Privacy Policy
Effective 22 September 2026. This policy covers two things: the VeloUtils application for macOS, all versions, and the veloutils.app website. They have different answers, so the website has a section of its own.
The app collects nothing. There is no account, no sign-in, no analytics, no telemetry, no crash reporting and no advertising identifier. The app has no server. Nothing you type or open is transmitted to the developer or to any third party.
This website is not the app. It counts visits, without cookies and without identifying you. Section 9 sets out exactly what that means.
1. Data the app collects
None. The app does not collect, receive, store, process or share any personal data, usage data, diagnostic data or identifiers of any kind. This is a statement about the application; for the website, see section 9.
Because nothing is collected, there is nothing to sell, share, link to your identity or use for tracking. In App Store terms, the app's privacy declaration is Data Not Collected.
2. Your documents
VeloUtils runs inside the macOS App Sandbox. It can read and write only the files that you choose — through the system open panel, the system save panel, a drag onto the window, or a file handed to it by Finder. It cannot reach anything else on your Mac.
Your documents are processed in memory on your own machine and are never uploaded. The app never modifies a file you opened. Its only write path is the Mermaid tool's Export, which creates a new PNG or SVG at a location you pick in a save panel.
3. Network access
VeloUtils requests the macOS outgoing-network entitlement for one reason, and we want to be precise about it, because it is the only part of the app that can cause a request to leave your Mac.
The Markdown preview is a real web view. If your own document references a remote image — for example a badge image in a README — the preview fetches that image, exactly as a web browser would. That request goes from your Mac directly to whichever server your document names. The developer neither sees, routes nor logs it. No document content is sent with it.
Clicking a link in the Markdown preview hands the address to your default browser. The preview itself never navigates away.
The Mermaid preview loads its rendering library from inside the app
bundle, not from the network, and renders with Mermaid's strict security
level. It makes no request of its own.
The Markdown, JSON and CSV tools perform no network access at all.
If you open no document that references a remote resource, VeloUtils makes no network request.
4. What is stored on your Mac
One value: the identifier of the tool that was selected when you last closed the window, so that the app reopens where you left it. macOS stores this in the app's own sandbox container. It contains no document content and no personal data.
VeloUtils writes no other preferences, no caches of your documents, no history and no logs. Deleting the app removes its container.
5. Third-party code and services
The application integrates no third-party service, SDK, analytics provider or advertising network. The website is separate and does use one, described in section 9.
It bundles one open-source library, Mermaid, which runs locally inside the app and is never downloaded at runtime. Mermaid and its dependencies are listed with their licences inside the app, under Help › Acknowledgements.
6. Encryption
VeloUtils implements no encryption of its own. It uses only the encryption that
macOS provides, in the form of HTTPS inside WebKit. Its
ITSAppUsesNonExemptEncryption declaration is NO.
7. Children
VeloUtils collects no data from anybody, including children under 13. It contains no advertising, no in-app purchases and no user-to-user communication.
8. Your rights
Data-protection rights such as access, correction, portability and erasure apply to personal data that a controller holds about you. We hold none, so there is nothing to disclose, correct, export or delete. If you believe otherwise, write to the address below and we will answer.
9. This website
Everything above describes the application. This section describes veloutils.app, which does collect a small amount of anonymous traffic data — unlike the app, which collects none.
The site uses Cloudflare Web Analytics to count visits. It records the page you viewed, the page that referred you, general technical information such as browser, operating system and device type, and an approximate country. It does not identify you, does not follow you between sites, and is never used for advertising or sold to anyone.
This site sets no cookies and stores nothing in your browser — no
cookies, no local storage, no session storage. Verified on 22 September 2026: no
page returns a Set-Cookie header.
The site is hosted on Cloudflare Pages, so Cloudflare handles the requests needed to serve it, including your IP address, and acts as our processor for that. Cloudflare derives the approximate country from the IP address; the address itself is not part of the analytics data we can see.
We use this only to learn which pages people find useful. If you would rather not be
counted, any content blocker that blocks
static.cloudflareinsights.com will stop it, and the site works normally
without it.
10. Changes to this policy
If this policy changes, the revised version appears on this page with a new effective date. Material changes will also be noted in the release notes of the version they accompany.
11. Contact
Questions about this policy, about privacy in VeloUtils, or about this website, go to support@veloutils.app.