing the app or deleting its preferences does not by itself guarantee removal of Keychain items.
Online account, profile, entitlement, session, and security records are retained for as long as needed to provide and secure the account, satisfy applicable recordkeeping or legal requirements, and resolve disputes. Authentication audit records may include IP address and user agent. Ordinary customers delete the shared online account and cloud Buddy Log through Film Buddy iPhone app → Account → Delete Account and Buddy Log as described above; the privacy contact remains available for other rights requests. Some security, fraud-prevention, legal, or backup records may remain for a permitted period after closure.
Because we cannot access your local library, a privacy request sent to us cannot retrieve or erase data that never left your Mac. You control that data with the app, Finder, your backups, and macOS account tools.
Your privacy rights
Depending on where you live and whether we hold account or support information about you, you may have rights to request access, correction, deletion, restriction, portability, or an objection; to withdraw consent where consent is the basis; and to complain to your local data-protection authority. California residents may also have rights to know, correct, or delete covered information and to be free from discrimination for exercising privacy rights. We do not sell or share covered personal information for behavioral advertising.
Submit a request to hello@filmbuddyapp.com. We may need proportionate information to verify the request. These rights can be limited by applicable law. If we do not hold information about you, we will say so.
International account and support transfers use the providers and safeguards identified above and in the online provider inventory.
Children
Film Buddy is a general-audience creative tool and is not directed to children under 13. The app does not send local image content to us. We do not knowingly allow children under 13 to create Film Buddy accounts or knowingly collect their personal information online. If we learn that a child submitted personal information through an account, support, or the website, we will delete it as required and may ask a parent or guardian to contact us.
Changes to this policy
We may update this policy to reflect a changed app, website, law, or service provider. We will change the effective date, publish the current version on the Film Buddy privacy page, and provide additional notice when required. Material changes will not retroactively reduce your rights without a valid legal basis.
Contact
- Controller: Film Buddy LLC
- Privacy: hello@filmbuddyapp.com
- Support: hello@filmbuddyapp.com
- Website: https://filmbuddyapp.com
Website and support data
This section covers information that Film Buddy LLC receives through
https://filmbuddyapp.com, the early-access waitlist, beta accounts, beta
downloads, and support. It is separate from the app data described above: Film
Buddy cannot see a local Film Buddy library, photographs, recipes, or exports
unless you deliberately send material through a separate support channel.
The current invitation-only beta is offered and targeted only in the United States. It is not offered or targeted to users in the European Union or United Kingdom.
Website delivery and request logs
The website is a Next.js site deployed on Vercel. Production server functions
are configured for Vercel's iad1 region. GoDaddy provides authoritative DNS,
and the deployed site uses a Let's Encrypt TLS certificate. When a browser
requests a page or asset, Vercel and the site's delivery infrastructure
necessarily receive request information such as the IP address, date and time,
requested URL, response status, referrer when supplied, and browser or device
headers.
Film Buddy uses this information to deliver the site, maintain availability,
diagnose errors, and protect the site from abuse. The EU/UK legal basis is Film
Buddy's legitimate interest in operating and securing the website.
Vercel is the hosting, deployment, edge-delivery, and request-log provider; GoDaddy is the DNS provider. The current Vercel Hobby plan retains runtime logs for one hour. Vercel retains build logs with their deployments indefinitely; Film Buddy has not configured a separate log drain or backup archive. Vercel's primary processing facilities are in the United States, while Vercel and its subprocessors may process data in the United States and other countries where they operate. Where an international transfer safeguard is required, Vercel's applicable terms provide the EU Standard Contractual Clauses and UK transfer terms. See Vercel's runtime-log retention documentation and Data Processing Addendum.
Early-access waitlist
The early-access form asks for name, email address, scanning workflow, source format, approximate monthly roll volume, an optional note, and an affirmative choice to receive early-access updates. The submission also records its time, the page referrer when the browser supplies one, browser user-agent string, and an internal status. A hidden anti-spam field may be evaluated and discarded.
The waitlist endpoint requires same-origin browser submissions, limits request size, and applies a best-effort bound of five attempts per ten minutes on each running server instance. For that bound, it holds only an HMAC-SHA256 digest of the forwarded IP address in ephemeral process memory for the remainder of the ten-minute window; this code does not persist the raw IP or send that digest to the Google Sheet. Because Vercel may run multiple instances, the bound is not a global rate-limit guarantee. Normal hosting request logs remain governed by the separate Vercel disclosure above.
The production website sends accepted submissions from Vercel through a
private Google Apps Script endpoint into the Film Buddy Waitlist Google Sheet.
That linkage was operationally verified from accepted submissions originating
at filmbuddyapp.com. Film Buddy uses an operational
submission to manage early access, understand whether the beta fits the
requested workflow, and send the updates requested. The EU/UK legal bases are
consent for requested email updates and Film Buddy's legitimate interest in
administering the beta. You may withdraw from updates at any time by emailing
hello@filmbuddyapp.com.
Waitlist records are retained until 12 months after the person's last interaction with Film Buddy or the end of the beta, whichever is later, unless the person requests earlier deletion where applicable. Google is the Apps Script and Sheets provider. Google may store or process data in the United States and other countries where Google or its subprocessors maintain facilities. Google's applicable Cloud Data Processing Addendum provides the EU Standard Contractual Clauses and other legally recognized transfer mechanisms where required.
Beta accounts, access codes, and downloads
Supabase provides authentication, database, and private build storage for the
beta portal from a primary project region in U.S. West (us-west-2). Account
records include an email address, optional name, Supabase user identifier,
account and update timestamps, role, beta status, and beta approval metadata.
Supabase handles password credentials and authentication email flows and may
retain authentication-session IP address and user-agent information in its
Auth systems. Supabase Auth sends account-confirmation and password-reset
messages through Resend SMTP, operated by Plus Five Five, Inc. The verified
filmbuddyapp.com sending domain uses Resend's North Virginia (us-east-1)
region. Resend stores account data, email metadata, logs, and API records in the
United States and documents a 30-day email-data retention period for standard
plans. Open and click tracking are disabled for the domain. Film Buddy has not
configured Resend receiving, templates, or webhooks. Resend's Data Processing
Addendum, Privacy
Policy, and region
documentation describe its
processing, subprocessors, and applicable transfer safeguards.
Account creation requires an access code issued through Film Buddy's admin console. Film Buddy stores only a SHA-256 hash of the code, never the plaintext, along with an optional admin label, optional lowercased intended-email restriction, optional expiration, creation time and administrator identifier, and any use or revocation time and user or administrator identifier. The signup action hashes the submitted code before sending it to Supabase. The signup trigger uses the hash to redeem the code atomically, then removes that hash from the Auth user's general metadata in the same transaction. It does not record an IP address or browser or device data for the access-code check. The plaintext is shown once to the generating administrator and is not recoverable from the admin page after refresh.
The portal records allowed and denied download attempts with the user identifier, event type and time, IP address, browser user-agent string, and limited details such as a denial reason. It includes the build identifier when a candidate build has been identified. Before an allowed download, it also records affirmative App EULA acceptance, including the EULA version and effective date and checksum; the user and build identifiers; the build version, filename, storage path, byte size, and SHA-256 checksum; the timestamp and transaction identifier; the Storage object and version identifiers; the IP address; and the browser user-agent string. The app file remains in a private Supabase Storage bucket and an approved account receives a short-lived signed download URL only while those immutable object identifiers still match.
Film Buddy uses account, entitlement, EULA-acceptance, and download records to authenticate users, administer and secure beta access, deliver requested builds, document the applicable agreement, investigate abuse, and maintain an appropriate release record. The EU/UK legal bases are contract or steps taken at the user's request before contract, compliance with legal obligations where applicable, and Film Buddy's legitimate interests in access control, software security, and agreement records.
Account and entitlement records are retained while the account is active.
After an account-deletion request, ordinary residual account information is
deleted within 30 days, except for security, agreement, or legally required
records governed by a longer period. Access-code records are retained for 12
months after the code is used, expires, or is revoked. EULA-acceptance and
download-event records are retained for three years after the associated beta
download or account closure, whichever is later. Supabase is the
authentication, database, and storage provider. The Film Buddy project and its
database are hosted in AWS U.S. West (Oregon), us-west-2. Supabase and its
infrastructure and support subprocessors may also process limited service data
in the United States and other countries where they operate. Where required,
Supabase's Data Processing Addendum provides the EU Standard Contractual
Clauses, UK transfer terms, and other applicable lawful transfer mechanisms.
Native app update delivery
Film Buddy for macOS checks the public, signed beta update feed at
https://filmbuddyapp.com/updates/beta/appcast.xml. Automatic download and
installation are disabled. A check requests the feed only; it does not send
photographs, filenames, library data or identifiers, recipes, diagnostics,
usage analytics, or Sparkle's optional system-profile parameters. If a person
chooses an offered update, the app separately requests the versioned ZIP and
release-notes files identified by that signed feed.
Update delivery is public and separate from beta account access. It does not
require an access code, account, authentication cookie, or expiring signed
Storage URL. Vercel serves the stable website paths and the small appcast
route. Immutable versioned files are stored and delivered through Supabase
Storage. The audited Supabase organization is on the Pro plan, its project and
Storage origin are in AWS U.S. West (Oregon), us-west-2, and Supabase's edge
request logs include Cloudflare delivery metadata. Vercel, Supabase, Amazon Web
Services, and Cloudflare therefore participate in the hosting, storage, or
edge-delivery chain for these requests.
The public update paths do not require a cookie. Supabase's Cloudflare delivery
edge may nevertheless return a short-lived __cf_bm bot-management cookie on
a Storage response. It is an infrastructure security control, not a Film Buddy
account, advertising, or analytics identifier, and the feed and files remain
publicly retrievable when a client presents no cookie.
Ordinary delivery and security logs may contain the IP address, request time, requested file, response status, and standard HTTP headers such as user agent, referrer when supplied, range, host, and forwarding headers. Film Buddy uses that information only to deliver updates, diagnose failures, protect the download service, and investigate abuse. It is not used for advertising, profiling, product analytics, or cross-site tracking.
The current Vercel Hobby plan retains runtime logs for the appcast function for one hour. The current Supabase Pro plan retains API and Storage logs for seven days. Film Buddy has not added an update-specific log archive or analytics system. Signed appcasts, versioned update artifacts, hashes, and administrator publication records are release-integrity records rather than usage analytics; the immutable release files are retained for the duration of distribution so installed copies can verify and retrieve the release they were offered.
Support and privacy requests
The public website does not currently provide a support upload or contact form. Domain mail records route the support mailbox through Google. If you email Film Buddy, we receive the reply address, message, email-routing metadata, and anything you choose to attach. Do not send photographs, diagnostics, sidecars, credentials, or other sensitive material unless it is necessary and you are authorized to share it. Creating a diagnostics ZIP in Film Buddy does not upload it.
Support messages are retained for 30 days after receipt; diagnostics and technical attachments are retained for 90 days after receipt. Google Workspace and its subprocessors provide the support mailbox. Processing occurs in the United States and other countries where Google Workspace and its disclosed subprocessors operate. Transfers use Google Workspace's applicable data-processing terms and Standard Contractual Clauses, or another legally recognized transfer mechanism.
Film Buddy cannot retrieve, correct, or erase a Film Buddy library that never left a user's Mac. A request can cover only the website, account, waitlist, download, EULA, or support information Film Buddy and its providers actually hold.
Audited website provider inventory
| Function | Provider or technology | Verified status | Unresolved publication facts |
|---|---|---|---|
| Hosting, deployment, CDN, request logs | Vercel | Project verified; Hobby runtime logs retained one hour; build logs retained with deployments; no Film Buddy log drain or backup archive | U.S. primary processing with subprocessors in other operating countries; applicable SCC and UK transfer terms |
| DNS | GoDaddy | Authoritative DNS verified | Provider retention and subprocessors |
| TLS certificate | Let's Encrypt | Deployed certificate verified | Not used as a marketing or analytics service |
| Authentication, database, private build storage, public update storage and CDN | Supabase, with AWS U.S. West (us-west-2) origin infrastructure and Cloudflare edge metadata | Healthy Pro-plan project verified; API and Storage logs retained seven days; public update files require no account or signed URL | U.S. primary hosting with limited processing by subprocessors elsewhere; applicable SCC and UK transfer terms |
| Native beta update routing and appcast delivery | Vercel | Stable filmbuddyapp.com routes; Hobby appcast-function logs retained one hour; no update analytics or update-specific archive | Vercel subprocessors may process requests in their operating countries under applicable transfer terms |
| Waitlist transport and storage | Google Apps Script and Google Sheets | Production submissions from filmbuddyapp.com verified in the Film Buddy Waitlist sheet; approved retention is 12 months after last interaction or beta end, whichever is later | Google may process in countries where it and its subprocessors operate under applicable transfer terms |
| Support mailbox | Google mail infrastructure | Domain MX route verified | Mailbox retention, backups, full provider chain, countries, transfer safeguard |
| Authentication email SMTP | Resend (Plus Five Five, Inc.) | Verified domain in North Virginia; confirmation and reset messages delivered through Supabase Auth; tracking, receiving, templates, and webhooks disabled or unused | Resend documents U.S. data storage, 30-day email-data retention for standard plans, and DPA transfer safeguards |
| Fonts and media | Same-origin website assets | Browser delivery verified | No remote font or embedded-media vendor in audited launch code |
Payments, analytics, advertising, and embedded services
The audited launch code does not contain a checkout or payment processor. It does not load third-party analytics, advertising, chat, CAPTCHA, remote browser fonts, maps, videos, or social-media embeds. It does not use behavioral profiling or automated decision-making that produces legal or similarly significant effects.
Film Buddy does not sell personal information, share it for cross-context behavioral advertising, or use website data for targeted advertising. The site does not respond differently to browser Do Not Track signals because it does not perform the nonessential tracking those signals are intended to control. The same is true for legally recognized opt-out preference signals in the current no-sale, no-share configuration. If that configuration changes, Film Buddy must update this notice and implement any required choice before the new technology loads.
Cookies and browser storage
The public marketing and legal pages do not set nonessential cookies or local storage in the audited launch code. A clean signed-out audit of the homepage, login, and signup routes found no cookies, local storage, session storage, IndexedDB, Cache Storage, or service worker. Supabase authentication uses strictly necessary session and verification cookies on authentication and account flows. They keep a user signed in, complete email-link flows, rotate sessions, and protect gated routes. See the Cookie and storage notice for the current inventory and controls. No consent banner is shown while only strictly necessary technology is used.
Native Film Buddy update checks and public update downloads do not use the beta portal's cookies, access codes, or browser storage.
Recipients, international transfers, and security
Website information is available only to authorized Film Buddy personnel and the providers identified above for the stated purposes. It may also be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a business transaction subject to appropriate safeguards.
Film Buddy uses access controls, private build storage, short-lived download links, encrypted transport, server-side authorization checks, and provider security controls appropriate to the website's current role. No system can be guaranteed completely secure. The countries, retention periods, and transfer mechanisms still shown as double-brace release markers must be approved before production publication.
Rights and requests
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive covered personal information; object to processing; withdraw consent where consent is the basis; and appeal a denied request or complain to a data-protection authority. Film Buddy accepts privacy requests from any user without requiring a California eligibility determination. The business has not represented that it meets California statutory threshold tests, and it does not sell or share covered information for behavioral advertising.
Email hello@filmbuddyapp.com with enough detail to identify the relevant account, waitlist entry, download, or support record. Film Buddy may request proportionate verification and will explain any lawful limitation or appeal route that applies. Withdrawing early-access email consent does not affect processing already performed lawfully and does not require deleting a security or agreement record that must be retained on another legal basis.
General audience and policy changes
The website and beta portal are general-audience services and are not directed to children under 13. Film Buddy does not knowingly collect online personal information from children under 13. If it learns that a child submitted personal information, it will delete it and may ask a parent or guardian to contact Film Buddy.
Material changes to website practices will be reflected here with a revised version and effective date, and additional notice or renewed agreement will be provided when required.