Legal
Privacy Policy
Last updated:
1. Who is responsible
The controller for personal data on this website, including the update checks of the apps, under the EU General Data Protection Regulation (GDPR) is:
TimMade in Germany
nov-ai.de is run by this one private individual. In this policy, “we”, “us” and “our” mean that person.
2. Visiting this website
2.1 Hosting by Netlify
This website is a set of static files hosted by Netlify, Inc. in the USA. When you open a page or download a file, your browser sends a request to Netlify's servers, and Netlify logs the usual request data:
- your IP address,
- the date and time of the request,
- the address (URL) of the page or file requested,
- the referrer, meaning the page you came from, if your browser sends it,
- your browser's user agent, which names your browser and operating system.
- Purpose
- To deliver the website to your browser and to keep the website and its servers secure, for example to notice and stop attacks and misuse.
- Legal basis
- Art. 6(1)(f) GDPR. Our legitimate interest is to show you the website reliably and securely. Without your IP address, a page cannot reach your browser.
- Processor
- Netlify processes this data on our behalf as our processor (Art. 28 GDPR). More in Netlify's privacy policy.
- Transfer to the USA
- Netlify may process the data in the USA. For this transfer we rely on the safeguards Netlify offers under Chapter V GDPR, for example standard contractual clauses approved by the European Commission, or the EU-U.S. Data Privacy Framework if Netlify is certified under it. Netlify's privacy policy has the details.
- Storage period
- How long Netlify keeps these logs is set by Netlify; its privacy policy has the details. We do not keep copies of them, do not use them to find out who you are and do not combine them with other data.
2.2 No cookies, no tracking, no third-party content
This website sets no cookies and uses no other storage in your browser, such as local storage or session storage. There is no analytics, no advertising, no tracking and no social media button. Everything the pages need comes from nov-ai.de itself, including the Three.js library behind the 3D view on the Duo page, and the text uses the fonts already on your device. Your browser does not contact any other company while you visit, unless you follow a link to another website.
To show the current version, file size and checksum of each app, the pages read a small file (releases.json) from this same server and ask it for the size of each download, without downloading it. These are ordinary requests to Netlify, logged like any other page view. If you click a copy button, for example next to a checksum, your browser puts the text on your clipboard; nothing is sent.
3. The apps
Duo, Isle, Isle+ and Iface work on your Mac. They have no account, no telemetry and no analytics, and they send no crash reports. What they read and save stays on your Mac, and we never receive it. That also means we cannot see, change or delete it; you can, as described in section 5.
The apps only connect to the internet in three cases: when you click Check for updates (section 3.3), when Isle loads a cover picture from Spotify, and once when you connect Isle to Apple's Clock app (both in section 3.2).
Each app saves its settings in its own preferences file on your Mac, as macOS apps do.
3.1 Duo
- One picture of your screen, in memory only. With your permission for Screen Recording, Duo takes one picture of your screen when the lid starts moving. It keeps that picture only in memory and throws it away when the picture snaps back. It never saves the picture and never sends it anywhere.
- At the lock screen Duo may use a blurred copy of your desktop picture instead, also only in memory.
- The lid angle sensor. Duo reads it to know how far the lid is open.
- A log file. Duo writes technical events, never screen content, to
~/Library/Logs/Duo.logon your Mac. They include your Mac's model name and when the screen was locked and unlocked.
3.2 Isle and Isle+
- Now Playing. Isle reads what is playing locally from macOS or, if you allow it, directly from Music or Spotify through Apple Events. Through Apple Events it also plays, pauses or skips when you use the island's buttons.
- Cover pictures from Spotify. When Isle reads Spotify directly, it may load the song's cover picture from the web address Spotify gives, which is on Spotify's image server. Like any request on the internet, this shows Spotify your IP address and the usual request data; nothing else about you is sent. The request goes straight from your Mac to Spotify, and we receive nothing. See Spotify's privacy policy.
- Charging and AirPods battery are read locally from your Mac.
- File shelf. Files you put on the shelf stay where they are. The shelf only keeps references to them while Isle runs. If you click AirDrop, macOS's own AirDrop sends the files to the device you choose there.
- Timers. Isle keeps its own timers and alarms in its preferences file, and shows the timers of Apple's Clock app, which it reads from Clock's local preferences on your Mac.
- Timers in Apple's Clock, only if you connect it. If you click Connect next to “Also start timers in Apple's Clock”, Isle writes a small shortcut called “Isle Timer”. macOS's own Shortcuts tool has Apple sign it, which needs the internet, and Shortcuts then asks you whether to add it. The shortcut holds one action, starting a timer, and nothing about you. After that, Isle runs it on your Mac each time you start a timer.
- A log file. Isle writes a log to
~/Library/Logs/Isle.logon your Mac. Besides technical events, it can contain the title of a song when it starts playing and the names of headphones that connect, and in Isle+ when the Mac was locked and unlocked and whether Iface recognised you.
Isle+ also contains Iface, described in section 4.
3.3 Update checks
The apps only look for updates when you click Check for updates. The app then sends one ordinary request to nov-ai.de, hosted by Netlify, for a small JSON file that names the current version. When you click install, it downloads the new version from nov-ai.de and checks it against its SHA-256 checksum and the developer's signature before installing it. Netlify logs these requests like any visit to the website, with the data, purpose and legal basis described in section 2.1; instead of a browser, the user agent names the app. Nothing else is sent.
Duo and Isle show this update address in their settings. If you change it, the app sends these requests to the address you entered instead, and that server's operator receives them.
4. Iface and your face
Iface unlocks your Mac at the lock screen with its normal camera. It is part of Isle+ and also an app of its own. Unlocking is off until you turn it on.
- The camera is on only while you set up or test Iface, and for a few seconds at a time at the lock screen once your face is saved: when you open or wake the locked Mac while unlocking is switched on, and when you rest the pointer on the notch at the lock screen. The second also happens while unlocking is off, as long as “Show at the lock screen” is on; Iface then only tells you that it recognised you. At every other moment the camera is off.
- Camera frames are processed in memory by Apple's Vision framework on your Mac. No picture or video is ever saved.
- What is saved: only numbers that describe your face, in
~/Library/Application Support/Isle/iface.dat, a file only your user account can read. When Iface recognises you with confidence, it adds the numbers of that look to the same file, keeping the last ten at most, so it still recognises you when your light, glasses or hair change. A new scan replaces them. Isle+ and the Iface app share this one file. - Your Mac password is kept in your login keychain on this Mac, only while unlocking with your face is switched on: switching it off removes the password. Iface only types it into the lock screen's own password field, using the Accessibility permission, after clicking the lock screen once so that field appears.
- A log file. The Iface app writes technical events to
~/Library/Logs/Iface.logon your Mac, such as when the Mac was locked and unlocked and whether Iface recognised you. Isle+ writes them to its own log (section 3.2).
Plainly: the numbers that describe your face are biometric data, a special category of personal data under Art. 9 GDPR. They never leave your Mac, and we never receive them. Iface does not send them anywhere: not when you set it up, not when it unlocks your Mac and not when it checks for updates. The same goes for your password.
Whether you set up Iface is your choice, and you can delete your face data and the saved password at any time (see section 5). If you back up your Mac, for example with Time Machine, the backup may contain the face data file like any other file of your user account.
5. Deleting app data
Everything the apps keep is on your Mac, so you can delete it yourself at any time:
- Face data and saved password. In the Iface app, or on the Iface page in the settings of Isle+, click Delete face data. This removes the face numbers and the password Iface saved in your keychain, and switches unlocking off. Isle+ and the Iface app share both, so they are gone from both. One exception: if you click it in the Iface app while Isle+ is running, the password stays, because Isle+ uses it; delete it in Isle+. Do this before you remove the app.
- Files. In the Finder, choose Go, then Go to Folder, and delete:
~/Library/Application Support/Isle, the folder with Iface's face data~/Library/Logs/Duo.log,~/Library/Logs/Isle.logand~/Library/Logs/Iface.log- the settings files in
~/Library/Preferences:com.macbookduo.app.plist(Duo),com.isle.island.plist(Isle),com.isle.app.plist(Isle+) andcom.isle.iface.plist(Iface). Quit the app first.
- Keychain entry. If you removed Iface or Isle+ without clicking Delete face data first, open the Keychain Access app, search for “Isle Iface unlock” and delete that entry.
- The Clock shortcut. If you connected Isle to Apple's Clock app, delete the shortcut “Isle Timer” in the Shortcuts app.
- Permissions and login items. In System Settings, under Privacy & Security, turn off or remove the apps under Screen Recording (called Screen & System Audio Recording in newer versions of macOS), Camera, Accessibility and Automation. Under General, then Login Items, remove any of the apps you set to open at login.
- The apps. Quit each app and move it from Applications to the Trash.
6. Your rights
Under the GDPR you have the right
- to know what personal data we process about you, and to get a copy (Art. 15 GDPR);
- to have wrong data corrected (Art. 16 GDPR);
- to have data deleted (Art. 17 GDPR);
- to have processing restricted (Art. 18 GDPR);
- to have a correction, deletion or restriction passed on to anyone we shared the data with, and to learn who they are (Art. 19 GDPR);
- to receive your data in a common, machine-readable format (Art. 20 GDPR);
- to object to processing (Art. 21 GDPR, see below).
Your right to object: where we process data on the basis of Art. 6(1)(f) GDPR, you can object at any time for reasons arising from your particular situation. We then stop, unless we can show compelling legitimate grounds that outweigh your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Consent. Nothing on this website asks for your consent, because nothing here needs it. Should we ever ask for it, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). In the apps you decide through macOS: you can turn off any permission in System Settings and delete your data as described in section 5.
No automated decisions. We do not make decisions about you by automated means and do not create profiles.
Complaints. You can complain to a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work or where you think the infringement took place. The operator is based in Germany.
We keep no data about you ourselves: the hosting logs are kept by Netlify on our behalf, and everything the apps keep stays on your Mac, where you can see and delete it yourself.
7. Changes to this policy
We update this policy when the website or the apps change in a way that affects your data, or when the law changes. The date at the top shows the current version.