No account, no analytics, no advertising, and nothing that follows you between visits. But it is no longer true to say nothing leaves your Mac, so this page lists exactly what does.
last updated 5 August 2026
Vivarium has no account system, sets no cookies, runs no analytics or advertising SDK, and never sends your videos, your library, or anything you make. The app and website send a crash report, feedback you type and send, and a count when the app is downloaded. Update checks and licence validation also make network requests. Feedback can contain any personal information you choose to type. Service providers receive your IP address when handling requests.
Everything else stays on your Mac, in
~/Library/Application Support/Vivarium/ and in your app
preferences: your imported videos and their thumbnails, the loop points you
set, your playlists and schedule, your licence key, your hue and speed
settings, and any feedback drafts you have written. Removing the application alone does not remove these files. Imported
videos may also live in your Movies/Vivarium folder, and preferences are
stored separately by macOS.
If Vivarium or its wallpaper agent crashes, a report is written to disk and sent the next time the app starts — never at the moment of the crash, because doing work inside a dying process is how you lose the report and hang the machine.
A report contains: which of the two processes died, the signal or exception that killed it, its reason, the stack trace, the app version and build, your macOS version, whether the Mac is Apple silicon or Intel, and the two-letter country the request arrived from. That is the whole list.
Home directory paths are replaced with ~ before the
report is written to disk, so your username does not appear in a
file path even in a stack trace. There is no name, no email, no machine
identifier, no serial number, and no way to group two crashes as being from
the same Mac. Reports cannot be read back out by anyone visiting the site —
the database grants permission to add a crash report and no permission at
all to read one.
This is deliberately not Sentry or any other crash SDK. Those bring a vendor, an account, a network client that is not ours, and a payload that cannot be read before it leaves. This is one table and about a hundred lines of code, and it collects nothing a crash does not need.
The Feedback pane sends nothing until you press send. When you do, it transmits the topic you picked, the mood, the message you wrote, and — only if you tick the box — a diagnostics block that is shown to you verbatim beforehand so you can read every character before it goes. The country the request came from is recorded alongside it.
You are not asked for an email address and there is no field for one. If you type your contact details into the message, they are stored, because you put them there; leave them out and there is no way to reply to you, which is the trade.
If sending fails for any reason, the app opens a pre-filled mail draft instead, addressed to hello@getvivarium.app. That draft is yours — nothing is sent unless you send it.
When you download the app from this site, one row is recorded: which version, the country, and the referring website's origin if your browser sent one. No IP address, no cookie, no identifier, and nothing that distinguishes you from the next person downloading the same build.
All three carry a two-letter country code. It is provided by Cloudflare, which derives it from the IP address of the request. The IP address itself is not stored by us — only the country it implies, which is kept so it is possible to tell whether a crash affects one region or everyone. Cloudflare, as the host, sees the IP address in the course of serving the request and keeps standard access logs under its own privacy policy.
The website stores your motion preference in this browser's local storage. This preference is not sent to a server.
The site is static and hosted on Cloudflare Pages. It sets no cookies and runs no analytics. One thing worth naming: it loads two typefaces from Google Fonts, which means Google receives a request from your browser when you visit. You can see this, and everything else the page loads, in your browser's network inspector.
Sparkle checks the update feed when update checks are enabled. Its hosting providers receive the request and ordinary network information. Activating a licence sends its key to our validation endpoint. Saved keys are checked at launch and periodically while the app runs to discover renewals, expiry, and refunds. A network failure keeps the last verified entitlement; subscription access is limited to its verified expiry.
Sales are not open. The planned payment provider is Lemon Squeezy, which handles checkout, card details, receipt emails and licence-key delivery. Vivarium does not store card details. During verification our server sends the licence key to the provider and checks the associated order and subscription. Provider responses may contain buyer details; these are not returned to the app or stored in the new billing mirror. That mirror stores provider record IDs, plan, status and billing dates, not raw keys, buyer emails or payment-card information. A verified key and cached entitlement remain in your Mac’s preferences. Retention and deletion procedures still need to be finalized before sales begin.
Vivarium is not directed at children and collects nothing that identifies anyone, of any age.
Feedback and purchase records may identify you. Contact us to request access, correction, or deletion of information associated with you. If you sent feedback and want it removed, write to hello@getvivarium.app and quote enough of it to find the row, and it will be deleted.
This page is updated before a change ships, not after, and the change is named in the release notes rather than made quietly. It last changed on 5 August 2026, when crash reporting was added and the feedback path moved from opening a GitHub issue to sending directly.
hello@getvivarium.app