Privacy Policy
Reconize ("the App") is developed by Lil Dog Productions, LLC ("we", "us", or "our"). We are committed to protecting your privacy. This Privacy Policy outlines our strict data collection policies and practices.
1. Local-First by Design
We believe your content and identity belong solely to you. Reconize is built to be a local-first application. Your media is processed entirely on your Mac, and the one narrow exception to "nothing leaves your device" is the optional verified-identity feature described in Section 3, which is engineered to hold as little as possible. In particular:
- No Media Collection: All video and image files you sign, verify, or monitor are processed entirely on your local Mac. No media files or frames are ever uploaded to our servers, stored by us, or shared with third parties.
- Local Cryptographic Keys: The cryptographic signing keys (private keys and certificates) generated for your creator profiles are stored securely within the macOS Keychain on your device. We do not have access to these keys.
- Local History Registry: The history of your signed files (watermark IDs, creator handles, and timestamps) is logged locally in an append-only file on your disk. No analytics, tracking, or cloud backup of this history is conducted by us.
2. Network Access
The App makes network requests for three purposes, all optional:
- Trusted Cryptographic Timestamps: During C2PA metadata signing, the App can request a trusted timestamp from an RFC 3161 public Time Stamping Authority (TSA) (the default provider is DigiCert at
https://timestamp.digicert.com). This request transmits only a cryptographic hash of the credentials manifest and contains no media, names, or identifying user information. Timestamps are optional and can be disabled in the App settings. - Identity Verification and Trusted Signing: If you choose to verify your identity (Section 3), the App talks to our verification relay at
relay.reconize.me: once to register the verification, and then each time you sign a file as a verified creator, to have the file's credential signed by our trusted certificate. If the relay is unreachable, signing automatically continues on-device as self-declared; it never blocks your work. - Sign-In Flows: When you start a sign-in (Sign in with Apple, or Google), the authentication itself happens with that provider, under that provider's privacy policy.
3. Verified Identity (Optional)
Reconize lets you optionally verify your identity, so that files you choose to sign carry a "Verified" credential from our trusted certificate instead of a self-declared one. You can verify with Sign in with Apple, with Google, or by proving control of your website domain (a DNS or file token you publish). Verification is entirely optional; the App is fully functional without it, and files signed without it are still signed, watermarked, and tamper-evident.
What is sent when you verify. The sign-in happens directly with Apple or Google. The App then sends our verification relay (relay.reconize.me) three things: the provider's signed token proving your address (or, for a domain, the token check happens server-side), a public key your Mac generates for this registration (the private half never leaves your Keychain), and your App Store transaction proof, used once to confirm a genuine copy of the App.
What the relay keeps. The relay's verification record is deliberately minimal: your registration public key; the provider name (Apple, Google, or domain); a salted one-way hash of the verified address or domain, from which the address cannot be recovered; the App Store transaction identifier; registration timestamps; revocation status; and daily signing counters used for abuse prevention. The relay does not store your email address in readable form, your name, your media, your file names, or the content of anything you sign.
Signing as a verified creator. Each verified sign sends the file's credential bytes (a cryptographic structure, not your media) to the relay, which signs and returns them. These bytes are processed to produce the signature and are not retained. The relay keeps standard operational logs (request timing, status, device identifier) without file content.
Your email on signed files. By default, your verified email is not shown on files you sign; files show your name, handle, and Verified status. Showing the email is a separate, per-profile opt-in switch in the App, off by default, and it only takes effect on files signed through the trusted route. Apple's Hide My Email addresses are fully supported and count as verified.
What stays on your Mac. The verified account details shown in the App (the address on your profile, your channels) are stored locally on your creator profile, as with everything else in Section 1. OAuth tokens are used for the verification and are not stored.
Sharing. We do not sell or share any of this information. Your identity appears inside a file's Content Credentials only when you sign that file.
Disconnecting and deletion. You can disconnect your identity at any time in the App (Profiles → Disconnect), which stops verified signing from your device and keeps your verification record so you can reconnect instantly. To permanently delete the record instead, choose Disconnect and Delete Data in the same dialog: your device sends an authenticated deletion request and the relay erases its record entirely (the device key fingerprint, the hashed identity, and the App Store transaction identifier). If you no longer have the Mac, email hello@reconize.me and we will remove it promptly. You can also revoke Reconize's access from your Google Account at myaccount.google.com/permissions or in your Apple ID settings under Sign in with Apple.
YouTube channel connection. If you choose to connect a YouTube channel to prove you control it, Reconize requests the read-only scope https://www.googleapis.com/auth/youtube.readonly and makes a single API call — channels.list with mine=true — to read only your own channel's ID and handle. Reconize does not access your videos, playlists, subscriptions, comments, analytics, or any other account's data. The channel ID and handle are stored only locally on your device (on your creator profile) and are never transmitted to our servers — the App has no backend account system. The OAuth access token is used once for this read and is then discarded. You can disconnect the channel in the App at any time (Profiles → the channel's remove control), or revoke access at myaccount.google.com/permissions.
Instagram account connection. If you choose to connect an Instagram professional (Business or Creator) account to prove you control it, Reconize uses the Instagram API with Instagram Login and requests only the instagram_business_basic permission, reading only your account’s username and account ID. Reconize does not access your media, insights, stories, messages, comments, or any other account’s data. The username and account ID are stored only locally on your device (on your creator profile) and are never transmitted to our servers — the App has no backend account system. The OAuth access token is used once for this read and is then discarded. You can disconnect the account in the App at any time, or revoke Reconize’s access in your Instagram settings under Apps and Websites. Reconize’s use of Instagram and other Meta Platform Data adheres to the Meta Platform Terms and Developer Policies, including their limited-use requirements, and is never used to develop, train, or improve AI/ML models.
Threads account connection. If you choose to connect a Threads account to prove you control it, Reconize uses the Threads API and requests only the threads_basic permission, reading only your account’s username and user ID. Reconize does not read, publish, delete, or access your Threads posts, replies, mentions, insights, or any other account’s data. The username and user ID are stored only locally on your device (on your creator profile) and are never transmitted to our servers — the App has no backend account system. The OAuth access token is used once for this read and is then discarded. You can disconnect the account in the App at any time, or revoke Reconize’s access in your Threads settings under Account → Website Permissions. Reconize’s use of Threads and other Meta Platform Data adheres to the Meta Platform Terms and Developer Policies, including their limited-use requirements, and is never used to develop, train, or improve AI/ML models.
Google API Limited Use. Reconize's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Reconize does not use Google or YouTube user data — raw, aggregated, anonymized, or derived — to develop, train, or improve any generalized artificial-intelligence or machine-learning models; the only Google data Reconize reads is your own YouTube channel’s ID and handle, used solely to display your verified channel. YouTube data is additionally governed by the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
4. Purchases
Reconize offers an optional one-time "Pro" unlock through Apple's App Store. All payment processing, billing, and refunds are handled entirely by Apple under Apple's own privacy policy. We never see or receive your payment details. Your purchase status is delivered to the App on-device by Apple's StoreKit framework. We do not maintain user accounts; the only server-side records we hold are the minimal verification records described in Section 3, which include the App Store transaction identifier (never payment information) when you verify your identity.
5. No Third-Party Trackers or Analytics
The App does not integrate any usage trackers, advertisement SDKs, analytics packages, or silent crash-reporting tools that transmit info about how you use the app or what files you sign.
6. Children's Privacy
The App collects no personal information beyond the optional, minimal verification records described in Section 3, and it is not directed to children. We do not knowingly collect or maintain any information from children under the age of 13.
7. Our Website
This policy governs the App. Our website (reconize.me) is served through a standard web host that may retain basic, non-identifying server logs (such as IP address and request time) for security and reliability. We do not run advertising or analytics trackers on the site.
Free code claims and the update list: if you request a free unlock code or join the wait list on our site, we collect the email address you submit. It is stored with our infrastructure provider (Upstash, a managed data store) and used for exactly two purposes: delivering your code (and showing it to you again if you return), and occasional product-update emails, each of which includes an unsubscribe link. We never sell, rent, or share this list. To have your address deleted, email hello@reconize.me and we will remove it promptly.
8. Your Rights in the European Economic Area, United Kingdom, and Switzerland
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and the equivalent UK and Swiss laws give you specific rights over your personal data. Because Reconize is local-first, the only personal data we hold about you is the optional, minimal verification record described in Section 3 and, if you opt in on our website, your email address (Section 7). This section explains how those laws apply.
Data controller. The controller responsible for the limited personal data described in this policy is Lil Dog Productions, LLC, Glendale, Arizona, United States. You can reach us about any privacy matter at hello@reconize.me.
What personal data we process, and our lawful basis. We rely on the following lawful bases under Article 6 of the GDPR:
- Verified-identity record (registration public key, provider name, salted one-way hash of your address or domain, App Store transaction identifier, timestamps, and revocation status): processed on the basis of your consent and to perform the verified-signing service you asked for (Article 6(1)(a) and 6(1)(b)). Verification is entirely optional and the App is fully functional without it.
- Operational logs and daily signing counters used to keep the signing relay reliable and to prevent abuse: processed on the basis of our legitimate interests in the security and integrity of the service (Article 6(1)(f)). These logs contain no media, file names, or file content.
- Website email list (free-code and update-list addresses, Section 7): processed on the basis of your consent, which you can withdraw at any time using the unsubscribe link in any email or by writing to us.
Trusted timestamp requests (Section 2) transmit only a cryptographic hash and contain no personal data. We do not subject you to automated decision-making that produces legal or similarly significant effects, and we do not use your personal data to develop, train, or improve any artificial-intelligence or machine-learning models.
Your rights. Subject to the conditions in the applicable law, you have the right to: access the personal data we hold about you; have it rectified if it is inaccurate; have it erased; restrict or object to its processing; receive it in a portable format (data portability); and withdraw consent at any time, without affecting processing already carried out before you did so. Because our verification record stores a salted one-way hash rather than your address, several of these requests are satisfied simply by deleting the record, which you can do yourself at any time.
How to exercise your rights. The fastest route to erasure is built into the App: choose Disconnect and Delete Data in the Profiles dialog, and your device sends an authenticated request that erases the verification record entirely. For the website email list, use the unsubscribe link in any email. For anything else, or if you no longer have the Mac, email hello@reconize.me and we will respond within the timeframe required by law (normally within one month).
International transfers. Our verification relay and email infrastructure are operated in the United States, so the limited data described above is processed there. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, reinforced by the fact that the data we hold is minimized by design: a salted one-way hash rather than your address, and no media or file content.
Retention. We keep your verification record only for as long as your identity remains connected; when you delete it, in-app or by email, it is erased. Operational logs are short-lived and truncated. Website email addresses are kept until you unsubscribe.
Right to complain. You have the right to lodge a complaint with your local data protection supervisory authority. In the EEA you can find yours through the European Data Protection Board (edpb.europa.eu); in the UK, the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would welcome the chance to address your concerns first, so please consider contacting us before you file.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by the "Last updated" date above; continued use of the App or Site after an update constitutes acceptance of the revised policy.
10. Contact Us
If you have any questions or feedback regarding our privacy practices, please contact us at: hello@reconize.me