Your privacy matters to us. Obry is designed to do its job on your Mac — not in our cloud — so the screens you capture, the text we recognise from them, the cards you create, and the folders they live in never reach our servers. We can't see them.

Obry runs entirely on your Mac. Every capture, scroll stitch, OCR pass, card edit, history view, and preference change happens on-device. No screen content, no recognised text, no card data, no thumbnails, and no usage analytics are sent to Obry or to any third party. Obry has no accounts, no telemetry, and no analytics. The few things that do touch the internet — an update check, the Paddle checkout if you buy, and the email that delivers your license key — are listed exhaustively below.

This notice explains the small amount of information that does leave your Mac, what we do with it, and what we deliberately don't. It covers the Obry menu-bar app, the obry.app website, the Sparkle update feed, and any support we provide (together, the "Service"). The rules for using Obry are in our Terms of Use. If you ever have a question, email us at yevhen@obry.app.

  1. Information that stays on your Mac.

    Almost everything Obry works with lives on your Mac and never reaches us. That includes:
    • Region captures. Images obtained through Apple's ScreenCaptureKit framework when you press the region-capture shortcut (default Option+Tab) and draw a rectangle on the selection overlay. Captures are saved as PNG files.
    • Scroll captures. Long captures produced by the scroll-capture shortcut (default Option+S). Frames are stitched together on your Mac using a sum-of-absolute-differences offset algorithm running on the green channel of each frame; no frames or intermediate results leave your Mac during stitching.
    • Optical character recognition (OCR). Text extracted by Apple's on-device Vision framework, both as a fast live preview during selection and as a more accurate pass after capture. Recognition runs entirely on your Mac, without any network call.
    • Cards and card state. The floating cards that appear after a capture, including the image and text tabs, the link between a text card and the image it came from, dimensions, screen coordinates, dock state (which screen edge a card is docked to), opacity and lock state, and the position of any controls.
    • Editable text and formatting. Anything you type, paste, or change inside a text card, including bold, italic, underline, strikethrough, bullet and number lists, checkbox lists, links, text and background colours, and the results of the inline calculator.
    • Gesture and animation state. Data produced by trackpad gestures such as drag, pinch-to-resize, eight-way edge resize, click bounce, and the two-finger throw-to-dock physics. This data is used only to drive Obry's animation system, which runs at up to 120 frames per second using CVDisplayLink.
    • History and thumbnails. The arc-scroll history, its 240-pixel JPEG thumbnail cache, and the JSON metadata that describes each card.
    • Preferences. Application preferences stored in UserDefaults, including your custom hotkeys for region and scroll capture, throw-animation parameters, dock-side preferences, and other behaviour toggles.
    • Trial state. The date Obry was first launched, written to your Mac’s local preferences so the app knows how many days of the 14-day trial are left. It is a date and nothing more — no identifier, no account, and no message to us. Nothing about your trial is reported anywhere.
    • Multi-display layout. Information about which connected display a capture came from, used to position cards correctly across screens.
    • Diagnostic logs. Standard application logs written to ~/Library/Logs/Obry/, including crash reports, breadcrumbs produced during a session, and aggregated MetricKit payloads (hang reports, CPU and disk exceptions, and crash context) saved under ~/Library/Logs/Obry/metrickit/. MetricKit is Apple's on-device diagnostic framework; the payloads are written to disk by the operating system, are never transmitted by Obry, and remain available for your own review or, if you choose, to include in a support email.

    By default, all captures, thumbnails, and metadata are written to ~/Pictures/Obry/, organised into the following subfolders:

    • ~/Pictures/Obry/Screenshots/ — full-resolution PNG captures, named with the date and time (for example, Obry-14-April-2026-21-25-00.png);
    • ~/Pictures/Obry/.metadata/ — one JSON file per card, named after the card's identifier;
    • ~/Pictures/Obry/.thumbnails/ — cached 240-pixel JPEG thumbnails used by the history view.

    If a folder from a previous version of the application named ~/Pictures/Copse/ is present on first launch, Obry will offer to migrate its contents into ~/Pictures/Obry/. You may open, copy, move, rename, or delete any of these files at any time using Finder. Deleting the application removes its preferences; deleting the folder removes your capture history. Obry cannot recover content you delete locally. By default, the application is configured to retain captures for seven (7) days, after which entries beyond the retention window are removed; you can change this from preferences.

  2. Information that leaves your Mac.

    A small number of things need the internet — here's the full list, what each does, and what we send.

    2.1 Purchases (Paddle)

    Obry is free for 14 days. If you keep it, it is a one-time payment of US$12 — €12 in the euro area, £12 in the UK — with tax included in that price or added on top at checkout, depending on where you live. Paddle.com Market Limited ("Paddle") is the Merchant of Record: Paddle is the seller on the transaction, and Paddle — not us — takes the payment, calculates and remits VAT and sales tax, and issues your receipt. At checkout Paddle collects what it needs for that: your name, email address, billing address, country, payment method, and, where it applies, a tax identifier. Paddle handles all of it under its own privacy policy at paddle.com/legal/privacy. We never see your card details. What reaches us is a purchase notification containing your email address and the order details, used only to generate and send your license key — see the next section.

    2.2 Your license key

    A license key is a short signed token. It contains the email address you bought with and the date of purchase, signed with our private key so the app can confirm it is genuine. The app verifies that signature locally — there is no license server, no activation call, no periodic re-check, and no device fingerprint.

    When Paddle confirms a purchase, a Cloudflare Worker generates the key and passes it to Resend, our email provider, which sends it to you. Your email address passes through both services for that delivery. We do not keep a customer database. The Worker stores nothing once the email is on its way; the record of your purchase lives with Paddle.

    2.3 Re-sending a lost key

    If you lose your key, ask and we will send it again. We look up a transaction matching your email address through Paddle's API, rebuild the key from that record, and email it via Resend. To stop the page being used to flood someone's inbox, we keep a one-way fingerprint of the address for an hour and of the requesting IP address for ten minutes, then delete them; the address itself is never stored.

    2.4 Update checks (Sparkle)

    Obry checks for new versions using the open-source Sparkle framework. It fetches a static appcast.xml file, and the update package itself if there is one, from a public URL hosted on GitHub Pages. That is an ordinary request for a static file, so it exposes ordinary HTTP request metadata: your IP address, your user-agent (which includes the Obry and macOS version), and the file requested. GitHub records those in standard server logs. No identifiers are sent — no license key, no email address, no device fingerprint, no install or analytics ID — and nothing about your captures or how you use the app. Updates are verified against Obry's published public key before installing. Checking is automatic by default; installing is not. You can change both in preferences.

    2.5 Support correspondence

    If you email us for help, we receive your email address, the contents of your message, and any attachments you choose to include (for example, screenshots or excerpts from ~/Library/Logs/Obry/crash.log). If you attach a capture or a log, you are voluntarily sharing the content of that file with us.

    2.6 Website

    The obry.app website is served as static files and links to these legal pages, to a downloadable build of the application, and to the Paddle-hosted checkout for license purchases. Your browser's standard request information (IP address, user-agent, requested URL, referer, and timestamp) reaches the hosting infrastructure that serves the site and is retained briefly for security and debugging. To show the price in your currency, the home page loads Paddle's script, which sends your IP address to Paddle so it can work out your country; Paddle handles it under its own privacy policy. Paddle sets cookies strictly necessary to process a checkout; we do not use advertising cookies, third-party analytics, tag managers, session-replay tools, or tracking pixels on the website.

  3. macOS permissions.

    macOS controls sensitive capabilities through its Privacy & Security settings. Obry asks only for what its features actually need, and you can review or revoke each permission at any time in System Settings → Privacy & Security.
    • Screen Recording — required for any form of capture. Without it, Obry cannot function. The macOS prompt for this permission is shown the first time you attempt a capture.
    • Automation (Apple Events) for Notes — requested only the first time you use the optional "Export to Apple Notes" action on a card. The export runs locally on your Mac via AppleScript and does not transmit card content to Obry.
    • Desktop, Documents, and Downloads folder access — requested by macOS only when you choose to save or drag an exported card into one of those locations.
    • Local Network — requested only when development diagnostics are enabled in a development build; production builds do not require it.

    Obry does not request microphone, camera, contacts, calendar, reminders, location, Photos library, Full Disk Access, HomeKit, Bluetooth, Motion, Health, or Media-and-Apple-Music permissions.

  4. Clipboard, drag-and-drop, and other hand-offs.

    Obry interacts with the macOS clipboard only when you ask it to. When you choose "Copy Image" or "Copy Text" from a card's controls or context menu, the corresponding image or text is placed on your system clipboard; thereafter, ordinary macOS clipboard behaviour applies and any application you paste into may receive that content. Obry never reads or writes the clipboard automatically. Similarly, when you drag a card out of Obry, the application provides the content as a PNG image (for image cards) or as plain UTF-8 text (for text cards); the receiving application — whether Finder, a text editor, a chat client, or any other — controls what happens to it from there. Obry does not record where you drag content or what you paste it into.
  5. How we use what we collect.

    We only use the small amount of information described above to:
    • generate and email your license key, and re-send it when you ask;
    • deliver and maintain the Service, including the secure delivery of updates;
    • respond to your support requests;
    • comply with tax, accounting, anti-fraud, export-control, and other legal obligations;
    • detect, prevent, and address abuse and security incidents;
    • enforce the Terms of Use and the purchase terms applicable to your order.
  6. Who we share it with.

    We don't sell your personal information, share it for advertising, or use it to train machine-learning models. The only parties who see any of it are:
    • Paddle, as the Merchant of Record for all purchases. Paddle independently controls the data it collects at checkout under its own privacy notice.
    • Update host (GitHub). The Sparkle update feed and the update binaries are hosted on GitHub. Standard request information reaches GitHub when an update check runs.
    • Cloudflare, which serves the website and runs the Worker that generates and dispatches your license key.
    • Resend, our email provider, which delivers your license-key email. It receives your email address and the contents of that message.
    • Our email provider for support, which relays correspondence you send us.
    • Legal, regulatory, or safety bodies, where we are required to disclose information to comply with applicable law, a valid legal request, or an enforceable governmental requirement, or where disclosure is needed to protect the rights, property, or safety of Obry, our users, or the public.
    • Successor entities, in the event of a merger, acquisition, reorganisation, sale of assets, or insolvency, subject to terms at least as protective as this Privacy Notice.
  7. What we don't do.

    Some things we've deliberately chosen not to build in:
    • We do not upload screen captures, scroll stitches, thumbnails, OCR text, card edits, or card metadata to any server at any time.
    • We do not run any analytics, advertising SDK, attribution framework, crash reporter, or session-replay tool inside the application. Crash logs, breadcrumbs, and MetricKit diagnostic payloads stay on your Mac in ~/Library/Logs/Obry/ unless you choose to send them to us.
    • We do not inspect, moderate, index, or read the contents of your ~/Pictures/Obry/ folder.
    • We do not run user accounts. There is no sign-up, no username, no password, and no profile.
    • We do not keep a customer database. Purchase records live with Paddle, not with us.
    • We do not sell, rent, or trade personal information for marketing.
    • We do not use your content, your gestures, or your usage patterns to train or improve machine-learning models, our own or any third party's.
  8. Legal bases for processing (EEA, UK, Switzerland).

    If you are in the European Economic Area, the United Kingdom, or Switzerland, our processing is based on one or more of the following legal bases under the General Data Protection Regulation and the UK GDPR:
    • Performance of a contract — to deliver your license key, to re-send it when you ask, and to provide support.
    • Legitimate interests — to deliver software updates, to secure our infrastructure, to prevent abuse of license keys, and to communicate essential product information, where those interests are not overridden by your rights.
    • Compliance with a legal obligation — to satisfy tax, accounting, sanctions-screening, and other regulatory requirements.
    • Consent — where we rely on consent (for example, optional announcements), which you may withdraw at any time without affecting the lawfulness of prior processing.
  9. Retention.

    • On-device content is retained on your Mac until you delete it. Obry has no ability to access or delete it. The application's default retention setting removes captures from the local history after seven (7) days; you can change or disable this in preferences.
    • Purchase records. We keep no customer database, so there is no order record on our side to retain. Paddle holds the transaction record as Merchant of Record, for as long as its own policy and tax law require.
    • Support correspondence is kept for up to twenty-four (24) months after the end of the exchange, or longer if required to defend a claim or comply with law.
    • Server logs for the website, the license Worker, and the update feed are kept for up to thirty (30) days, or longer when a specific security investigation requires it. The exact retention period for GitHub-hosted assets and for data processed by Paddle is governed by their respective policies.
  10. Your rights.

    Depending on where you live, you may have the right to access, correct, or delete the personal information we hold about you, to obtain a portable copy of it, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to lodge a complaint with your local supervisory authority. Residents of California have equivalent rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know, correct, delete, and opt out of the "sale" or "sharing" of personal information; we do not sell or share personal information as those terms are defined under California law. Residents of other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) have analogous rights.

    To exercise any of these rights, write to yevhen@obry.app. Worth knowing first: we hold almost nothing to show you or delete. Your captures, cards, and trial state sit on your Mac under your control — delete the files in ~/Pictures/Obry/ and the app's preferences and they are gone, with no involvement from us.

    Because we keep no customer database, requests about your purchase — access, correction, deletion, or a copy of the record — need to go to Paddle, which holds that data as Merchant of Record. You can reach Paddle through the contact route in its privacy policy. Write to us anyway if you are unsure and we will point you to the right place. We answer within the timeframes the law sets, and we will not treat you differently for asking.

  11. International transfers.

    The infrastructure that supports the Service, as well as Paddle, may operate from the United States, the European Union, and the United Kingdom. Where personal information is transferred outside your jurisdiction, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum, or, where available, adequacy decisions.
  12. Children.

    Obry is not directed to, and is not intended for use by, children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe that a child has provided personal information to us, please contact us and we will take steps to delete it.
  13. Security.

    We use commercially reasonable administrative, technical, and organisational safeguards to protect the limited personal information that we hold. These include encryption in transit (TLS), scoped access controls on our systems, minimisation of collected data, cryptographic verification of update binaries against Obry's published public key, and the deliberate choice not to build servers that hold your capture content. No system is perfectly secure; if we become aware of a security breach affecting your personal information, we will notify you and the appropriate authorities to the extent required by law.
  14. Changes to this notice.

    We may update this Privacy Notice to reflect changes in the application, our practices, or the law. When we do, we will update the "Last updated" date above and, for material changes, post notice on the website or within the application. Material changes take effect no earlier than thirty (30) days after posting. Your continued use of the Service after that date constitutes acceptance of the updated Privacy Notice.
  15. Who we are, and how to reach us.

    Obry is made and run by Yevhen Yurchuk, a sole proprietor based in Ukraine, who is the data controller for the limited processing described in this notice. For privacy questions, requests, or complaints, write to yevhen@obry.app. If you are in the EEA or the UK, you may also complain to your local data-protection authority.