Last updated: September 2, 2026
OwnClip ("we," "us," "our") is a privacy-first screen recording and editing tool available as a native macOS application. This Privacy Policy explains how we collect, use, share, and protect information when you use the OwnClip macOS application, the hosted video viewer at view.ownclip.io, our server-side infrastructure, and the ownclip.io website (collectively, the "Service").
For purposes of data protection law, OwnClip is the data controller for the personal data described in this policy. For payment-related data, Lemon Squeezy acts as an independent data controller (see Section 5).
| Data Type | Purpose | Storage | Legal Basis (GDPR) |
|---|---|---|---|
| Google Account (OAuth) | Authentication, license management, and uploads to your own Google Drive if you connect it | Our authentication service (UID, email, display name, profile photo URL) + locally cached on your device | Consent / Contract performance |
| License tier | Determine feature access tier (Free/Pro/Studio) | Our secure cloud database + locally cached for offline use (up to 7 days) | Contract performance |
| Email address | Respond to support inquiries (only if you contact us) | Our email system | Legitimate interest |
| Email address | Account emails: confirm your address, reset your password, welcome you and explain how to get started, and confirm a purchase | Our email system | Contract performance |
| Email address | A short onboarding series (at most two emails in your first week) suggesting features you may not have found, and explaining the difference between the free and paid tiers | Our email system | Legitimate interest — you can opt out at any time, from a link in every such email |
We send two kinds of email, and they are treated differently:
To stop the onboarding emails: use the unsubscribe link in the footer of any of them — it works in one click, needs no login, and takes effect immediately. Your account emails are unaffected. You can also email support@ownclip.io and we will do it for you.
We do not sell, rent, or share your email address with anyone for their own marketing, and we do not send you email on behalf of third parties.
When you purchase OwnClip Pro, payment is processed by Lemon Squeezy (lemonsqueezy.com), which acts as our Merchant of Record. Lemon Squeezy collects and processes the following data directly from you at checkout:
| Data Type | Purpose | Controlled By |
|---|---|---|
| Full name | Billing & invoicing | Lemon Squeezy |
| Email address | Order confirmation and receipts | Lemon Squeezy |
| Payment method (credit card, PayPal, etc.) | Transaction processing | Lemon Squeezy (PCI-DSS compliant) |
| Billing address | Tax calculation, fraud prevention | Lemon Squeezy |
| IP address | Tax jurisdiction, fraud detection | Lemon Squeezy |
| Country / region | VAT/GST/sales tax calculation | Lemon Squeezy |
We do not have access to your full credit card number, CVV, or payment credentials. Lemon Squeezy may share limited order information with us (email address, order ID, license/purchase status) to facilitate license key delivery and customer support. Lemon Squeezy's handling of your payment data is governed by their Privacy Policy.
All recordings, webcam video, audio, AI effects (such as camera blur, background replacement, noise removal, and transcription), AI-generated content (such as generated or edited images, generated audio and music, generated and animated video, synthetic voiceovers, and generated slide decks), editing operations, and user-generated metadata are processed and stored entirely on your Mac. This data is never sent to any server, including ours. All AI runs on your device — no audio, video, image, or text data is transmitted to any external AI service, and any input you provide to an AI feature (for example, a photo, an audio sample, a text prompt, or a web address) is processed locally and not transmitted to us.
Some advanced AI features rely on a model that is downloaded to your Mac the first time you use the feature. That download delivers only the model itself and never includes any of your content — see Section 2.7.
Locally stored data (recordings, projects, generated content, settings) persists in the application's data directory until you delete it or uninstall the application.
The Service uses secure cloud infrastructure (operated by Google) for authentication, feature gating, sharing, and analytics. The following data is stored on our servers:
| Data Type | Purpose | Storage Location | Retention |
|---|---|---|---|
| User profile (UID, email, display name) | Authentication and license management | Cloud database | Until account deletion |
| License tier and purchase status | Feature gating enforcement | Cloud database | Until account deletion |
| Installation IDs | Multi-device license tracking | Cloud database | Until account deletion |
| Hardware identifier | Device-based license activation and enforcement (device limit varies by tier — Pro: 1 Mac, Studio: 2 Macs) | Cloud database | Until device is deactivated or account deletion |
| Machine name (e.g., "MacBook Pro") | Device identification in account management UI | Cloud database | Until device is deactivated or account deletion |
| Share metadata (title, description, view count, which storage provider the file lives on, and that provider's reference to the file) | Serve shareable links and social previews | Cloud database | Until share is disabled or deleted |
| Recognized text, for a shared text capture only — the text OwnClip read from a screenshot, when you choose to share that capture | Render the text as a selectable layer on the share page, which is the purpose of that share type | Cloud database, with the share record | Deleted when you turn the link off; re-sent if you turn it back on |
| Branding settings (logo, colors, CTA text/URL) | Branded share pages (Studio only) | Cloud database + secure cloud storage (logo files) | Until user deletes or account deletion |
| Last login timestamp | Account activity tracking | Cloud database | Until account deletion |
None of the above includes your recordings, screenshots, transcriptions, or any media content, with one narrow exception named in the table above and explained in full below. Your content remains on your Mac and, if you switch on a backup destination or share a file, in the storage account you connected — never on our servers.
The one exception: sharing a text capture. Capture Text reads the words out of a screenshot on your Mac, and nothing about that leaves your device. But if you then choose to share that capture, the recognized text is the thing being published — the share page renders it as a selectable text layer, which is the entire point of the share type — so it is stored with the share record on our servers. This happens only when you press Share on a text capture, never in the background and never for any other kind of file. OwnClip shows you the text and tells you it will be stored before you create the link, turning the link off deletes the text, and the underlying screenshot is never sent to us — it goes to your own storage like every other file.
To improve product quality and stability, the OwnClip macOS application uses two separate, independently-controllable reporting channels: crash & stability reports (on by default — you can turn them off anytime in Settings → Privacy) and anonymous usage analytics (off by default — opt-in). Both run on our own first-party infrastructure (hosted on our Google Cloud servers). The application does not embed any third-party analytics or advertising SDKs, and we do not sell analytics data to anyone. (Our website at ownclip.io uses Google Analytics separately — see Section 8.2.)
| Data Type | Examples | Purpose | Retention |
|---|---|---|---|
| Usage events | Event name (e.g., recording_start, screenshot, feature_used), category, timestamp, application version, system locale | Understand which features are used, prioritize development | 90 days (raw events) |
| Installation ID | Random identifier unique to your application installation | Deduplicate events, rate limiting (60 batches/min) | 90 days (with events) |
| Session ID | Temporary identifier, expires after 30 minutes of inactivity | Group related events within a session | 90 days (with events) |
| Crash & error reports | Error messages, error codes, stack traces, and recent in-app steps/state ("breadcrumbs" — diagnostic text only, never your content), macOS version, hardware model, application version | Diagnose and fix crashes and bugs, improve stability | 30 days |
| License/purchase events | Tier change events (from Lemon Squeezy webhooks) | Aggregate business metrics (e.g., total paid licenses) | Indefinite (aggregated only) |
If you are signed in, your anonymized user ID may be associated with analytics events for license tier enrichment (e.g., to understand feature usage across free vs. paid tiers). This data does not include: the content of your recordings, screenshots, or transcriptions; or your screen activity or application usage outside OwnClip.
Aggregated daily statistics (counts only, no individual data) are retained indefinitely for product improvement.
Legal basis (GDPR): Crash & stability reports — legitimate interest in providing a stable, secure product; on by default, and you may opt out anytime in Settings → Privacy without affecting functionality. Anonymous usage analytics — consent; off by default, opt in via the first-launch notice or Settings → Privacy. Neither channel ever includes the content of your recordings, screenshots, transcriptions, filenames, or the contents of any storage account you connect.
We do not collect or have access to:
Several AI features use a model (a data file) that is too large to ship inside the application, so it is downloaded to your Mac from our infrastructure the first time you use that feature. This is the only additional network activity these features involve, and it flows to your device, not from it.
| Data | Purpose | Notes |
|---|---|---|
| Model identifier | Tell our infrastructure which model file to provide | Identifies the model, not you or your content |
| Sign-in token & license tier | Confirm you are entitled to a paid model before it is provided | Uses the account and license data already described in Section 2.4; some models are available on the Free tier |
| Standard connection data | Deliver the file, as with any file download | IP address and application version, seen by our infrastructure and our cloud storage / content-delivery provider |
The download never includes any of your content — no recordings, screenshots, audio, images, prompts, or transcriptions. Once a model is on your Mac, the corresponding AI feature runs entirely on your device. Downloaded models are cached locally and are removed when you delete them or uninstall the application.
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Authenticate your Google account | Authentication profile (UID, email, display name, profile photo) | Consent (you initiate OAuth) |
| Validate license tier and enforce feature limits | User ID, license/purchase status | Contract performance |
| Process payments for Pro/Studio one-time purchase | Payment data (via Lemon Squeezy) | Contract performance |
| Activate license after purchase | Email, user ID, order ID (from Lemon Squeezy webhook) | Contract performance |
| Manage shareable links | Share metadata, the storage provider you shared from, and that provider's reference to the file | Contract performance / consent |
| Serve branded share pages (Studio) | Branding settings, logo | Contract performance |
| Provide customer support | Email, order details (only if you contact us) | Legitimate interest / consent |
| Serve the ownclip.io website and view.ownclip.io player | Standard web request data (see Section 6) | Legitimate interest |
| Diagnose & fix crashes, improve stability | Crash & error reports (see Section 2.5) | Legitimate interest (on by default, opt-out) |
| Understand feature usage | Anonymous usage analytics (see Section 2.5) | Consent (off by default, opt-in) |
| Comply with legal obligations | As required by law | Legal obligation |
We do not use your personal data for targeted advertising or selling to third parties. We may use anonymized or aggregated data for product analytics and improvement.
OwnClip can copy your recordings and screenshots to cloud storage, and can turn a stored file into a shareable link. In every case the destination is an account you own — you choose it, you connect it, and you can disconnect it. There are five destinations:
| Destination | Where the copy goes | How you connect | Can produce a share link? |
|---|---|---|---|
| Google Drive | An "OwnClip" folder in your own Drive | Google sign-in (OAuth), limited to files OwnClip itself created | Yes |
| iCloud Drive | An "OwnClip" folder in your iCloud Drive, visible in Finder | Uses the iCloud account already signed in to macOS — no separate sign-in, and no credentials of any kind are stored by OwnClip | No — iCloud Drive can store your files but cannot produce a share link, so it is never offered as a source for sharing |
| OneDrive | An "OwnClip" folder in your OneDrive | Microsoft sign-in (OAuth) | Yes |
| Your own S3-compatible storage (Studio) | The bucket you name, under the optional prefix you name. The bucket, its region, and its access policy are yours, not ours | No sign-in and no OAuth — you enter the endpoint, bucket, region and access keys yourself (see Section 6.3) | No — this destination is for backup only and is never offered as a source for sharing |
A shareable link (view.ownclip.io) points at a file in your storage account. We store the share's metadata in our cloud database (see Section 2.4); we never host, cache, copy, or inspect the file itself. Sharing is available from Google Drive and OneDrive.
When you enable sharing, your Mac hands our server-side service a short-lived access token for that provider, and the service uses it once to set "anyone with the link can view" on that one file (or, for a restricted share, to grant read access to the specific people you named). When you disable sharing, the same mechanism revokes it. The token is used for that call and is not stored on our servers. You can also change or remove these permissions yourself, directly in the provider's own interface.
Alongside an uploaded file, OwnClip may store small private tags on it (for example, a marker recording that OwnClip created the file, so it can find and tidy up its own files later). Where a provider supports it, these tags are private to OwnClip and are not visible to other applications. They contain no analytics data and are never sent to us.
OwnClip requests the minimum required Google permission scope — access only to files created by OwnClip. We cannot access your other Drive files. You can revoke OwnClip's access to your Google Drive at any time via Google Account Permissions. Revoking access does not delete files already in your Drive. The section immediately below sets out our commitments under the Google API Services User Data Policy in full.
OwnClip requests the following Google OAuth scopes, each used only for the purpose described and never sold, transferred, or used for advertising or for training generalized AI/ML models:
| Scope | Why we request it | What we do with the data |
|---|---|---|
https://www.googleapis.com/auth/drive.file |
Upload your screen recordings and screenshots to your own Google Drive when you choose to share or back them up. | Files are uploaded directly from your Mac to your own Drive. We can access only the files OwnClip itself created — we cannot read your other Drive content. Server-side, we set or revoke "anyone with link" permission when you toggle sharing. |
https://www.googleapis.com/auth/youtube.force-ssl |
Create and manage YouTube Live broadcasts on your behalf when you use the Go Live feature (Studio tier). | We call the YouTube Data API v3 only to create a broadcast, bind a stream, and transition broadcast state to "complete" when you stop. Video frames stream peer-to-peer over RTMP from your Mac to YouTube's ingestion endpoint and never touch OwnClip servers. We retrieve your channel title for display in the app; we do not list, read, or modify any other channel content. |
You can revoke either scope at any time. Inside the app: Settings → Account → Sign Out for Drive, or Go Live → Disconnect for YouTube. Outside the app: Google Account Permissions. Revocation through the app contacts oauth2.googleapis.com/revoke so OwnClip is removed from your third-party-apps list immediately.
The Go Live feature (Studio tier) can broadcast to YouTube (see above), Twitch, and custom RTMP destinations:
You can disconnect a broadcast account at any time from Go Live → Disconnect in the app.
OwnClip Pro and Studio are one-time purchases (not subscriptions), handled by Lemon Squeezy, which acts as our Merchant of Record. When you make a purchase:
For data protection purposes, Lemon Squeezy acts as an independent data controller for the payment and billing data it collects. We encourage you to review Lemon Squeezy's Privacy Policy before making a purchase.
The OwnClip macOS application may request the following system permissions, all managed by macOS and revocable at any time in System Settings > Privacy & Security:
No permissions are used for advertising or tracking. The application does not access data from other applications, your filesystem outside its own data directory, or any system resources beyond the permissions listed above.
The application uses a built-in software-update mechanism to check for updates. During update checks, your IP address, macOS version, and application version are sent to our software update feed, which is hosted on GitHub Releases. No other personal data is transmitted during update checks. You can disable automatic update checks in the application settings.
Recordings, edit projects, settings, and cached data are stored in the application's local data directory on your Mac. This data persists until you delete it or uninstall the application. We do not have access to or visibility into locally stored data.
Connecting a storage destination (Section 4) creates a credential. Every one of them is held on your Mac, in the macOS keychain, and none of them is ever transmitted to us. Specifically:
Keychain items created by OwnClip are device-bound: they are marked as non-synchronising, so they are not copied to your other Macs through iCloud Keychain. Connecting a destination on a second Mac means entering or authorising it again there. You can remove any of these credentials at any time by disconnecting the destination in Settings; for your own S3-compatible storage, disconnecting deletes both the settings item and the secret item.
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Google Cloud Platform | Authentication, cloud database, server-side infrastructure, secure storage for branding assets, and website hosting | User ID, email, display name, license/purchase status, analytics events, share metadata, branding settings, logo files. Standard web server logs (IP, user agent) for hosted sites. | Google Cloud Privacy |
| Cloud storage & content delivery | Host and deliver downloadable AI model files (see Section 2.7) | The model identifier requested, plus standard connection data (IP address, application version). No user content. | Governed by our provider's privacy terms |
| Google Drive | Backup and shareable links, if you connect it (Section 4) | Recordings and screenshots you choose to upload (to your own account); share permissions set and revoked by our server-side infrastructure using a short-lived token from your Mac | Google Privacy |
| Microsoft OneDrive | Backup and shareable links, if you connect it (Section 4) | Recordings and screenshots you choose to upload (to your own account); share permissions set and revoked by our server-side infrastructure using a short-lived token from your Mac | Microsoft Privacy Statement |
| Apple iCloud Drive | Backup only, if you switch it on (Section 4) | Recordings and screenshots you choose to copy into an "OwnClip" folder in your own iCloud Drive. No credentials are involved and no share links are possible; we see nothing | Apple Privacy Policy |
| Your own S3-compatible storage | Backup to a bucket you own and configure (Studio tier — Section 4) | Your files go directly from your Mac to the endpoint you specify, signed with credentials that stay on your Mac (Section 6.3); we do not see the endpoint's contents or the transfer | Governed by whichever provider operates the storage you chose |
| Google Identity (OAuth) | Authentication | OAuth token (no password shared with us) | Google Privacy |
| Lemon Squeezy | Payment processing, billing, tax, license issuance | Payment & billing data (collected directly by Lemon Squeezy); webhook sends purchase/license events to our server-side infrastructure | Lemon Squeezy Privacy |
| Twitch | Live broadcasting (Go Live, Studio tier) | OAuth authorization (callback relayed through our server); your video/audio streams peer-to-peer over RTMP and does not pass through our servers | Twitch Privacy |
| Custom RTMP destination | Live broadcasting to a destination you configure (Go Live, Studio tier) | Your video/audio streams directly from your Mac to the endpoint you specify; we do not see or store it | Governed by your chosen provider |
| GitHub Releases | Software update feed (auto-update checks) | Your IP address, macOS version, and app version when checking for updates | GitHub Privacy |
| Sparkle | Application auto-update framework | Performs the update check above against the GitHub-hosted feed; sends no additional data | Sparkle Project |
| Google Analytics | Website usage analytics (ownclip.io only — not in the app) | Your IP address, page views, and standard web analytics data when you visit the website; sets analytics cookies | Google Privacy |
| Google Fonts | Typography (ownclip.io website only) | Your IP address when loading fonts | Google Fonts Privacy |
We do not use advertising networks or retargeting services that profile users for marketing purposes. In-app analytics are limited to first-party usage statistics and error reporting as described in Section 2.5; the only third-party analytics we use is Google Analytics on the ownclip.io website (see Section 8.2).
The OwnClip macOS application does not use cookies, browser tracking, or advertising identifiers. Analytics data collected by the application is limited to product improvement as described in Section 2.5.
The ownclip.io website asks for your consent before loading analytics cookies. When you first visit, a cookie banner lets you Accept all, Reject all, or customize. Google Analytics does not load until you opt in — if you reject (or simply ignore the banner), it is never loaded and sets no cookies. You can change your choice at any time via the "Cookie preferences" link in the website footer; turning Analytics back off deletes its cookies. This applies to the website only — the macOS application uses no cookies or web tracking (see Section 8.1).
| Category | Cookies / Storage | Purpose | Loads |
|---|---|---|---|
| Strictly necessary | ownclip_cookie_consent (records your choice); ownclip_aff_ref and the Lemon Squeezy affiliate.js link-rewriter (cookieless affiliate attribution, if you arrived via a referral link) | Remember your consent choice across pages and subdomains; credit the partner who referred you. Functional/necessary — exempt from consent under ePrivacy. | Always |
| Analytics | Google Analytics — _ga, _ga_6J266QBB45 (measurement ID G-6J266QBB45) | Aggregate, non-advertising site usage: page views, referral source, approximate region. Processed under Google's Privacy Policy; includes your IP address. | Only after you accept Analytics |
The website also loads Google Fonts (typography), which is strictly necessary for rendering and receives your IP address when fonts are fetched. We do not use advertising, retargeting, or cross-site tracking cookies. Legal basis (GDPR): consent (Art. 6(1)(a)) for Analytics cookies; legitimate interest for strictly necessary cookies (including affiliate attribution for a referral link you chose to follow).
We respect Global Privacy Control (GPC) and Do Not Track (DNT) browser signals. If your browser sends either signal, the website's default state is forced to fully denied — no Analytics or Marketing cookies are loaded unless you subsequently opt in yourself via the banner.
We implement appropriate technical and organizational measures to protect your data:
We do not sell, rent, trade, or share your personal information with third parties for their commercial or marketing purposes. We will never monetize your data.
We may share limited information only in these circumstances:
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):
To exercise any of these rights, email support@ownclip.io. We will respond within 30 days (extendable by 60 days for complex requests, with notice).
If you are a California resident, under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of personal information collected in the preceding 12 months: Identifiers (email, display name via Google authentication; email if you contact support). Commercial information (license/purchase status, order data via Lemon Squeezy). Internet or electronic network activity (anonymous usage events and error reports via analytics — see Section 2.5). We do not collect biometric data, geolocation data, or inferences for profiling purposes.
Our privacy-by-design architecture (local media processing, minimal data collection, no advertising) is designed to comply with major global data protection frameworks. If you have specific rights under your jurisdiction's data protection law, contact support@ownclip.io and we will accommodate your request in accordance with applicable law.
OwnClip is not directed to children under 16 (or the applicable age of digital consent in your jurisdiction — 13 in the US under COPPA, 16 in the EU under GDPR). We do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has provided personal information to us (e.g., through support email), please contact support@ownclip.io and we will promptly delete it.
OwnClip processes media data locally on your Mac, which means your recordings, transcriptions, and screenshots never leave your machine unless you explicitly send them to a storage destination you have connected (Section 4). Where such a copy is stored, and in which country, follows from the account and — for your own S3-compatible storage — the region you selected; that is a transfer you direct, not one we make.
The data transfers that do occur:
We do not independently transfer personal data across borders beyond these necessary interactions with the services listed above.
While we do not store user content (recordings, screenshots, transcriptions) on our servers, we do maintain server-side data (authentication profiles, license/purchase status, share metadata, branding settings, and analytics) on Google Cloud infrastructure. If we become aware of a security incident that affects personal data in our possession or on our cloud infrastructure, we will:
For breaches at third-party services (Lemon Squeezy, Google), those providers are responsible for notification under their respective obligations.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For material changes (especially changes to what data we collect or how we use it), we will provide prominent notice through the application, website, or email at least 30 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy. If you disagree with any changes, you should stop using the Service.
If you have questions about this Privacy Policy, want to exercise your data rights, or need to report a privacy concern, contact us at:
Email (privacy, support, legal): support@ownclip.io
Website: https://ownclip.io
We aim to respond to all privacy-related inquiries within 30 days.