Muxsmith Privacy Policy

Your media stays on your Mac.

Muxsmith does not upload media or filenames. Sparkle may send five support fields with an update check at most once a week.

Effective date: 2 September 2026

Muxsmith app icon

1 · Scope and developer

What this policy covers.

This policy describes the Muxsmith macOS app, its update service, muxsmith.com and the legacy Muxsmith pages on nandakusumadi.com. Muxsmith is developed by Nanda Kusumadi. Contact: muxsmith@nandakusumadi.com.

Muxsmith 1.2 is available as a signed and notarized direct download for macOS 14 or later.

2 · Local media processing

Muxsmith processes media on the Mac.

Muxsmith uses bundled FFmpeg and ffprobe executables to inspect and process files you choose. Video, audio, subtitle data, media metadata and filenames stay on the Mac during these operations. Muxsmith does not send them to Nanda Kusumadi or to a cloud-processing service.

3 · Files and outputs

What Muxsmith reads and writes.

  • Selected sources: Muxsmith reads files you add to inspect their streams and perform the operation you request.
  • Media metadata: The app reads codec, track, language, title, dimension, channel, timing and related container information needed for the workflow.
  • Outputs: Remux, Join and Split create new files in the folder you choose. Sequence Rename changes names only after showing the planned destinations.
  • Temporary previews: If macOS cannot preview a Split source, Muxsmith can prepare a temporary local MP4 preview without changing the source.

Source files are treated as immutable during media processing and are not silently overwritten.

4 · Accounts, advertising and analytics

No Muxsmith account or media upload.

No app account

No media upload

No advertising

No third-party analytics

No behavioural tracking

Muxsmith does not include a public profile, sharing feed or cloud media library. It has no general analytics or telemetry beyond the limited Sparkle update profile described below.

5 · Sparkle update profiling

Five fields, sent at most once a week.

Sparkle may attach a small system profile during an update check. Muxsmith allows exactly these fields:

  • appVersion: the Muxsmith build version.
  • osVersion: the macOS version.
  • cputype: the CPU architecture or type.
  • model: the Mac model.
  • lang: the preferred language.

Sparkle sends this profile at most once per week during update checks. Muxsmith does not add a hardware serial number, account identifier, custom tracking ID, media field or filename. The update service sets no tracking cookie and creates no persistent or device identifier.

The aggregate counts help measure update adoption, supported macOS and hardware distribution, and languages to consider for localization. They count update requests and field distributions, not unique devices.

6 · Supporter purchases

Paddle handles payment and billing details.

A Muxsmith Supporter purchase is a one-time USD 9.99 payment through Paddle’s hosted checkout. Paddle is the merchant of record and processes the payment, billing details, tax and receipt. Nanda Kusumadi does not receive payment-card details. Muxsmith receives the Paddle transaction and customer identifiers plus the purchase email needed to fulfil and recover the licence. Read Paddle’s privacy notice for how Paddle handles checkout data.

Paddle.js is loaded from Paddle only when you start checkout or open a Paddle transaction link. That request gives Paddle ordinary connection information such as your IP address, browser details, request time and referring page.

7 · Licence activation

A random installation ID, not a hardware fingerprint.

The licence service stores the Paddle transaction and customer identifiers, an encrypted recoverable licence key, a keyed digest of the purchase email, and keyed digests of random installation IDs generated by Muxsmith. It also stores activation, validation, deactivation and recovery timestamps. It does not receive media, filenames, media metadata, a hardware serial number or a hardware fingerprint.

One Supporter licence can have up to three active Macs. The service signs a perpetual Supporter entitlement with validation timestamps and a 30-day offline grace period. If the licence service is unavailable, Muxsmith’s free features remain usable.

Purchase and licence records are kept while needed to fulfil and recover the licence, resolve payment disputes, prevent abuse and meet tax or legal recordkeeping obligations. Email muxsmith@nandakusumadi.com to ask about access, correction or deletion. Some Paddle transaction records may need to be retained even when other account-linked information can be deleted.

8 · Server metadata and retention

Raw server records are kept for no more than 30 days.

An update request also gives the server ordinary HTTP metadata, including an IP address, request time and user agent. Access to those logs is restricted. They are deleted within 30 days.

The update collector accepts only the five named profile keys and ignores unknown parameters. It does not retain raw query strings. It stores separate daily aggregate counts for update requests and each allowed field. Those aggregates may be kept longer because they contain no IP address, raw query, persistent identifier or unique identifier.

9 · This website

The website is separate from the app.

The Muxsmith pages use privacy-friendly Umami analytics to count visits and selected actions without advertising cookies. muxsmith.com, nandakusumadi.com, the licence service and the update origin can also process ordinary server-request data such as IP address, requested URL, time and browser information for delivery, reliability and security.

10 · Support email

You choose what to send.

If you contact support, Nanda Kusumadi receives the email address, message and attachments you provide. Send the minimum information needed to answer the question. Do not attach private or copyrighted media unless it is necessary and you have the right to share it.

11 · Security

Release checks cover the app and bundled tools.

Public releases use Apple Developer ID signing, Hardened Runtime, notarization and a stapled ticket. FFmpeg, ffprobe, Sparkle helpers and other nested executables are signed as part of the release. No system can be described as completely secure.

12 · Changes and contact

Questions about this policy.

This policy may change when Muxsmith's release build, update behavior or data practices change. A revised policy will show a new effective date.

Developer: Nanda Kusumadi
Email: muxsmith@nandakusumadi.com

From Nanda Kusumadi

More apps from the developer.