Privacy Policy
Last updated: September 30, 2026
Summary
- We collect and upload nothing: no accounts, no telemetry, no crash reporting.
- Your sign-in credentials, task history and downloads stay on your device only.
- Downloads happen directly between you and the platform — traffic never passes through our servers.
- Checking for updates contacts our version server; that is our only data channel, and it carries none of your personal data.
Introduction
This Privacy Policy explains how MAD Toolbox handles information. It applies to this website and to the MAD Toolbox application, whatever the distribution channel, including versions installed through the Microsoft Store. The party responsible under this policy is MAD Producer Studio (“we”, “us”).
MAD Toolbox is built on a local-first, minimum-collection principle: the app does all of its work on your device, and we operate no servers that gather user data. Please read this policy to understand what stays on your device, which network requests occur, and how responsibility is divided between us and third-party platforms.
Information we do not collect
We do not collect, record or upload any personally identifiable information. Specifically:
- This website uses no tracking cookies and no analytics services. Your language preference is saved only in your browser's localStorage, so the site can remember your interface language.
- The app has no account system and never asks you to register for or sign in to any service of ours.
- The app contains no telemetry: we do not collect usage behaviour, device information or performance data.
- The app contains no crash reporting: crash information is never sent to us or to any third party.
We build no user profiles and we do not track you across devices or services.
Data stored on your device
Everything the app works with stays on your device, including:
- Task records and task logs;
- Preferences and application state;
- Bilibili credentials obtained through QR-code sign-in (cookies such as SESSDATA);
- Cookie files you import manually;
- Media files you download (saved by default to the Downloads/MADToolbox folder in your system download directory; you can change the location).
None of this data exists on our servers, and we keep no copies of it. Uninstalling the app or clearing its data deletes it for good. When you export a task log, the app redacts credential fields (such as SESSDATA and bili_jct) automatically, but you should always inspect a log before sharing it.
Network requests
The app does not send your data to us. To complete a task you initiate, the app — together with the open-source tools it invokes, such as BBDown, yt-dlp and musicdl — communicates directly with the third-party platform you target, for example Bilibili, YouTube and other sites supported by yt-dlp, or the music platforms. That traffic does not pass through our servers, and we cannot see it.
When the app starts it checks for updates by fetching a version manifest from our distribution service at openlist.frameneo.com (cached by FRAMENEO's CDN). The request itself carries none of your personal data. The CDN provider records standard network logs — such as IP addresses — in line with industry practice, for security and service-quality purposes.
When the app is installed through the Microsoft Store, data processing tied to the store itself — download, update and licence verification — is governed by the Microsoft Privacy Statement and is Microsoft's responsibility.
Third-party services and responsibility
MAD Toolbox is a graphical front-end for independent open-source tools, including BBDown, yt-dlp, FFmpeg, MediaInfo, Deno and musicdl. Each tool runs under its own licence; see the third-party notices included with the application.
- Content, accounts and terms of service on each platform are defined and enforced by that platform. Whether and what you may download depends on the platform's rules and on your own account permissions.
- Credentials you provide — QR-code sign-in or imported cookie files — are used only to authenticate you to the corresponding platform. They are never used for any other purpose and are never sent anywhere other than that platform.
- We are not responsible for the availability of third-party platforms, for their content, or for any action a platform takes with regard to your account.
The app does not bundle its external tools. FFmpeg, yt-dlp, BBDown, Deno and MediaInfo are installed on demand from within the app, either from the FRAMENEO CDN mirror or through system package managers such as WinGet or Homebrew — depending on the source you pick in Settings. musicdl is always installed separately and is never distributed with the app. Requests made while installing such dependencies go to the corresponding source — the CDN mirror or the package repository.
Copyright and tool neutrality
MAD Toolbox does not provide, host, index or recommend any audio or video content. It has no content library and no catalogue: download targets are determined entirely by the links or IDs you enter. In this respect the app is a neutral, general-purpose channel, no different from a web browser or a download manager.
We expressly require that, when using the app, you:
- fetch only content you are authorised to access;
- comply with each platform's terms of service and with the copyright law of your jurisdiction;
- use downloaded material solely for personal study and creative work;
- never redistribute, share or sell unauthorised material.
The music feature depends on musicdl, which is licensed for non-commercial use and is not distributed with the app; the relevant licence terms and compliance requirements are stated in the app's dependency installation notes.
MAD Toolbox is fully open source, so anyone can audit its code and network behaviour. If you are a rights holder and believe that content infringes your rights: because we store no content, please direct your claim to the platform that actually hosts it. You may also contact us, and we will cooperate where reasonably possible.
Data security
- All user data stays local — there is no remote storage to breach;
- This website is served over HTTPS;
- In-app update packages are verified against a minisign public key, and installation is refused on signature mismatch;
- Release artifacts ship with a SHA256SUMS.txt file so you can verify their integrity yourself.
If you discover a security issue, please contact us through GitHub's private vulnerability reporting (see Contact us) instead of disclosing credentials or exploit details in a public issue.
Children's privacy
MAD Toolbox is not directed at children, and we do not knowingly collect personal information from anyone, including children. Because the app collects no data at all, children cannot provide personal information to us through it. If you believe personal information from a child has reached us in some other way, contact us and we will delete it promptly.
Changes to this policy
If we change this policy, we will publish the change on this page and update the effective date at the top. Significant changes may also be announced on the website or in the app. Continuing to use the website or the app after a change takes effect means you accept the updated policy.
Contact us
For any question, request or complaint about this policy or our privacy practices, reach us on GitHub:
- GitHub Issues: github.com/MAD-Producer/MAD-Toolbox/issues
For security matters, please use GitHub's private vulnerability reporting rather than a public issue. We will never ask you for credentials or personal information outside these channels — beware of phishing attempts impersonating us.