On this page
- Current public beta
- Support records and local libraries
- Product support
- Report a vulnerability
- Security scope and limitations
- What stays on your Mac
- Default locations
- Account, seat verification, and library binding
- Originals are referenced
- Delete and clear controls
- Logs and diagnostics
- Export metadata and sidecars
- Local security
Current public beta
Film Buddy 0.7.20 (build 25) requires macOS 13 or later. The invitation-only Developer ID beta is available to approved United States testers through the account portal after acceptance of the current App EULA. The app download is delivered from private storage through a short-lived signed link. The elected LibRaw source, camera-SDK open-source packages, and final release SBOM are publicly available from the Licenses page.
Support records and local libraries
Support and privacy requests go to hello@filmbuddyapp.com. Support messages are retained for 30 days after receipt. Diagnostics and technical attachments that a user deliberately emails are retained for 90 days after receipt.
Film Buddy cannot retrieve, correct, or erase a local Film Buddy library that it never received. Local libraries, photographs, recipes, previews, and exports remain under the user's control unless the user deliberately sends material through a separate support channel.
Ordinary customers can permanently delete the shared Film Buddy Auth account and associated cloud Buddy Log data without contacting support: use Account website → Settings → Delete account and online data or Film Buddy iPhone app → Account → Delete Account and Buddy Log, then complete the authenticated confirmation flow. The server deletes the account and cloud data. The iPhone flow also removes that account's local Buddy Log records from that iPhone; the website cannot erase device-local data. Mac-local libraries and files remain under the user's control and must be removed locally.
Updated July 9, 2026
Product support
Film Buddy, not Apple or a camera manufacturer, provides support for the App.
- Support email: hello@filmbuddyapp.com
- Support page: https://filmbuddyapp.com/support
- Privacy requests: hello@filmbuddyapp.com
Include the Film Buddy version, macOS version, steps to reproduce, expected result, and actual result. You may attach a screenshot or a diagnostics archive only if you are authorized to share it and have reviewed it for sensitive filenames, paths, photographs, and project information.
Film Buddy has no automatic support uploader. Creating a diagnostics ZIP keeps it on your Mac until you send or delete it.
Report a vulnerability
Send security reports privately to hello@filmbuddyapp.com. A minimal private proof of concept is welcome when needed to reproduce the issue, but do not deploy it against third parties or include unnecessary destructive payloads, personal data, photographs, credentials, or test results. Do not send secrets or unnecessary personal data by ordinary email.
Please include:
- the affected Film Buddy version and macOS version;
- the affected component and whether camera tethering is involved;
- clear reproduction steps and impact;
- any proof of concept in the least destructive form practical; and
- how we may contact you and whether you want public credit.
The current beta version is supported throughout beta testing, with security updates provided for 12 months after the final beta release. We aim to acknowledge a vulnerability report within five business days. Unless immediate disclosure is necessary to protect people, coordinate public disclosure with us for up to 90 days while a fix and user notice are prepared.
Do not access another person's data, degrade a system, persist after confirming the issue, conduct denial-of-service or social-engineering tests, or violate law or third-party terms. This page does not authorize testing that would otherwise be unlawful, and it is not a bug-bounty promise.
Security scope and limitations
Film Buddy is a local desktop application. Its catalogs, logs, working files, exports, and sidecars are ordinary files protected by macOS and the user's security choices; Film Buddy does not encrypt them itself. Optional tethering uses camera-vendor components and may communicate over USB or local IP.
If you believe photographs or diagnostics were accidentally sent to Film Buddy, contact hello@filmbuddyapp.com and identify the message so we can apply the published retention and deletion process.
Applies to the seat-aware Film Buddy Mac release — Updated August 22, 2026
Film Buddy is designed around a local library. This guide explains what lives where, what deletion controls actually do, and what to review before sharing an export or diagnostics file.
What stays on your Mac
Core image processing is performed by the Film Buddy app and its local helper processes. Film Buddy uses an online account only to authenticate you, verify approved beta access, and authorize one of the account's two current server seats. It does not provide a cloud image library, advertising SDK, or automatic support uploader. Photographs, filenames and paths, recipes, ratings, edits, exports, diagnostics, and editor usage activity are not uploaded or cloud-synced by the account connection.
Optional direct camera tethering can communicate with a supported camera over USB or your local IP network. That traffic is between your Mac and camera through the camera SDK; it is not a Film Buddy cloud-processing path. Canon states that its camera SDK may separately collect limited SDK usage information and statistics under Canon's privacy statement. Film Buddy does not receive that Canon-collected information.
Film Buddy also checks its signed beta update feed automatically while the app is running. The check does not upload photographs, library data, diagnostics, usage activity, or a system profile. Film Buddy notifies you when an update is available and waits for you to choose whether and when to download and install it.
Default locations
Film Buddy's default data root is:
~/Library/Application Support/Film Buddy/FilmBuddyLibrary
It can contain the SQLite catalog and WAL files, per-image JSON records,
recipes, analysis, previews, decoded or normalized working images, render
caches, approvals, export records, and logs/events.jsonl.
Preferences are stored by macOS for bundle identifier com.filmbuddy.app.
macOS may also retain local unified-log entries according to its own policies.
Those preferences include the last update-check time and versions you choose to
postpone or skip.
The Supabase access and refresh tokens, cached account UUID, email and optional name, entitlement status, current Auth session binding, current seat lease, and last successful account-and-seat verification time are stored in a non-synchronizing, device-only macOS Keychain item. A separate device-only Keychain item holds a random Film Buddy installation UUID. That installation identity ordinarily remains after sign-out so signing in again identifies the same app installation. Neither item contains the account password. Deleting the preferences domain does not delete either Keychain item.
The seat lease records the approved account, installation UUID, Auth session, reported device, assignment, seat number, assignment generation, issue time, and seven-day (168-hour) expiration. Preferences also contain a non-secret, installation-wide wall-clock high-water mark and offline-access fence outside the account session. A backward, corrupt, or regressing clock observation fails closed and remains fenced until a fresh online account-and-seat check succeeds. While the app remains running, a continuous system clock that includes sleep prevents a frozen wall clock from extending the lease. No local technique can provide a perfect trusted clock across every restart on a device whose owner controls the clock, storage, executable, and network connection while offline.
The app reports the platform; a device label supplied by the operating system or app, which may be generic; Film Buddy app version and build; and operating-system version when it checks or requests a seat. The account owner can provide a separate optional custom label. These reported labels and versions are metadata and do not authorize access.
You can move regenerable cache data from Preferences. The selected cache path then contains Film Buddy preview and decode artifacts. Referenced originals remain at their existing locations; catalog data and recipes remain in the library.
Account, seat verification, and library binding
On first sign-in, Film Buddy sends the entered email address and password over TLS to Supabase Auth. It receives a user UUID, limited account profile fields, and rotating session tokens, then asks authenticated account-and-seat endpoints whether beta access is approved and whether that exact installation and Auth session hold one of the account's two current server seats. Supabase may retain the request IP address and user-agent string in session, security, and authentication audit logs.
A valid login or approved beta entitlement alone does not unlock the gated Mac app. The current Mac installation and Auth session must hold a seat. The iPhone app, Buddy Log, account website, and the act of downloading a Mac update do not consume a Mac seat.
After one successful online account-and-seat verification, the same approved account, installation, Auth session, device, assignment, seat number, and assignment generation can use its bound local library under a seven-day (168-hour) cached seat lease. After the lease expires, another online check is required. A pending, revoked, missing, different, expired, or unseated result locks the gated feature. Because the cached lease reflects the last verified state, a server-side approval or seat change may not be known until the next connection.
A disabled or replaced server seat is available to another installation immediately. An installation already offline may temporarily continue using its cached lease, so local app use can overlap the account's two current server assignments until the offline Mac installation reconnects or its seven-day (168-hour) lease expires.
The existing library is bound to the first approved Film Buddy account used by that macOS user. Another Film Buddy account does not automatically gain access to, claim, merge, or receive the library. The binding does not upload the library; it is a local access association. Signing out does not delete or unbind the library.
Originals are referenced
Film Buddy currently records the path to an original instead of treating its library as the only copy. Moving, renaming, or disconnecting an original can make it unavailable until relinked. Removing a frame from Film Buddy preserves that referenced original.
Keep an independent backup of originals and important exports. The Film Buddy library and cache are not a substitute for a backup.
Delete and clear controls
- Move to Trash changes a Film Buddy catalog flag. It is reversible and is not erasure.
- Remove from Library permanently removes Film Buddy's catalog records, recipes, approvals, analysis, previews, and cache for that frame. It preserves the referenced original file.
- Clean Old Renders removes regenerable preview artifacts under the stated policy.
- Clear Cache removes regenerable previews and decoded masters. For film negatives it also deletes every saved develop-recipe row and recipe sidecar, negative analysis, film-base and manual-base defaults, and resets every film-negative frame to Import. You must redo white balance, crop, Convert, and saved edits for those negatives. It preserves referenced originals and external exports.
- Delete the library folder in Finder removes the remaining Film Buddy catalog and library artifacts after the app is quit. Verify the path and make a backup first. Inspect the folder before deletion: if you deliberately chose a tether or capture destination inside it, captured originals may also be there.
- Sign Out first asks the server to deactivate the seat bound to the current authenticated session, then immediately locks Film Buddy and removes the local account session and cached seat lease even if the server request cannot be confirmed. A warning identifies an unconfirmed server-side release, and the account website remains available to disable or replace the seat. Sign Out does not delete the random installation UUID, server-side installation, seat, or audit history, sign out the phone app or website, delete the online account, delete or unbind the local library, or remove exports, sidecars, diagnostics, or backups.
- Uninstalling the app does not guarantee removal of Application Support, custom cache, preferences, external exports, sidecars, diagnostics ZIPs, backups, macOS unified logs, or the device-only Keychain item. Sign out before uninstalling when you want the active Mac session removed.
To identify a custom cache before resetting it, open Preferences > Cache
Storage and choose Show in Finder. Record that location, quit Film Buddy,
and remove the Film Buddy Cache folder there if you intend to erase it.
There is not yet one in-app button that erases all Film Buddy data, account state, and preferences. To perform a full local reset, sign out, quit Film Buddy, back up anything you need, remove the default library and any custom cache in Finder, remove external exports/sidecars/diagnostics separately, and remove Film Buddy's macOS preferences using normal macOS administration tools. Signing out immediately locks the app and removes the local account session and cached seat lease; it does not delete the random installation identity, online account, server-side device, seat, or audit history, or the library's first-approved-account binding.
To remove the production app's stored preferences after quitting Film Buddy, run this command in Terminal:
defaults delete com.filmbuddy.app
macOS may report that the domain does not exist when no preferences remain. Managed Macs may require an administrator. This command does not delete the library, a custom cache, exports, sidecars, diagnostics, backups, or Keychain account state.
Logs and diagnostics
Local logs may include image IDs, filenames, absolute paths, project or roll names, export activity, settings hashes, timing, and errors. The event log does not currently have an automatic expiration period.
Export Diagnostics creates a ZIP where you choose. It contains the local
logs folder and an info.txt with the generation time, Film Buddy version,
macOS version, and Mac chip model. It does not transmit the ZIP.
Before sending diagnostics:
- Make a copy if you want to preserve the original archive.
- Open the ZIP and review
info.txtand the files underlogs/. - Remove entries or files you do not want to disclose.
- Send it only through the support channel at hello@filmbuddyapp.com.
- Ask support to delete it when the issue is resolved if that is your preference.
Film Buddy receives a diagnostics archive only if you choose to send it.
Export metadata and sidecars
Film Buddy does not intentionally copy source EXIF, IPTC, or GPS fields into TIFF or JPEG outputs. It does add necessary output properties such as an ICC profile. Inspect a file with a metadata tool if metadata absence is critical.
The optional sidecar is enabled by default and is written as:
<full-export-filename>.filmbuddy.json
For example: frame-01.tif.filmbuddy.json.
A sidecar may contain:
- absolute source and export paths;
- a persistent cryptographic hash of the source;
- the Film Buddy image ID;
- recipe, render graph, crop, analysis, and edit values; and
- output details, timestamps, and export history.
An absolute path can reveal your Mac username and folder structure. A source hash can show that two sidecars refer to the same source even if the filename changes. Disable sidecars before export, or review and redact the JSON, when you do not intend to share this information.
Local security
Film Buddy does not add application-level encryption to its catalog, logs, previews, decoded files, exports, or sidecars. Use a strong macOS login, appropriate file permissions, trusted backup media, and disk encryption where appropriate. Limit access to any folder used for tether capture or a custom cache.
The Film Buddy account-and-seat gate controls access through the app; it does not encrypt the local library or prevent someone who already has filesystem access under your macOS account from reading ordinary local files. The seven-day (168-hour) cached seat lease is an availability feature, not continuous online revocation checking, and an already offline installation may temporarily retain local access after its server seat is disabled or replaced.
For privacy questions, contact hello@filmbuddyapp.com. For security issues, use hello@filmbuddyapp.com and follow the Security & Support page.