// App privacy
Effective August 20, 2026
Graphic Meat builds local-first software. This policy explains how apps published by Graphic Meat handle information. It covers every Graphic Meat app: the Mac apps (PhotoBooks, MailVault, MeatPad), the MailMule migration service, and the Graphic Meat apps for Shopify.
The short version
- We do not sell personal information.
- We do not use your content for advertising or AI training.
- We do not embed third-party advertising trackers in our apps.
- The Mac apps keep your files on your device unless you deliberately use a feature that connects to another service.
- The Shopify apps run on our servers because they have to, and store shop settings — not your shoppers' personal details.
Mac apps
These run entirely on your Mac. They require no Graphic Meat account, and we receive none of your content.
PhotoBooks
PhotoBooks processes your selected photos and creates photobook projects and PDF exports on your Mac. Graphic Meat does not receive your photos, projects, or exported books. The app requires no Graphic Meat account and does not perform remote photo processing.
MailVault
MailVault connects to email services you configure so it can retrieve messages and save them locally as standard .eml files. Your email credentials and archived messages are used for that function and are not sent to Graphic Meat. Connections to your email provider are governed by that provider's privacy terms.
MeatPad
MeatPad stores your notes and projects as ordinary files in a folder you choose on your Mac. There is no account, no sync engine, and no proprietary database, so there is nothing for Graphic Meat to receive. Opening a folder of code reads only that folder. The app's Privacy settings let you inspect where its data lives, export it, and delete it.
Where a Mac app is distributed directly by us rather than through the App Store, it checks for updates by requesting an update feed from graphicmeat.com. Like any web request, that reveals the requesting IP address and app version to our server, but it carries none of your content.
MailMule
MailMule moves mail between two IMAP servers you nominate. It is a hosted service, so unlike the Mac apps it briefly handles your credentials — deliberately, and without keeping them.
- Mailbox credentials are held in memory for the life of a migration job. They are never written to our database and never written to logs.
- Message contents stream directly from the source server to the destination server and are never stored on our disk.
- Job metadata — which folders were copied, message counts, and the identifier map needed to roll a migration back — is kept for 7 days and then deleted.
Shopify apps
The Shopify apps (Prime Bundles, Smart Cart, Popup, Post-purchase, Subscriptions, and Meatlytics) are installed by a merchant on their own store. They run on servers we operate in Europe, because pricing has to be calculated at checkout and a merchant's settings have to live somewhere.
For every one of them we store the merchant's shop domain, the configuration the merchant creates, and the Shopify session that authorises the app — which includes the staff name and email address Shopify provides at install. Where an app records the revenue it generated, it stores a Shopify order id and an amount, never the customer attached to that order.
None of these apps reads a shopper's name, email address, phone number, or billing or shipping address from an order. Four of them have specifics worth stating plainly:
- Popup — when a shopper enters an email address to claim a discount, that address is passed straight to Shopify to create a customer record on the merchant's store, tagged so the merchant can find it. We do not keep a copy. To stop the same visitor claiming a prize repeatedly, the app stores a random visitor token that identifies nobody.
- Post-purchase — survey answers are stored against the Shopify order id they came from, with no customer identity attached.
- Subscriptions — the customer portal stores the Shopify customer id Shopify supplies for a logged-in shopper, so a subscription can only be viewed and changed by the person who owns it. It is an identifier, not contact details.
- Meatlytics — store analytics deliberately built so visitors are not identifiable. Each pageview records a path, a country, a session id, and a visitor value derived by hashing the IP address and browser user agent together with a salt that rotates every day. The raw IP address is never stored, the same visitor cannot be linked across days, and no tracking cookie is set on your shoppers.
The apps do not sell merchant or shopper data, share it for advertising, or use it to train models.
If you are a Shopify merchant
For data belonging to your store you are the controller and we are your processor. Uninstalling an app deletes every row belonging to your shop from our database, sessions included. We also honour Shopify's mandatory privacy requests: shop/redact performs the same deletion, and customers/redact and customers/data_request are answered with nothing, because no shopper personal data is held to erase or return.
Our sub-processors are Shopify, which is the source of this data and the platform the apps run on, and Hetzner Online GmbH, which hosts our servers.
Information we receive
The Mac apps do not send your documents, photos, email contents, or archives to Graphic Meat. If you contact us for support, we receive the information you choose to include in your message. Please avoid sending private content that is not needed to resolve your request. Support messages sent from inside a Shopify app carry your shop domain, your message, and any reply address you enter.
Apple, an app store, an operating system, or a distribution platform may separately process purchase, download, diagnostic, or crash information under its own privacy policy and settings. Graphic Meat receives only the information those platforms make available to developers.
Retention and security
App content stored locally remains under your control and is retained until you remove it. Shopify app data is retained until the app is uninstalled or the store is redacted. MailMule job metadata is kept for 7 days. Support messages are kept only as long as reasonably needed to answer your request, maintain relevant business records, and meet legal obligations. No system is perfectly secure, but we limit the information we receive and use reasonable safeguards for information in our possession.
Your choices
You can remove locally stored app data by deleting the relevant files or projects and uninstalling the app. For a Shopify app, uninstalling it removes your data from our servers. To ask about information you have sent directly to Graphic Meat, use the contact form. We may need enough information to verify and respond to your request.
Changes to this policy
We may update this page when an app or its data practices change. The effective date above identifies the latest version. Material changes will be described here before or when they take effect.
Contact
Questions about app privacy can be sent through the Graphic Meat contact form.