Privacy policy
FlicksForge is designed to do its job on your Mac without sending your data anywhere it doesn't have to. This page explains exactly what the app and this website do with network connections, what information gets collected along the way, and what your rights are.
Short version
- No analytics SDKs, no user accounts, no identifiers that follow you between launches.
- Your video files never leave your Mac.
- When the app checks for updates it tells our server which version of FlicksForge you are running — and nothing else about you, your Mac, or your library. Details below.
- The app talks to three external services: TMDb (for metadata), OpenSubtitles (only when you click Search), and our own update server (to check for new versions). Each is explained below.
- This website is statically hosted, sets no cookies, and runs no JavaScript analytics. The server keeps standard access logs.
- The only personal data this site collects is an email address, and only if you choose to join the founders' list.
Who we are
FlicksForge is a free macOS application developed by Paul Edward Goossens, based in the United Kingdom. The data controller under UK GDPR and EU GDPR is Paul Edward Goossens. Contact: support@flicksforge.com.
What the app does on the network
TMDb (The Movie Database)
When you drag a file into FlicksForge and click Auto-Match, the app sends
the cleaned filename (e.g. "The Matrix") and, once you pick a
match, the TMDb ID of the movie or TV show to TMDb's public API. TMDb
returns metadata (title, overview, year, cast, director, genre, artwork).
TMDb may log the request IP and query as part of their normal service
operation. See
TMDb's privacy policy.
OpenSubtitles
Only when you explicitly click Search OpenSubtitles in the Metadata Editor, FlicksForge sends the title, year, and (optionally) the video file's hash to OpenSubtitles to find matching subtitles. Downloaded subtitle files are saved to your local subtitle cache. Your video files themselves are never uploaded. See OpenSubtitles' privacy policy.
Our update server (flicksforge.com)
On launch and every six hours thereafter, FlicksForge fetches two small
files from our own server at flicksforge.com:
/updates/latest-mac.yml— version manifest; the app compares it to its installed version to decide whether to offer an update./updates/status.json?v=0.3.4— minimum-supported-version info and optional announcement messages (e.g. upcoming release notes). Thev=value is the version of FlicksForge you are running.
These are plain HTTPS GET requests. If a new version is available, the update zip is downloaded the same way. The only information our server sees from these requests is what every webserver sees: your IP address, the requested URL, the timestamp, and the user-agent string (standard nginx access-log fields). We do not set any cookies, tokens, or unique identifiers on these requests.
Why we send the version number. It is the one piece of information about your installation that we deliberately include, and we want to be straightforward about it. It tells us how many people are on each release — which is how we know whether a security or data-loss fix has actually reached everyone, and when it is safe to stop supporting an old version. Nothing else in the update process reveals this: the version manifest is fetched by a generic library that does not identify itself.
It is a version string such as 0.3.4 and nothing more. It is
not tied to an account, a licence, a device identifier, or anything that
persists between launches, and it says nothing about your files, your
library, or how you use the app. We use it only in aggregate — counting
how many installations report each version — and we do not build per-user
histories from it.
These access logs are retained for up to 30 days for operational and security purposes (troubleshooting, detecting abuse). They are stored on the same server that hosts the website; they are never shared with third parties except where legally required.
What the app does not do
- It does not upload your video files anywhere. Remuxing, transcoding, and tagging all happen locally via bundled ffmpeg and AtomicParsley.
- It does not use any analytics SDK (no Google Analytics, Mixpanel, Amplitude, Sentry, Crashlytics, Rollbar, or similar).
- It does not have accounts, logins, or identifiers that persist between launches.
- It does not report crashes to us automatically. If you want to report a bug, please email us manually.
What this website does
flicksforge.com is a static site served by nginx. It loads a small amount of CSS and a little inline JavaScript: one line that fills in the copyright year, and a handler that submits the founders'-list form without navigating you away from the page. It does not:
- Set any cookies.
- Run any analytics or tag-management SDK.
- Include any tracking pixels, or load any script from a third party. Submitting the founders'-list form sends your email address to Formspree — that is the only request this site makes to anyone else, and only at the moment you submit it.
- Embed any third-party iframes. The demo video is served directly from this domain — it is not a YouTube or other third-party embed.
Standard nginx access logs record your IP, URL, timestamp, and user-agent when you visit. These are retained for up to 30 days.
The founders' list
The download page has an optional form where you can give us your email address to join the "founders' list". It is the only place on this site that collects personal data, and it is entirely optional — nothing about downloading or using FlicksForge requires it.
- What we collect: your email address, and nothing else. There is no name field, no tracking of which page you submitted from, and no profile built around it.
- Why: so we can tell you when paid plans launch, since everyone who joined during the early-adopter phase is entitled to permanent founders' pricing. If we couldn't contact you, the promise would be meaningless.
- Legal basis: consent. You gave us the address for a stated purpose, and you can withdraw at any time.
- Who processes it: the form is handled by Formspree, a US-based form service, which stores submissions on our behalf and forwards them to us by email. See Formspree's privacy policy. Because Formspree is in the United States, your address is transferred outside the UK/EEA. That transfer is made under appropriate safeguards for international transfers — such as the standard contractual clauses in Formspree's data-processing terms (see their privacy policy, linked above).
- How long: until paid plans launch and we have contacted you, or until you ask to be removed — whichever comes first.
- Getting removed: email support@flicksforge.com and we will delete your address. No form to fill in, no reason needed.
What we send, and when
We have changed what the founders' list can be used for, so it matters which side of the change you joined on. We are not applying the new option retrospectively to people who signed up under the old wording.
- Joined before 13 August 2026: exactly one email, when paid plans launch. Nothing else — no release announcements, no newsletter, no drip campaign. That was the promise made at the time and it still stands.
- Joined on or after 13 August 2026: the same single email when paid plans launch, plus — only if you ticked the separate, optional box — a short note when a new version ships, describing what changed. That box is unticked by default, and every such email contains a one-click unsubscribe that leaves you on the founders' list.
If you joined before 13 August 2026 and would like the release notes after all, email us and we will add you. We will not add you otherwise.
Legal basis and your rights (UK GDPR / EU GDPR)
We process personal data on two bases, and only these two:
- Legitimate interest — IP addresses in server logs, for running and securing the service you're using.
- Consent — your email address, if you chose to join the founders' list. You can withdraw that consent at any time by emailing us, and we will delete the address.
We do not process special-category data, and we do not sell, rent or share personal data with anyone for marketing purposes.
Under the UK GDPR, you have the right to:
- Request a copy of any personal data we hold about you.
- Ask us to correct inaccurate data.
- Ask us to delete data where no legal basis applies.
- Object to processing.
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
In practice, because we don't have user accounts and the only personal data we hold is short-lived server log entries, there's usually very little to request. Email support@flicksforge.com with any rights requests.
Third-party services summary
The table below lists every external service FlicksForge ever talks to, when, and why:
| Service | When | What's sent |
|---|---|---|
| TMDb | On Auto-Match, when fetching metadata, when loading poster variants. | Cleaned filename, TMDb IDs, image-request URLs. |
| OpenSubtitles | Only when you click Search OpenSubtitles. | Title, year, optional file hash. |
| flicksforge.com (our server) | On launch and every 6 h thereafter; during updates. | HTTPS GET requests — the FlicksForge version number, no custom identifiers. |
| Apple notary service | Automatically by macOS on first launch of a signed app. | Handled entirely by macOS, not by FlicksForge. |
Changes to this policy
If we change this policy, we'll update the "Last updated" date at the top and, for substantive changes, show an in-app notice via the status banner.
Contact
Questions, concerns, or rights requests: support@flicksforge.com.