Legal
Privacy Policy
Effective 7 October 2026
The short version. Convoy has no accounts, no analytics, no telemetry, no ads and no crash reporting. The developer never receives anything from the app: not your downloads, not your browsing, not your cookies. Your download list and settings stay on your Mac. Every network connection Convoy makes is listed below, and you can check all of it in the source code.
This policy covers the Convoy app for macOS, its browser extension, and this website. Convoy is made by an independent developer (“I”, “me”), who you can find on LinkedIn. Contact details are at the end.
What stays on your Mac
- Your download list. To show your queue and resume downloads after you quit, Convoy saves each download’s address, file name, size, progress and the page it came from in
~/Library/Application Support/Convoy/downloads.json. For video streams it can also save the request headers needed to continue, which may include that site’s cookies. - Your settings, in the app’s standard macOS preferences.
- The files you download and any partial files from interrupted downloads, in the folder you choose. Settings → Advanced finds leftovers and deletes them when you ask.
- Logs. Convoy writes diagnostic messages to the macOS system log. URLs, file names and video titles are marked private there, so macOS hides them. The log never leaves your Mac unless you share it yourself.
None of this is sent to me or anyone else. Deleting Convoy and the ~/Library/Application Support/Convoy folder removes it.
Network connections the app makes
Convoy only connects to the internet for the four reasons below.
1. The downloads you ask for
When you start a download, Convoy connects to the server hosting that file. If the download came from your browser, it sends the same cookies, referrer and headers your browser would have sent, so downloads behind a login work. These go only to the site the download comes from, as part of that download. The site sees your IP address, like any other download, and its own privacy policy applies.
2. Update checks
Once a day, Convoy checks thedynamicpunk.github.io/convoy/appcast.xml for a new version. If one exists, it asks before downloading it from GitHub Releases, and installs it only if it’s signed with the project’s key. The check sends no information about your Mac beyond what any web request carries (your IP address and the app’s name and version). You can turn the daily check off in Settings → General.
3. YouTube helpers, only if you install them
YouTube support relies on open-source tools (yt-dlp and the components it needs). Convoy doesn’t include them. If you choose to install them in Settings → YouTube, Convoy downloads them from those projects’ official GitHub releases and checks each file against a known SHA-256 checksum before using it. When you then download from YouTube, yt-dlp connects to YouTube, and a helper runs locally on your Mac (at 127.0.0.1) without being reachable from the internet. Some YouTube downloads let yt-dlp read your browser’s cookies. That’s off unless you choose to use it.
4. Things you open yourself
Links in the app, such as “Report an issue”, open in your browser like any other link.
The browser extension
The extension needs broad permissions to do its job, so here is what each part does:
- Access to the pages you visit lets it notice downloads and videos and add the download button over them. It reads what it needs to find media on the page. It doesn’t record your browsing history.
- Downloads, context menus and notifications let it hand downloads to Convoy, add the right-click items, and tell you when something was sent.
- Cookies (optional, and only granted if you allow it) let it pass a site’s cookies along with a download from that site.
- Native messaging is how it talks to Convoy. Everything it collects goes to the Convoy app on your Mac, through a small program inside the app, over a local connection. Both ends check that the other really is Convoy before exchanging anything.
The extension stores a single setting in your browser (whether it’s catching downloads), and sends nothing to me or to any server of its own.
This website
This site is a static page hosted on GitHub Pages. It sets no cookies and has no analytics or tracking scripts. To show a download count, your browser asks GitHub’s public API for the number of release downloads. GitHub may log technical information such as IP addresses when you visit, under the GitHub Privacy Statement.
Third parties
The only outside services involved are the ones described above: GitHub (website, updates and helper downloads), the sites you download from, and YouTube if you use the YouTube helpers. Each has its own privacy policy. I don’t sell, share or receive any personal data, because Convoy doesn’t send me any.
Children
Convoy doesn’t collect personal information from anyone, children included.
Changes to this policy
If Convoy’s data handling changes, this page will be updated and the effective date above will change. Its full history is public in this website’s repository. A change that sends any data off your Mac will be announced in the release notes first.
Contact
Find me on LinkedIn.
For bugs and questions, open an issue on GitHub.