Privacy Policy
Last updated: August 2026
What happens on your machine
Image generation, video generation, movie assembly, music-video generation, and faceless-reel generation all run locally, using your own GPU. The prompts you write and the media you generate are never uploaded to us. They stay in your local output folder until you decide to do something with them.
What can leave your machine — and only if you turn it on
A few features are opt-in cloud connections. None of them are required to use MoneyForge, and none of them are enabled by default without your own account/API key:
- Distribution. If you connect a YouTube, TikTok, Instagram, Facebook, Pinterest, or X account and choose to post, the finished video or image is sent to that platform through your own connected account — the same as uploading it yourself through their app.
- Premium captions and voices. If you supply your own Gemini or ElevenLabs API key, the relevant text or audio is sent to that provider to generate captions or narration. Without a key, MoneyForge falls back to a fully local alternative (a local language model via Ollama, or local Chatterbox voice cloning) that never leaves your machine.
- License activation. Verifying a purchase requires checking your license key. Depending on how you purchased, this is a request to the payment provider's own license-check API (Gumroad, LemonSqueezy), or, for Stripe purchases, a signature verified entirely offline with no network call. Separately from this, every activation — regardless of provider — is also checked against a MoneyForge-operated device-limit service that enforces the "one device per license" limit stated in your purchase terms; see "License device-limit enforcement" below for exactly what that service stores.
License device-limit enforcement
Your license lets you activate MoneyForge on a limited number of devices (currently one). To enforce that limit, MoneyForge checks with a MoneyForge-operated cloud service when you activate a license, roughly every 7 days while the app is running (a "heartbeat"), and when you deactivate a device.
- What's stored. A device identifier generated by your own installation (not derived from any personal information), and a one-way-hashed activation token for that device. Your license key itself is never stored in readable form — only a one-way hash of it is used to look up your record. Nothing about your prompts, generations, or usage is ever sent to or stored by this service.
- Why. Solely to prevent one license key being used on more devices than your plan allows.
- Availability. If this service is unreachable, activation and continued use are never blocked — the check simply fails open.
- Retention & deletion. Deactivating a device (Settings → License → Deactivate this machine) removes that device's record from this service.
Google user data (YouTube distribution)
If you connect a YouTube channel to publish generated videos, MoneyForge requests two Google OAuth scopes: youtube.readonly (to confirm which channel you're connected as) and youtube.upload (to publish a video you generated to that channel).
- What we access and store. When you connect an account, MoneyForge reads and stores, locally on your machine only: your YouTube channel ID, your channel title, and your channel's subscriber count (kept only to support an in-development feature gate that requires a minimum subscriber count; it is not currently used for anything else and is never displayed or transmitted anywhere). We also store the OAuth access token, refresh token, and token expiry that Google issues for the connection. MoneyForge does not access or store your subscriptions, watch history, comments, playlists, or recommendations, and does not read or upload any video except the one you explicitly choose to publish.
- Use. This data is used only to call the YouTube Data API directly from your machine — to confirm your connected channel and to upload the specific video you chose to publish.
- AI/ML training. MoneyForge never uses Google user data to develop, improve, or train any AI or machine-learning model, generalized or otherwise.
- Sharing. This data is never shared with any third party, sold, or used for advertising.
- Retention & deletion. This data persists locally only until you click Disconnect next to the account on MoneyForge's Distribution page — which deletes the stored tokens and account data from your local database immediately, and also revokes the token with Google — or until you revoke access directly from your Google Account permissions page at any time.
MoneyForge's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How this data is protected
MoneyForge is a local desktop application, not a cloud service — this shapes how Google user data is protected:
- No MoneyForge server in the loop. Your tokens and channel data are stored only in a local database file on your own computer. They are never transmitted to, or held by, any MoneyForge-operated server, because none exists in this flow.
- Encrypted in transit. Every call to Google's APIs, and the OAuth authorization flow itself, happens over TLS.
- PKCE-protected authorization. The OAuth sign-in flow uses PKCE (Proof Key for Code Exchange), so the authorization code can't be intercepted and exchanged by anything other than your own MoneyForge installation.
- Credentials kept out of the shipped application. The OAuth client secret used to talk to Google is held in a local environment configuration file, never bundled into the distributed application itself.
- Local access control. The MoneyForge interface that can view or manage a connected account sits behind its own local login, and the stored data is protected by your operating system's own user-account and file permissions, the same as any other file on your machine.
- You control deletion. You can remove stored tokens and account data at any time — see Retention & deletion above.
What we collect
We don't operate an account system for MoneyForge — there's no MoneyForge cloud database of your prompts, your generations, or your usage. The one exception is the narrow device-limit record described above, used solely to enforce your license's device cap. Beyond that, the only information tied to a purchase is what your payment provider (Gumroad, LemonSqueezy, or Stripe) collects to process that purchase, governed by their own privacy policies.
Third-party services
If you choose to use them, Gemini, ElevenLabs, Ollama (local), and the distribution platforms listed above each operate under their own privacy policies and terms. MoneyForge only sends data to these services when you've explicitly configured and enabled them.
Changes to this policy
If this policy changes in a way that materially affects what data leaves your machine, we'll update this page and the date above.
Contact
Questions about this policy: privacy@moneyforgestudio.com