Privacy
A deliberately small data footprint.
Desktop analytics and distribution
VODForge creates one random installation UUID locally. This is a pseudonymous identifier: it lets us recognize activity from the same installation across launches. It is not derived from your hardware, account, IP address, email, username, or any device fingerprint. In VODForge 0.2.2, “Share anonymous analytics” controls installation, app-version, Pro interest, and product events together. A minimal region-policy request contains no installation UUID. Analytics defaults on in permitted regions; in opt-in regions it waits for your choice, and an unresolved region waits for a retry. Older releases may retain their earlier telemetry behavior until updated. Update checks and app functionality do not require analytics.
To limit abuse, the server validates submissions and uses request limits. Newer clients keep a random private telemetry credential locally. Daily keyed hashes of network addresses and telemetry identifiers support abuse counters; raw IP addresses are not stored in these D1 counters. Old counters are removed in bounded batches as later traffic arrives. They are not used for advertising or device fingerprinting.
Failure events may include a reason and specific failure code, processing stage, approved exception type, HTTP status, operating-system error code, tool exit code, certificate verification code, and counts of available video/audio formats. Raw exception messages, commands, and tool output are not sent. Newer development builds also include numeric OS, Python, Qt and downloader versions, processor architecture, logical CPU count, total/available memory in MB, exact build revision, and NVIDIA driver/vendor when observed by the existing Windows capability check. They can retain up to eight approved first-party module/line pairs, an observed cookie failure category, and structural path measurements such as length and component count. These contain no path text, raw cookies, hostname, GPU UUID or other hardware identifier. Unavailable facts remain unknown; HTTP 403 alone is not classified as expired cookies. Unsent optional events expire locally after 30 days.
On a fresh installation, the app may open one thank-you page in your default browser. A random, temporary ticket lets that page wait up to two minutes for app permission without sending an installation ID or campaign ref first. Linking requires both app and browser permission. When available, a validated campaign source is stored with the installation; missing sources stay unknown. Declining or granting permission later never automatically opens another tab. Ordinary web requests necessarily expose a network address to the hosting provider.
With app analytics permitted, first-launch and version observations and product events can reach VODForge and HeyCatch without a successful browser link. VODForge stores these records in Cloudflare D1. We use them to understand feature use, export outcomes, reliability, and return usage. Each permitted app open refreshes the installation’s last-seen time, including when the app version has not changed.
- Usage events cover app opens; download and local audio-to-video conversion starts, completions, failures, and stops; exports; and queue additions, removals, skips, and retries.
- Feature events record Library actions such as searching or filtering, saving notes/tags/categories, playback and seeking controls, missing-media recovery, appearance changes, help and recovery actions, and update or Repair progress and outcomes.
- Records include event times and identifiers, the installation UUID, app version, operating-system family, release channel, and relevant run/output types. Opaque attempt identifiers connect outcomes and retries within an installation.
- Where relevant, events include preset, CPU/NVIDIA/copy encoder category, rate-control mode, input type, artwork choice, metadata enabled/disabled, outcome, and theme category. Settings snapshots also include allowlisted output, quality, audio, thumbnail, sidecar and playlist choices, cookie-access mode (disabled, browser or file), processor architecture, and bounded bitrate/quality values. Cookie contents, browser profiles and cookie-file paths are never included. Custom artwork and themes are reported only as “custom.” Media duration, processing and queue-wait time, file size, item count, and source/output resolution are reported in predefined ranges or categories.
Automatic analytics does not include URLs, media titles, filenames, file paths, search text, tag/note/category text, artwork contents, exact playback positions, custom color values, or unrestricted settings values. For example, a search event records that search was used, not the words entered; an artwork event records the choice, not the image.
Turning the app’s analytics setting (“Share usage analytics” in newer builds) off stops future sharing and clears unsent events. A request already in flight may complete; previously received data is not automatically erased. Browser analytics has its own separate choice, described below.
Website analytics and download clicks
When analytics are on, HeyCatch receives page visits, sessions, campaign and referrer data, interaction events such as clicks and form submissions (not what you type), IP address, device/browser data, and a random pseudonymous browser UUID stored by VODForge in that browser. We use this to understand which public posts and pages lead to VODForge downloads, first launches, and Pro interest. Session replay is disabled, and we do not send your email address to HeyCatch.
Separately, when a download link is requested, VODForge records the operating-system build, time, and an optional source label such as a campaign or community name before redirecting to GitHub Releases. This is download intent, not proof of an installation. When browser analytics is permitted, the source label is also saved in that browser profile for up to 30 days so closing the download tab does not lose it. Disabling browser analytics clears that saved label.
Email a desktop download link
If you request a download email, we pass your email address to Cloudflare Email Sending to deliver that one message. This does not subscribe you to a mailing list. VODForge’s database does not store the recipient address. It stores a hashed link token, a validated campaign label when present, request and provider-acceptance times, and the first link visit for up to seven days, removed by daily cleanup after expiry. Rotating keyed counters limit abuse without storing raw email addresses or IP addresses. Cloudflare processes delivery information under its email-service policies.
The email link restores your campaign label on the desktop download page. Browser storage and app attribution remain subject to the existing analytics choices. An email request, accepted message, link visit, download click, and installation are separate observations; none is treated as another. Link visits may include automated email-security scanners.
Waitlist
If you join, we store your normalized email address and, when present, associate it with that random installation UUID. Repeated submissions do not create duplicate signups. You can also join without an installation ID. A successful signup is sent to HeyCatch as an anonymous conversion event only when analytics is allowed; the email address is not included.
What is not collected
VODForge does not add advertising identifiers, device fingerprints, downloaded-file contents, session replay, or a desktop account. Automatic analytics includes the bounded usage and export measurements described above, but not the identity or contents of your media. HeyCatch acts as our analytics processor and uses PostHog in the United States; it does not use these events for advertising.
Optional feedback and ratings
In builds offering Help & feedback, sending a report is a separate, explicit action and does not enable analytics. We receive the reason and message you submit, app version and operating-system family, plus a reply email only if you provide it. Recent failure diagnostics and a canonical YouTube source link are separate unchecked options. Newer builds also offer an unchecked output-folder attachment, enabled only with diagnostics. The review shows the selected attachments. YouTube links may identify private or unlisted content, and folder names may identify people or projects. Cookies, tokens, whole logs, media contents and memory dumps are not attached; do not include passwords, cookies, or other secrets in your message.
Ratings contain your selected stars, optional comment, and optional display name, which defaults to Anonymous. Selecting Submit public review permits your rating, comment, and display name to appear publicly on the VODForge website, subject to moderation rather than automatic publication. Help and feedback reports remain private. Previously private reviews are not made public by this change. Reports and reviews are stored separately in Cloudflare D1 and are not sent to HeyCatch. A separate random support credential protects retries and updates. Request limits and an optional Cloudflare browser check help reduce automated abuse; the check does not receive your report or diagnostics.
To request removal of a submitted report or review, use Help & feedback and include its receipt reference. Do not include additional sensitive details. Minimal request receipts and revoked credential records may remain to prevent duplicate or replayed submissions.
Your analytics choice
In the EU/EEA and UK, and whenever the site cannot reliably determine the visitor’s country, analytics stays off until you allow it. Elsewhere it may run by default where permitted, with this notice and an opt-out. Your saved browser choice also controls whether a new desktop installation is joined to that browser’s attribution history. Global Privacy Control and an enabled Do Not Track signal are honored as refusals everywhere. You can review or change the choice at any time with in the footer.
Retention and requests
HeyCatch states that customer analytics data is retained while the subscription is active and for two months after it ends, then deleted or irreversibly anonymized unless instructed earlier. To request access or deletion of VODForge website analytics data, email support@heycatch.ai, identify getvodforge.com, and do not include sensitive information. HeyCatch’s data-processing terms say it will pass the request to the site operator.