Convoy

Legal

Privacy Policy

Effective 7 October 2026

The short version. Convoy has no accounts, no analytics, no telemetry, no ads and no crash reporting. The developer never receives anything from the app: not your downloads, not your browsing, not your cookies. Your download list and settings stay on your Mac. Every network connection Convoy makes is listed below, and you can check all of it in the source code.

This policy covers the Convoy app for macOS, its browser extension, and this website. Convoy is made by an independent developer (“I”, “me”), who you can find on LinkedIn. Contact details are at the end.

What stays on your Mac

None of this is sent to me or anyone else. Deleting Convoy and the ~/Library/Application Support/Convoy folder removes it.

Network connections the app makes

Convoy only connects to the internet for the four reasons below.

1. The downloads you ask for

When you start a download, Convoy connects to the server hosting that file. If the download came from your browser, it sends the same cookies, referrer and headers your browser would have sent, so downloads behind a login work. These go only to the site the download comes from, as part of that download. The site sees your IP address, like any other download, and its own privacy policy applies.

2. Update checks

Once a day, Convoy checks thedynamicpunk.github.io/convoy/appcast.xml for a new version. If one exists, it asks before downloading it from GitHub Releases, and installs it only if it’s signed with the project’s key. The check sends no information about your Mac beyond what any web request carries (your IP address and the app’s name and version). You can turn the daily check off in Settings → General.

3. YouTube helpers, only if you install them

YouTube support relies on open-source tools (yt-dlp and the components it needs). Convoy doesn’t include them. If you choose to install them in Settings → YouTube, Convoy downloads them from those projects’ official GitHub releases and checks each file against a known SHA-256 checksum before using it. When you then download from YouTube, yt-dlp connects to YouTube, and a helper runs locally on your Mac (at 127.0.0.1) without being reachable from the internet. Some YouTube downloads let yt-dlp read your browser’s cookies. That’s off unless you choose to use it.

4. Things you open yourself

Links in the app, such as “Report an issue”, open in your browser like any other link.

The browser extension

The extension needs broad permissions to do its job, so here is what each part does:

The extension stores a single setting in your browser (whether it’s catching downloads), and sends nothing to me or to any server of its own.

This website

This site is a static page hosted on GitHub Pages. It sets no cookies and has no analytics or tracking scripts. To show a download count, your browser asks GitHub’s public API for the number of release downloads. GitHub may log technical information such as IP addresses when you visit, under the GitHub Privacy Statement.

Third parties

The only outside services involved are the ones described above: GitHub (website, updates and helper downloads), the sites you download from, and YouTube if you use the YouTube helpers. Each has its own privacy policy. I don’t sell, share or receive any personal data, because Convoy doesn’t send me any.

Children

Convoy doesn’t collect personal information from anyone, children included.

Changes to this policy

If Convoy’s data handling changes, this page will be updated and the effective date above will change. Its full history is public in this website’s repository. A change that sends any data off your Mac will be announced in the release notes first.

Contact

Find me on LinkedIn.
For bugs and questions, open an issue on GitHub.