Skip to content
Poison Powder
  • Apps
  • About
  • Contact
  • English ✓ — current language
  • Español
  • Deutsch
  • Français
  • 日本語
Browse the shelf
The fine print

Privacy Policy

Last revised — 24 July 2026

The short version

Your files never leave your device. Poison Powder apps do their work locally, on your own machine, and there is no server for them to send anything to. There is no account to create and nothing to log in to.

The apps do collect a small amount of pseudonymous diagnostic and usage data through Google Firebase, so I can tell whether a release is crashing. That is the whole of it, and the detail is below.

Your files stay yours

Every image, video, audio file and document you open in a Poison Powder app is read, converted and written on your own device. Nothing is uploaded, copied to a server, or transmitted anywhere. I never see your files, their contents, or their names.

The apps run inside Apple's sandbox and can reach only the files you explicitly choose — through an open panel, a save panel, or by dragging them in. Where an app remembers a folder between launches, it does so purely to reopen the window you left.

What the apps do collect

Each app includes Google Firebase for three purposes. None of them involves your files.

  • Crash reports (Firebase Crashlytics). When an app crashes, a report is sent containing the stack trace, the app version, your device model and the operating system version, tied to a random installation identifier. Without this, a crash that happens only on some machines is invisible to me.
  • Usage statistics (Firebase Analytics). Automatic measurement only — app opens, session length, app version, device model, operating system version, and the country your network connection appears to be in. The apps log no custom events: nothing records which files you converted, which formats you chose, or how any setting is set.
  • Notifications (Firebase Cloud Messaging). Only if you turn on product news — see below.

This data is pseudonymous. It is tied to a random identifier generated on your device, not to your name, your email address or your Apple Account. Deleting the app resets that identifier.

Notifications are opt-in

Nothing is registered for push notifications until you turn on product news yourself. If you do, your device is issued a notification token by Apple and subscribes to a single broadcast list — everyone opted in receives the same message. There is no per-user targeting and no profile behind it. Turning notifications off, in the app or in System Settings, ends it.

Purchases

Where an app offers a paid unlock, the purchase is handled entirely by Apple through the App Store. Apple processes the payment; I never see your card details, your billing address or your Apple Account. The app is told only whether the unlock has been bought.

This website

This site is hosted on GitLab Pages, whose servers keep standard request logs including IP addresses. The site also loads Google Analytics, which sets cookies and measures pages viewed, approximate location by country, and the kind of device and browser you are using. Blocking it with a content blocker or a browser privacy setting costs you nothing here — the site works identically without it.

There are no comments, no sign-up, no newsletter and no advertising.

What is never collected

  • The contents, names or locations of your files
  • Your name, email address, postal address or phone number — unless you write to me
  • Precise location
  • Contacts, calendars, photo libraries or health data
  • Advertising identifiers. The apps do not use App Tracking Transparency and do not track you across other apps or websites.

Your data is never sold, rented or shared for advertising. I use no advertising network and no attribution or marketing SDK.

Who else handles this data

Google, as the operator of Firebase and Google Analytics, processes the diagnostic and usage data described above on my behalf. Apple operates the App Store and the notification service. GitLab hosts this site. Nobody else receives anything.

How long it is kept

Crash reports and usage statistics are retained by Firebase on its default schedules and deleted automatically afterwards. Email you send me is kept for as long as it is useful in answering you, and deleted when it is not.

Your rights

Under UK and EU data protection law you may request a copy of any personal data held about you, ask for it to be corrected or erased, or object to its being processed. Because the diagnostic data described here is pseudonymous, I generally cannot connect it to you — so the practical route is to stop it at source: uninstalling an app ends all collection from it, and a content blocker stops this site’s analytics.

For anything else write to greg@poisonpowder.com and I will answer within 30 days. If you are unhappy with the answer, you can complain to the UK Information Commissioner’s Office at ico.org.uk.

Children

These are file conversion utilities, not products aimed at children, and nothing here is knowingly collected from a child under 13.

Changes

If this policy changes, the revision date at the top of the page changes with it. A change to what is actually collected will also be described in the release notes of the version that makes it.

Contact

Questions about any of this go to greg@poisonpowder.com.

Poison Powder

Small, potent remedies for Mac. Not to be taken internally.

The house All apps About Contact
The fine print Privacy Policy Terms of Use greg@poisonpowder.com
© 2026 Poison Powder Apps · Handle with care · All remedies sold as measured doses