Privacy Policy

Your images never leave your Mac.

Framing, previewing, editing and exporting all happen on your device — we never see your pictures, your file names, or your folders. Wideframe does send an anonymous record of how the app itself is running, so we can find errors and see which features people actually use. No accounts, no ads, no third-party analytics, nothing sold. Every field is listed below, and there's an off switch in Settings.

Effective September 5, 2026 · applies to Wideframe for macOS

The short version: All the work happens locally — framing, previewing, editing, exporting, setting a wallpaper — and your images, file names and folders never leave your computer. What Wideframe does send is a small, anonymous record of how the app itself ran: how long a session lasted, roughly what kind of display rig you have, which features you used, and a code when something goes wrong. Section 1 lists every field. No accounts, no ads, no third-party analytics, nothing sold — and an off switch in Settings.

1. Usage signals

Wideframe sends an anonymous record of how the app runs to our own server at marks.wideframe.studio. We use it for two things: finding errors, and understanding how the app is really used so we know what to work on. Signals are on by default — the app tells you so on screen the first time it sends any, and you can switch them off at any time in Settings (section 6 has the details).

This is the whole list. Nothing outside this table is sent.

What's sent Exactly what it contains
Install IDA random identifier the app creates the first time you run it. It is not derived from your hardware and is never linked to your identity. It doesn't expire on its own, and turning signals off destroys it — turn them back on and you get a brand-new one, with nothing tying it to the old.
Session IDA separate random identifier covering a single launch of the app.
SessionWhen it started, how many seconds it was active (rounded to the nearest 30), whether the app exited cleanly, and counts of images opened, exports written, and wallpapers applied.
Display rigHow many monitors you have, a coarse layout string like 3840x2160@2+3840x2160@2P, and counts of built-in, external, and mirrored displays. Whether spanning is on. Bezel gap and an ordered per-display PPI bucket are sent as broad ranges, never exact values. Whether any display is HDR.
Product useWhich feature put a paywall in front of you, the outcome of a purchase or restore, and use of auto-framing, the frame chooser, span, Library, collections, tags, queue, preview surfaces, display workspace, settings, and appearance theme. Names you give collections or tags, searches, and every click/keystroke are never sent.
Output quality & timingCoarse quality grades and broad time ranges for image analysis, framing, export, and wallpaper application—enough to find a slow or soft result, never image contents, raw measurements, or crop coordinates.
Crashes, hangs and resource faultsIf Wideframe crashes, stops responding, or is stopped by macOS for using too much CPU or disk, macOS reports it to us through Apple’s MetricKit on a later launch. We receive the numbers that identify the fault (exception type, signal, exception code), how long a hang lasted, the termination reason macOS gives, the type and name of the underlying error, and the call stack—the list of functions that were running. We also receive your macOS version, Mac model and processor architecture, and the app version that faulted.

A call stack here is not source code or file paths: Apple gives it to us as the name of each compiled binary, its identifier, and a numeric offset inside it—addresses in Wideframe’s own code and in Apple’s frameworks, which we match against our build to find the line that failed. The one thing we do not take is the fully written-out error message, because that can have a file name you chose substituted into it; we take the message template instead. Turning usage signals off stops all of this.
ErrorsAn error domain plus a code from a fixed list — never the message text.
Build & languageThe app version and official build number, its release channel, your macOS major version, and the app language/region setting.
Rig Lab membershipIf — and only if — you joined the Rig Lab pilot and were given a seat, every signal carries a single flag saying so, so we can tell whether the pilot group experiences the app differently. It is a yes/no flag and nothing more. Turning usage signals off in Settings clears it along with your random install ID.
Rig Lab offer codeAt the one moment a Rig Lab seat is issued to you, the offer code we just gave you is recorded, so a seat that went out can be reconciled with what happened next. It travels on that single event only. It is a code we created and handed to you — not a payment detail, and never a card, receipt, or Apple Account.

What we never collect

None of this is ever sent:

How long we keep it

Signals are kept for 13 months, then deleted. They go to our server and nowhere else: no third party receives them, and we don't sell them — not now, not ever.

2. Voluntary feedback and Rig Lab

Wideframe includes an optional Send Feedback form. You choose what to write and affirmatively send each message. Before sending, the app shows the exact diagnostic context it can attach and lets you omit that context. It can include the app version, language, macOS version, Pro status, current surface and mode, coarse display count/layout/density ranges, release channel, and—only while usage signals are enabled—the random install ID from section 1.

Feedback never includes an image, filename, path, folder, clipboard, log, or hidden activity history. Because the text is yours, please do not include personal or sensitive information you do not want us to receive. Feedback is stored in a separate encrypted first-party inbox for up to 13 months, is used only to improve or support Wideframe, and is never placed in the usage-signal database or dashboards.

The limited Rig Lab pilot may invite unusually complex display configurations. If you choose to join, Wideframe sends only the same coarse qualification facts shown in the invitation plus an App Store-signed proof that this is a genuine copy of Wideframe. The proof is verified and immediately reduced to a one-way claim used to prevent duplicate allocations. We do not store your Apple Account, receipt, payment details, or raw proof. Apple handles redemption of the resulting offer code.

3. Your images and files

When you open an image, Wideframe reads it from the location you choose, in order to frame and preview it. All processing — cropping, scaling, auto-framing, and readability adjustments — happens on your Mac. Your images, and everything about them, are never uploaded to us or any third party.

Exports are written to the folder you pick (by default ~/Pictures/Wideframe). "Set as Wallpaper" hands the result to macOS through the system API and nothing more.

File & Photos access

Wideframe requests access to files or your Photos library only to open images you explicitly select and to save exports you ask for. macOS mediates this access through standard permission prompts; you can review or revoke it at any time in System Settings → Privacy & Security.

4. Purchases

Wideframe Pro is a one-time in-app purchase processed entirely by Apple through the App Store. We never see your payment details. Apple validates the purchase and provides the receipt the app uses to unlock Pro features. Apple's handling of your transaction is governed by the Apple Privacy Policy.

Whether a purchase or a restore succeeded is one of the signals in section 1. Your payment details, your receipt, and your Apple Account are not.

5. Analytics & tracking

There is no third-party analytics in Wideframe: no analytics SDK, no crash-reporting SDK, no advertising identifiers, no ad networks, and no trackers of any kind. Nothing follows you across other apps or across the web. We don't build a profile of you, and your data has never been sold or shared with anyone — it never will be.

What the app does send is its own usage signals: first-party, anonymous, listed field by field in section 1, and delivered only to our server at marks.wideframe.studio.

6. Network use

Everything that makes a wallpaper works fully offline — opening, framing, previewing, adjusting, exporting, and setting your desktop. Wideframe connects to marks.wideframe.studio for the signals in section 1 and only when you submit feedback or join Rig Lab for the services in section 2. Purchases and offer-code redemption travel through Apple's StoreKit and App Store.

Signals are on by default. The first time you run a version that sends them, Wideframe tells you so in the app, so you hear it there and not only here. To stop them, open Wideframe → Settings and turn usage signals off. That does two things: the app stops sending, and the install ID on your Mac is destroyed. If you ever switch signals back on, a new random install ID is created and there is no way to connect it to the old one.

Until September 2026 this policy said we deliberately did not take the call stack or termination reason from a crash. We changed that. The first crash ever reported from a real install arrived as four numbers and could not be traced to a line of code, which meant it could not be fixed — so the caution was costing the people it was meant to protect. The section above says exactly what a call stack contains and what we still leave out. As before, we would rather change the sentence and tell you than leave up a promise the app no longer keeps.

An earlier version of this policy promised that any future online capability would be opt-in. We chose differently — on by default, with a notice in the app and the switch above. We'd rather change the sentence and say so than leave a promise up that the app no longer keeps.

7. Children's privacy

Wideframe is rated 4+ and contains no objectionable content, but it is a creative tool intended for general audiences. The signals in section 1 carry no personal information about anyone, so there is none to collect from children either.

8. Changes to this policy

If we change how Wideframe handles data, we'll update this page and revise the effective date above. Material changes will also be noted in the app's release notes.

9. Contact

Questions about privacy? Email contact@wideframe.studio. For help using the app, see Support or write to support@wideframe.studio.