Flume privacy policy
Effective
Flume is a download manager for the Mac made by seqavo. It is a Mac app, a browser extension that hands downloads to it, and a download engine that runs inside the app. All three run on your Mac.
This policy explains what Flume can see, where it keeps things, and what it does with them. The short version: Flume talks to the sites you download from, checks dl.seqavo.com for new versions, and sends seqavo nothing unless you send a problem report.
What Flume keeps on your Mac
- Your download list: each file’s address, name, size, where it was saved, its progress, and the page, page title and browser it came from. Kept in Flume’s folder under ~/Library/Application Support until you remove the item or clear the list.
- Your settings: connection limits, speed caps, active hours, folders, which quality you picked for video downloads, and so on.
- Site passwords, only if you tick “Remember in Keychain” when a site asks you to sign in. They are stored in the macOS Keychain, not in Flume’s own files, and you can remove them from Settings or from Keychain Access.
- Logs that describe what the app did, for finding bugs. They stay on your Mac. Help › Export Logs… zips them, and Help › Report a Problem… can attach them to a report. Both remove sign-in tokens and other long codes from the query part of download addresses first.
Flume does not keep an account for you, because it has none.
What the browser extension can access
The extension asks the browser for broad permissions, because catching a download or adding a button on a video page needs them. Here is each permission and what it is used for:
- All websites, and a script on every page: to add the Download button on video pages and to notice when a page starts a download. The script looks for video players and download links. It does not read or record anything else on the page, except as described for the right-click items below.
- Downloads and web requests: to see a download begin, take it over, and hand it to the Flume app. If Flume can’t take one, the browser carries on with it as usual.
- Cookies: read only for the site a download comes from, so that a download that needs you signed in works. The cookies go to the Flume app on your Mac and nowhere else. For a video from a site that needs you signed in, Flume keeps them in a private temporary file until it quits, then deletes it.
- Tabs and navigation: to know which page a download or video came from, so Flume can show it and name the file sensibly.
- Context menus, scripting and the active tab: for the right-click items, such as “Download all links with Flume”. When you choose one, the extension collects the link addresses on that page, or in your selection, and hands them to Flume.
- Native messaging: the channel between the extension and the Flume app on the same Mac. This is how everything above reaches the app.
- Storage: the extension’s own settings, such as sites you have excluded. They are kept in the browser, and synced to your other browsers if you have browser sync turned on.
Nothing the extension reads leaves your Mac. It does not contact seqavo or any other server of its own.
Network connections
Flume connects to:
- The sites you download from. Flume fetches the file in parts over several connections, and passes along your browser’s sign-in for that site when a download needs it.
- Video sites, through the bundled yt-dlp and FFmpeg tools. When you open a page with a video, Flume asks the site which qualities are available, so the Download button can offer them; the video itself is only fetched when you choose one. These tools run on your Mac and are shipped inside the app, not fetched at run time.
- dl.seqavo.com, about once a day, to check for a new version of Flume. Versions up to 1.29.0 checked flume.morshed.im instead. The check sends the version you have and nothing about you or your Mac. Flume asks before installing an update, unless you tell it to install updates automatically.
- reports.seqavo.com, only when you send a report from Help › Report a Problem…. The report carries what you typed, your email if you give one, the versions of Flume, macOS and the browser extension, and the logs if you leave “Attach logs” ticked. The country your connection comes from is recorded with it, and your IP address is used briefly to limit how many reports can be sent.
That is the whole list. Flume contains no analytics, no crash reporter and no advertising. If your Mac uses a proxy, Flume respects it.
What your data is used for
Everything Flume knows is used to download your files and show you how that is going. seqavo does not receive your download list, the sites you visit, your cookies, your passwords or anything derived from them, and so cannot use them for anything.
Who your data is shared with
Nobody. The only parties that see a download are you and the site it comes from. If you send a report from Help › Report a Problem…, it is stored with our hosting provider, Cloudflare, and forwarded to seqavo’s support mailbox. We use it, and the email address if you gave one, only to look into that problem and reply, and delete it once the problem is dealt with.
Mac permissions
- Notifications: to tell you when a download finishes or fails. You can turn these off in System Settings.
- Open at login: off unless you turn it on in Flume’s settings.
- Keychain: only when you choose to remember a site password.
- Automation: asked once, and used only to ask macOS to shut down when you choose “Shut down the Mac” after your downloads finish.
Flume does not ask for access to your files beyond the folders you download into, and never for your camera, microphone, contacts or location.
Retention and deletion
Downloads stay in the list until you remove them. Removing an item deletes Flume’s record of it; the downloaded file stays wherever Flume saved it unless you delete it too.
Deleting Flume removes the app. To remove its records as well, delete the Flume folder under ~/Library/Application Support; its settings are in ~/Library/Preferences/com.morshedx.flume.plist. Flume also places a small file in each browser’s NativeMessagingHosts folder so the extension can reach it. Remembered passwords are removed from Settings or from Keychain Access, and the browser extension is removed from your browser’s extensions page.
seqavo holds no copy of any of this, so there is nothing for us to delete on our side, apart from any problem report you sent.
Children
Flume is not directed at children under 13, and we do not knowingly collect data from them. As described above, we do not collect data from anyone.
Changes to this policy
If Flume ever starts collecting, storing or sharing data in a way this policy does not cover, we will update this page and change the effective date at the top before that version of the app is released.
Contact
Questions about this policy go to [email protected].