ViBeZ Privacy Policy
Last updated: 24 August 2026
ViBeZ is made by Seven Ounce Computer Pty Ltd, in Australia. This policy covers the ViBeZ app for macOS.
The short version. ViBeZ has no accounts and no user database. We don't know who you are and we keep no record of what you listen to. Five things leave your Mac, and all five are described below.
What stays on your Mac
- Your vibes, genre mappings, themes and settings.
- Your Slack access tokens, in the macOS Keychain.
- Your license record — the key and when it was last verified, also in the Keychain.
- A snapshot of the Slack status you had before ViBeZ changed it, so it can be put back.
- Diagnostic logs, if you turn them on.
None of this is transmitted anywhere by us. Delete ViBeZ and it goes with it.
What leaves your Mac
1. The artist's name — to Apple
To choose a vibe, ViBeZ needs to know the genre of what you're playing. It sends the artist's name and nothing else to Apple's public iTunes Search API, directly from your Mac. Not the track name. Not a timestamp. Not an identifier, and nothing that says which Mac asked. Results are cached on your Mac so the same artist isn't looked up twice.
This request goes to Apple. It does not go to us, and we never see it.
2. Your status — to Slack
When your music changes, ViBeZ sets your Slack status using the token in your Keychain — the same thing that happens when you set your status by hand. When the music stops, it puts back what was there before.
Slack requires the users.profile:read scope in order to read a status at all.
That scope also returns your email address, phone number, real name and custom profile fields.
ViBeZ reads only status_text, status_emoji and
status_expiration, uses them solely to restore what you had, and stores
them on your Mac. Nothing else in that response is read, kept or transmitted.
3. Your Slack token — once, briefly, through our server
Connecting Slack uses OAuth, and OAuth needs a client secret that cannot safely live inside an app anyone can download. So the code-for-token exchange happens on a small server we run.
For that single exchange:
- the token is held under a one-way hash of a secret only your Mac knows;
- it is held for at most 120 seconds;
- it is deleted the moment your Mac collects it — before the response is even sent;
- it is never written to a log.
After that it exists only in your Keychain. There is no account, no user record, and nothing on our server that outlives those 120 seconds.
4. Update checks — to our website
ViBeZ checks for updates using the open-source
Sparkle framework. Each check contacts
vibez.sevenounce.computer, which sees your IP address and standard technical
details your browser or system sends with any web request (user-agent, macOS version), plus
your current app version so we know which builds are still in use. These logs live on our
host (Cloudflare) under their retention policy and are used for nothing but operating the
update feed. Updates themselves are cryptographically signed; an unsigned or wrongly signed
update is refused by your Mac before it can run.
5. Your purchase — through Gumroad
ViBeZ is sold through Gumroad. Gumroad acts as our merchant of record: it processes your payment, handles VAT/GST/sales tax, generates your license key, and keeps the purchase record. We never see your payment details. We see what Gumroad shows us as the seller: the email address on the purchase, the license key, and its status.
When you activate ViBeZ, the app sends your license key — not your identity — to Gumroad's public verification API to check it's genuine, then stores the result in your Keychain. After activation, ViBeZ re-checks at most about once a week, and only ever sends the key. Your Mac caches the result, so being offline doesn't get in your way.
What we don't do
- No analytics, no telemetry, no crash-reporting service beyond the update-check log above.
- No advertising, no tracking, nothing shared with data brokers.
- No user database — there is no record of you to sell, leak, or be compelled to hand over.
Children
ViBeZ is not directed at children, and collects nothing from anyone.
Changes
If this policy changes, the new version appears here with a new date, and anything material is called out in the app's release notes.
back to the mix