Privacy Policy

Last updated: September 11, 2026. Applies to every McMizzle app, including AmbientCast and Calorie Burndown.

The short version: your data stays on your own devices and in your own Apple Account. None of it passes through any server McMizzle operates, because there isn't one — every McMizzle app talks directly to the devices and services you've chosen to connect it to (your own printer on your own network, or YouTube), to Apple's own on-device frameworks (like HealthKit), or to your own iCloud account to keep an app's own settings and history in step across your devices, and nowhere else.

What McMizzle apps store, and where

Specifics vary by app, but the pattern is the same everywhere:

What McMizzle apps don't do

Third-party services

Where a McMizzle app connects to a service on your behalf (e.g. AmbientCast to YouTube for optional live streaming), what that service then does with your data on its own side is governed by that service's own privacy policy, not this one. How the McMizzle app itself requests, uses, stores, and deletes that data is covered here — see Google user data below for the full account of AmbientCast's YouTube Live feature.

No McMizzle app shares your data with any third party for McMizzle's own purposes. There are no analytics providers, advertising networks, tracking SDKs, or parent, subsidiary, or related entities with access to your data — the only services your data ever reaches are the ones you personally chose to connect the app to, and it goes there directly from your device. Apple's iCloud is the one thing you do not separately choose to connect, and it is not a third party in this sense: it is your own Apple Account, McMizzle has no access to what is stored there, and what goes into it is listed above.

Retention, deletion, and revoking access

Nothing here has to be requested from McMizzle, because none of it reaches McMizzle. Almost all of it lives on your own device, where you control it directly; the exception is what an app syncs to your iCloud, which sits in your Apple Account and is covered by the last point below:

Deleting a McMizzle app removes everything on your device. Whatever an app synced through iCloud remains in your Apple Account, where McMizzle cannot reach it. Since no copy is ever sent to a McMizzle server, there is nothing left behind for you to request the deletion of, and no deletion request to make.

Google user data (AmbientCast's optional YouTube Live feature)

This section exists specifically to satisfy Google API Services User Data Policy disclosure requirements for AmbientCast's optional YouTube Live broadcasting feature.

What's requested and why. When you turn on YouTube Live in AmbientCast's Settings and sign in, it requests the single OAuth scope https://www.googleapis.com/auth/youtube — the narrowest scope Google's device-flow sign-in (used because tvOS has no in-app browser for a standard OAuth redirect) permits for YouTube at all; the read-only youtube.readonly scope isn't sufficient because the app needs to create and manage a broadcast, not just read your channel. With that scope, AmbientCast only ever calls:

Nothing else on your YouTube account is ever read, listed, or modified — no other videos, playlists, subscriptions, comments, or channel settings. Every one of these calls is a direct consequence of something you started: a broadcast you began yourself, or a print you chose to have a timelapse made of. AmbientCast never creates a broadcast, and never uploads anything, on its own — and never ends one either, with the single exception described next.

The one thing it does without being asked. At launch, AmbientCast looks for live broadcasts left running by a previous session of the app — a print that ended while the Apple TV was asleep, or the app replaced mid-stream — and ends them, telling you it has done so. Without this, a dead broadcast can sit live on your channel indefinitely. It will only end a broadcast that both carries AmbientCast's own title suffix and has nothing currently publishing to it, so a stream you are running from another device or another tool is never touched.

Data protection. Your OAuth access and refresh tokens are stored in your device's Keychain, on-device only, encrypted at rest by iOS/tvOS's standard Keychain protection. In transit they are sent only over encrypted HTTPS/TLS connections, and only ever directly to Google's own token and YouTube Data API endpoints — never to any server McMizzle operates, because there isn't one. No McMizzle employee or system can read them, since they exist nowhere McMizzle can reach.

Retention and deletion. Your OAuth tokens stay in your device's Keychain only until you either sign out of YouTube from AmbientCast's Settings (which deletes them immediately, on-device) or revoke AmbientCast's access directly from Google at myaccount.google.com/permissions (which invalidates them on Google's side even if the local copy hasn't been cleared yet). No copy of these tokens is ever retained anywhere off your device — there is no McMizzle-operated server for any of it to be retained on. One thing derived from these calls does leave your device: the list of timelapses you have published, including their video identifiers and titles, syncs through your own iCloud account as described under "What McMizzle apps store, and where". The tokens themselves never do, and nothing derived from them ever reaches McMizzle.

Limited Use. AmbientCast's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Google user data is used only to provide the YouTube Live broadcasting feature described above; it is never transferred to others except as necessary to provide that feature (which, since there is no McMizzle server, means it is never transferred at all), never used for advertising, never used to build profiles or for any purpose other than the one you invoked it for, and never read by humans.

This website

Everything above is about the apps. This site is worth a short note of its own, because until now this policy didn't mention it at all.

Contact

Questions about this policy: see the support page for the right place to ask, per app.