Legal — Privacy
Privacy policy
This policy describes what personal data the STAGEVIS app, the stagevis.app website and our purchase and license delivery process handle, why, where it goes and how long we keep it. The short version: STAGEVIS has no accounts and no analytics or telemetry. Camera feeds, audio and recordings stay on your devices and your network. A small number of network requests exist and are listed below.
1. Who is responsible
The controller is d4b Janusz Maciejewski, Wiklinowa 21F
44-151 Gliwice
Poland. Privacy contact: contact@stagevis.app. Product support mailbox: hello@stagevis.app. If the STAGEVIS business is taken over by a successor (for example a company replacing the current sole proprietorship), the successor becomes the controller of the data described here, and we will update this page and the imprint.
2. What stays on your Mac
The app keeps its files on your computer and does not upload them:
- Settings, templates, paired cameras and the license file:
~/Library/Application Support/StageVis/. - Diagnostics and logs, including crash logs and the LiveKit server log:
~/Library/Application Support/StageVis/Diagnostics/and.../Logs/. Help → Copy Diagnostics prepares a text report with secrets and tokens removed. It is only sent if you paste it into an email to us. - Recordings of cameras and of the program output:
~/Movies/StageVis. - Help → Export Support Bundle… writes a redacted zip (diagnostics, the last part of the server log, crash logs, macOS crash reports of STAGEVIS and the media server from the last 30 days with per-Mac identifiers removed, saved diagnostics snapshots, and the recent app event timeline) to your Mac and reveals it in Finder. After a crash or stall the app can offer Send Report…, which creates the same zip and opens an email; nothing is sent unless you send that email.
- The in-app EventLog (a list of recent events such as cameras joining and leaving) is kept on your Mac only and is never uploaded.
- Names that guests type for their camera in the web camera page are stored locally in the app's settings on your Mac, together with the paired camera slots, and are not sent to us.
Camera video, audio analysis and control traffic run on your local network between your Mac and your phones. Audio input (beat detection) and Audio out are off at launch. Beat detection analyses audio locally for tempo and does not record or transmit it. Audio out adds the selected input to output recordings only while it is on.
We do not collect telemetry, analytics or usage statistics from the app.
Android camera app
The StageVis Camera app for Android (direct download, not on Google Play) talks only to your Mac on your local network. It has no accounts, no analytics and no advertising or tracking libraries.
- Stored on the phone: the pairing (camera name, your Mac's local address, the access token and the Mac's certificate pins) and, if the app crashed, up to a few crash report files. These stay on the phone and are shared only if you choose Share diagnostics and pick where to send them.
- Permissions and why: Camera, to publish video (and to scan the pairing QR); Notifications, for the persistent notification that keeps streaming alive; network access, Wi-Fi state, local discovery and wake lock, to find your Mac and stay connected with the screen off; foreground camera service, to keep the camera running in the background. The app does not use the microphone or your location.
- Sent to your Mac: video, and a status message with battery level, charging state, thermal state and the app version, so the Mac can show them on the camera row. Nothing is sent to us or to third parties.
- Removal: uninstalling the app removes everything it stored on the phone.
3. Network requests the app makes
- Update check. When the app starts, it requests
https://stagevis.app/updates/appcast.xmlto see whether a newer version exists (Sparkle update framework), then repeats this check automatically about every 24 hours while the app is running, and again when you choose Help → Check for Updates…. The request necessarily reveals your IP address to our website host, and carries the app name and version in the User-Agent header together with the standard identification of the macOS network stack. Sparkle's optional system profile (hardware report) is not enabled. We use this only to deliver updates; legal basis: our legitimate interest in delivering updates and the performance of the license contract (Art. 6(1)(f) and (b) GDPR). Our host's request logs are described in section 5. There is currently no setting in the app to switch the check off; the app works normally if the request fails. - STUN. The media server bundled in the app (LiveKit) and the browsers and apps of your cameras use WebRTC. By default WebRTC may contact public STUN servers (for example
stun.l.google.com) to discover network addresses. This reveals the public IP address of the device making the request to the STUN operator. No video, audio or content is sent to a STUN server. You can block these requests in your firewall; cameras on the same local network then still connect directly. - Downloads. Downloading the app from
stagevis.app/download/is served by our hosting provider and logs the usual technical request data (section 5).
The app makes no other requests to our servers or to third parties.
4. Buying a license
- Paddle. Our order process is conducted by our online reseller Paddle.com, the Merchant of Record. Paddle collects and processes your payment and billing data (such as name, email, billing address, country, tax details and payment method) as an independent controller under its own privacy policy: www.paddle.com/legal/privacy. We do not receive your payment card data. Paddle gives us your name, email address and the transaction reference.
- License fulfillment (Cloudflare Worker and KV). When Paddle reports a completed purchase, a small program on Cloudflare's network looks up your name and email at Paddle, signs your license key, and stores in Cloudflare Workers KV: your name, your email address, the transaction reference used as the license ID, the license key (which itself contains your name and email) and the dates of issue and of the end of the update window. Purpose: delivering your license and re-sending it if you lose it (performance of the contract, Art. 6(1)(b) GDPR), and keeping records of fulfillment. Retention: these records are deleted automatically 1825 days after the purchase. Short-lived technical records used only to avoid double delivery (they contain no name or email) are deleted after 30 days. After deletion we can no longer re-send your key from our own records; the key in your email keeps working indefinitely, and we can help you with your Paddle receipt.
- Email delivery (Resend). Your license email (key, download link, order reference) is sent through the transactional email provider Resend, which acts as our processor. Resend sees your email address and the message content for the time needed to deliver it and keeps delivery logs under its own retention rules.
- Operational logs. The fulfillment program writes event logs (for example "fulfilled" or "failed" with the Paddle event ID, transaction reference and error stage). These logs contain pseudonymous Paddle identifiers only, never your name, email address or license key, and are kept under Cloudflare's log retention for Workers.
- Refund and chargeback records. When a purchase is refunded or charged back, we keep the transaction reference, the action (refund or chargeback) and its date, for as long as needed to keep the key listed as revoked in later builds (our legitimate interest, Art. 6(1)(f) GDPR). This record contains no name or email address.
- Support mailbox. Email you send to
hello@stagevis.appor to the privacy contact is forwarded by Cloudflare Email Routing to the mailbox of the seller. We keep correspondence for as long as needed to answer you and to meet legal obligations, and for the launch list (people who asked to be told when the download opens) until the launch email has been sent or you ask us to remove you. - Accounting. Paddle issues the invoices as Merchant of Record. Records we keep for tax and accounting duties are retained for as long as the law requires.
5. The website
stagevis.app is hosted on Cloudflare Pages with downloads from Cloudflare R2. Cloudflare, as our processor, handles each request and may log technical data such as IP address, requested URL, time, browser and country. We do not run analytics or advertising on the site and do not set cookies. Pages that include the Paddle checkout load scripts and a checkout frame from Paddle, which then process your data as described in section 4.
6. Recipients and transfers
Recipients are Paddle (payments), Cloudflare (hosting, Worker, KV, Email Routing, R2), Resend (email delivery), and our professional advisers where required by law. Some of these providers process data outside the European Economic Area. Where that happens it relies on an adequacy decision or standard contractual clauses or an equivalent safeguard provided by the provider. We do not sell personal data.
7. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to processing based on legitimate interest, to data portability, and to withdraw consent given at any time. To exercise a right, email contact@stagevis.app from the address used for your purchase. We can erase the data we hold in Cloudflare KV on request; data held by Paddle must be erased through Paddle, which is a separate controller. You also have the right to complain to the data protection authority of your country, or to the authority competent for the seller under Poland.
8. Changes
We will update this page when the app, the website or our providers change.
