RenderMac

Privacy Policy

Effective: 2026-07-22  ·  Applies to buyers, providers, and admin/support users of the RenderMac Service  ·  Contact: support@rendermac.com

Counsel review pending. This Privacy Policy accurately reflects what the RenderMac control plane actually collects, stores, and encrypts today (verified against packages/control-plane/src, its migrations, and services/webhookSecurity.ts / byobStorage.ts's encryption code), but has not yet been reviewed by outside counsel for jurisdiction-specific obligations - most notably CCPA/CPRA "Do Not Sell or Share" mechanics if California traffic grows, and GDPR Article 27 EU representative requirements if any EU personal data is processed at meaningful volume. RenderMac's primary market today is US-based buyers/providers; the rights described in Section 8 are offered broadly as a matter of policy, not because RenderMac has confirmed each named regulatory regime formally applies.

1.What we collect

CategoryExamplesSource
Account & organization dataOrganization name/kind, admin user email, API key metadata (name, scopes, prefix - never the plaintext secret after issuance)You, at account/key creation
Job metadataService ID, input schema fields, status, timestamps, fee/hold/charge amounts, failure codes, capacity-cell identifiersGenerated by the API as you submit and the system processes jobs
Job ContentThe actual media/URLs/captions you submit as job input, and the resulting output artifactYou, via job input; see Section 2
Provider device dataHostname, chip model, RAM, disk/scratch/cache usage, capability probes (VideoToolbox/Metal/ANE), heartbeat timestamps, enrollment/pairing historyThe RenderMac Host agent, automatically while paired and online
Payment dataStripe customer ID, Stripe Connect account ID, checkout session status, payout batch amounts and approvalsStripe (we never receive or store raw card numbers)
Usage & security logsAPI request logs (method, path, status, timing), rate-limit counters, admin audit log entries, webhook delivery attemptsGenerated automatically by the control plane

2.Job Content specifically

Job Content (the media you submit for processing and the artifacts produced from it) is handled as follows:

3.Provider & device data

Running RenderMac Host on your Mac shares device telemetry (hostname, chip, capability probes, storage headroom, heartbeat) with the control plane so jobs can be matched to capable, available devices, and so RenderMac can compute and pay provider earnings accurately. RenderMac Host does not inspect, index, or transmit the contents of your Mac outside of the specific job input/output artifacts your device is leased to process, and does not run when paused, when on battery (if you enable AC-power-only mode), or outside your configured operating schedule.

4.How we use data

5.Sharing & subprocessors

RenderMac does not sell personal data. Data is shared only with the following categories of service providers, each acting as a processor/subprocessor on RenderMac's behalf under their own data protection commitments:

SubprocessorRole
Stripe, Inc.Payment processing (buyer top-ups), Stripe Connect payouts (providers)
Cloudflare, Inc.DNS, edge network, Workers/Pages hosting, Cloudflare R2 object storage (default artifact backend in production)
Neon (Neon, Inc.)Managed Postgres hosting for the control-plane database
Your own storage provider (BYOB)If you configure BYOB, your chosen S3/R2-compatible provider stores your job artifacts directly under your own account

The complete, contractually binding subprocessor list for customers who execute the Data Processing Addendum is maintained in the DPA.

6.Retention

Account, job metadata, and audit-log data are retained for the life of the organization's account plus a reasonable period thereafter for legal, billing, and dispute-resolution purposes. Ledger transactions and admin audit log entries are append-only by design (enforced at the database layer, not just in application code) and are retained indefinitely as the authoritative financial and security record, consistent with standard bookkeeping/audit retention practice.

7.Security

Representative security measures implemented in the control plane today: bearer/API-key secrets and device credentials are stored only as salted SHA-256 hashes, never in plaintext, after their one-time display; webhook signing secrets and BYOB bucket secret access keys are encrypted at rest with AES-256-GCM under keys distinct from each other and rotatable independently; every admin action is written to an append-only audit log with the acting principal, action, target, and reason; named admin roles (see services/adminRbac.ts) restrict what a support or finance hire can do relative to a full superadmin; and provider payout batches require two distinct named admins to approve before any real money moves, enforced as a database constraint in addition to application logic.

8.Your rights

Regardless of your jurisdiction, you may request: (a) a copy of the personal data RenderMac holds about your account, (b) correction of inaccurate data, (c) deletion of your account and associated personal data (subject to the append-only financial/audit retention described in Section 6, which RenderMac retains as required for legitimate business, tax, and legal purposes), and (d) an export of your Job Content and job history. Submit requests to support@rendermac.com; we will respond within a reasonable time, targeting 30 days.

9.Children's privacy

The Service is not directed to, and RenderMac does not knowingly collect personal data from, individuals under 18. If you believe a minor has provided personal data to RenderMac, contact support@rendermac.com and it will be removed.

10.International transfers

RenderMac's infrastructure (Neon Postgres, Cloudflare) is US-region by default today (see DEPLOYED.md's Neon aws-us-east-1 project). If you or your end users are located outside the United States, your data may be transferred to and processed in the United States. RenderMac does not currently offer region-pinned EU data residency; contact support@rendermac.com before relying on the Service for personal data subject to a legal residency requirement RenderMac cannot yet meet.

11.Changes & contact

RenderMac may update this Privacy Policy; material changes will be reflected by updating the effective date above. Questions or requests: support@rendermac.com.