Privacy Policy
Last updated: September 8, 2026
Our Commitment to Privacy
Vendivo is operated by Spitfire Creative. The released Mac app processes camera video and microphone audio locally. Forthcoming phone companions are designed to send video directly to the Mac over USB or the local network. We do not operate a cloud video relay that receives or stores that content, and the app and website do not use advertising or cross-site tracking SDKs. The optional Vendivo Account Center processes account metadata separately from the local media path.
Information Processed on Your Mac
Vendivo processes information needed to discover cameras, route a production, and explain its health. This can include camera and microphone names, stable device identifiers, selected roles, show settings, and stream-health information. A connected phone may also report its model, platform, operating-system version, battery state, thermal state, and frame-delivery metrics.
This operational information remains on the Mac and is not automatically transmitted to Spitfire Creative. Local system logs may contain device names or identifiers. We receive those details only if you choose to include them in a support message or diagnostic attachment.
What Is Not Automatically Sent to Us
- Camera streams, microphone audio, or local recordings
- Show queues, private seller cues, scene settings, or stream credentials
- Camera names, device identifiers, or production-health metrics
- Usage analytics or advertising profiles
- Contacts, precise location, or advertising identifiers
If you choose to use the Account Center, the account information described below is deliberately sent to Vendivo. Camera video, microphone audio, local recordings, stream keys, and private seller cues are not part of that account service.
How Vendivo Works
Cameras available to the released Mac app are processed locally. Public iPhone and Android companion apps are planned; their camera transport is designed to use USB or the local network without passing through a Spitfire Creative relay. Core camera operation:
- Does not require a Vendivo cloud video service or account for its core local production path
- Does not upload camera content to Spitfire Creative
- Writes a recording only when you start a Vendivo or OBS recording
- Sends a broadcast to a third-party destination only when you start that output
Permissions We Request
Vendivo may request the following permissions when a feature needs them:
Camera Permission
The Mac app uses Camera permission to enumerate integrated, external, and compatible Continuity cameras and to preview or route the camera you select. Forthcoming phone apps will request their own Camera permission for phone capture.
Microphone Permission
The Mac app uses Microphone permission when you test an input level or choose a microphone for a managed OBS production. The level test is held in memory and is not recorded. A microphone you apply to the production can be included in an OBS broadcast or recording. Vendivo Phone Camera (Direct) and OBS Virtual Camera are video-only, so camera-device destinations require a separate microphone choice.
Local Network Permission
Vendivo uses Local Network permission for camera discovery and local streaming when those features are active. OBS Studio may separately request its own network permissions under the OBS Project's software and policies.
Photos Permission
Forthcoming phone companions may request Photos or media-library access only when you enable an on-phone recording feature. Completed recordings are designed to remain in that local library.
Local Storage and Credentials
Vendivo stores production preferences, camera assignments, show queues, and local timelines in macOS preferences and Application Support. Stream keys and OBS WebSocket credentials are stored in the Mac Keychain. OBS configuration remains in OBS's Application Support data. Recordings are saved in Movies/Vendivo or another folder you choose.
Deleting the Vendivo app bundle does not automatically remove these settings, Keychain entries, OBS configuration, timelines, or recordings. You can remove local recordings and supporting data from the Mac separately when you no longer need them.
Optional Account Center
When you sign in at app.getvendivo.com, Vendivo processes the identity-provider issuer and account identifier, verified email address, display name, optional profile image, workspaces, membership roles, plan and entitlement state, and security and audit events needed to operate the account.
Trusted-device records use a randomly generated installation identifier and public-key information, plus platform, app version, registration time, last-seen time, and revocation state. Vendivo does not request a hardware serial number. Marketplace records can include provider status, seller-safe account references, granted capabilities, and verification times. Provider credentials are encrypted on the server and are not returned to the customer portal, staff console, or desktop app.
Sign-In, Sessions, and Invitations
Sign-in is handled by a managed OpenID Connect identity provider. Vendivo stores the provider's stable issuer and subject identifiers rather than a password. Secure, HTTP-only, host-only cookies maintain the session; a separate same-site value protects state-changing requests. Login transactions, invitation records, session records, source-network pseudonyms, and related audit events are processed to prevent abuse, join invited members, and investigate security incidents.
Website and Download Requests
The documentation search remembers up to five recent searches in your browser's local storage. A service worker may cache the site shell and brand assets for faster or offline loading. The download page requests signed release manifests from our file-delivery provider; that provider may receive ordinary request data such as IP address, browser user agent, timestamp, and requested file. The support link opens your email application rather than submitting a hidden website form. Authenticated Account Center and operations responses are marked not to be stored by shared caches, and its service worker does not cache account or API responses.
Broadcast Destinations and Other Third Parties
Vendivo does not integrate third-party advertising or cross-site analytics services. We use service providers for website and application hosting, managed PostgreSQL, identity, transactional email, and release delivery. These providers process only the information necessary to deliver their service. When you start a broadcast, OBS Studio or the destination's browser tools send the program video and selected audio directly to the service you chose, such as Whatnot, YouTube, Twitch, or a custom RTMP/RTMPS endpoint. That destination receives the stream under its own privacy policy. OBS Studio is separate software maintained by the OBS Project.
When phone purchasing becomes available, Apple StoreKit or Google Play Billing will handle purchases and entitlement restoration under the applicable store's policies.
In-App Purchases
Vendivo phone plans are not currently available to purchase. When purchasing opens through the App Store or Google Play, Apple or Google will handle the transaction. We will not receive or store your payment-card information. Refer to the applicable store privacy policy for its handling of purchase data.
Data Security
We do not maintain a centralized database of camera streams. Sensitive production credentials are kept in the Mac Keychain. Use a trusted local network for Wi-Fi streaming. Vendivo does not claim end-to-end encryption for the local Wi-Fi video transport; use USB when you do not want video sent over Wi-Fi.
Account data is transmitted over HTTPS and stored in a managed database with access controls, encrypted secret fields, separate migration and runtime identities, and audited staff operations. No security control eliminates all risk; contact us promptly if you believe an account has been compromised.
Retention and Account Deletion
We retain account information while the account is active and as needed to provide the service, protect users, resolve disputes, maintain required audit and transaction records, and comply with law. Short-lived login and invitation records expire automatically, while security and operational records may be retained longer when needed for fraud prevention, legal compliance, or a documented support matter.
An account owner can request deletion from the Account Center. The workspace enters a 14-day recovery period during which an owner can restore it. General self-service registration will remain closed until the post-recovery erasure process and retention schedule are operationally approved. Once activated, Vendivo will remove or de-identify account data that is not subject to a legitimate legal, security, billing, or record-retention requirement. Revoking an installation prevents new cloud entitlements but does not remotely interrupt an active local production.
Children's Privacy
Vendivo is not directed to children under 13, and the app does not send us camera content.
Changes to This Policy
If we make changes to this privacy policy, we will update the "Last updated" date at the top of this page. We may provide additional notice when required by law or appropriate for a material change.
Support Messages and Your Rights
If you contact support, we receive the message and attachments you choose to send through your email provider and ours. We retain that material only as needed to resolve the request, operate our business, and meet legal record requirements. You may request access, correction, or deletion of personal information associated with you, subject to applicable law and record-retention requirements.
Contact Us
If you have questions about this privacy policy or Vendivo's privacy practices, please contact Spitfire Creative at:
Email: [email protected]
Legal Basis for Processing
Core camera processing does not automatically send its content or local production data to Spitfire Creative. We process account and support information to perform the service you request, protect the service and its users, comply with legal obligations, and pursue legitimate operational interests that do not override applicable privacy rights. File-delivery providers process ordinary request information to deliver the website and downloads, and a broadcast destination processes content you direct to it.