IsoBridge Privacy Policy
Effective date: October 5, 2026
Last updated: October 5, 2026
This Privacy Policy explains how PixelDimension Ltd. ("we", "us") handles personal information when you use the IsoBridge macOS application (the "App") and the online services that support it: the sign-in and license service, the Zoom account-linking service, and the software-update service (together, the "Services").
Controller: PixelDimension Ltd., No. 23, Lane 52, Da'an Street, Xizhi District, New Taipei City 221, Taiwan (新北市汐止區大安街52巷23號). Contact: raymond@pxdim.com. We have not appointed a data protection officer or an EU representative; the App is not offered in the European Union.
1. Summary
- Meeting audio and video never reach our servers. The App receives meeting media from Zoom on your Mac, only after the meeting host grants permission, and sends it only to NDI® receivers on your local network. The App does not write recording files.
- Our servers process only what is needed to sign you in, link your Zoom account, let the App join meetings on your behalf, and deliver updates: your email address, a random device ID, session and security records, and your Zoom OAuth tokens (stored encrypted).
- We use only one Zoom API: we obtain your Zoom Access Key (ZAK) so the App can join meetings as you. We do not read your Zoom profile, contacts, meetings, chats or recordings.
- We do not sell or rent personal information, do not use it for advertising or profiling, and the App contains no analytics, advertising or crash-reporting SDKs.
2. Information we process
2.1 Information processed by our servers
| Data | How we get it | Why we use it | How it is stored | How long we keep it |
|---|---|---|---|---|
| Email address | You enter it to sign in | Identify your account; send one-time sign-in codes; security limits | Plain text in our database (Railway PostgreSQL) | While your account exists. There is currently no automatic deletion of account records; we delete them on request (Section 7). |
| One-time sign-in code (4 digits) | Generated by our server | Verify that you control the email address | Only a keyed hash (HMAC-SHA256) is stored; the code itself is sent to you by email | Valid 5 minutes; single use; up to 3 attempts. The record is removed when you request a new code, and by an hourly clean-up once it has been expired for 24 hours |
| Sign-in security counters | Created when you request or enter codes | Rate limits (60-second cool-down, 5 codes per hour) and lockout after 10 wrong codes within 24 hours | Stored with your account record | While your account exists; counters reset after a successful sign-in or when their time window passes |
| Session token | Generated by our server after you sign in | Keep you signed in on that Mac | Your Mac keeps the token in the macOS Keychain; our server stores only a SHA-256 hash with an expiry date | 90 days, or until you sign out or sign in again on the same Mac; expired sessions are deleted by an hourly clean-up |
| Device ID | A random identifier (UUID) created by the App — not a hardware serial number or advertising ID | Keep separate sessions for each Mac you use | Your Keychain and our session record | Deleted together with the session |
| IP address | Sent with every request to our services | Abuse prevention (per-address rate limit) | Our code stores only a SHA-256 hash of the address with a request counter | Removed by an hourly clean-up once older than one hour |
| Zoom OAuth access and refresh tokens | Issued by Zoom when you authorize the App | Obtain a ZAK when you ask the App to join a meeting; refresh access when it expires | Encrypted with AES-256-GCM before storage; the encryption is bound to your session, and the key is held only in server configuration | Until you disconnect Zoom in the App, sign out, sign in again on that Mac, your session expires, or Zoom refuses a token refresh — whichever comes first (see Section 5) |
| Authorization state and 6-digit confirmation code | Generated by our server when you link Zoom | Make sure the Zoom authorization completed in your browser belongs to the App session that started it | Stored only as hashes | State: 10 minutes, single use. Confirmation code: 10 minutes, 3 attempts; an unconfirmed authorization is deleted after a failed or expired confirmation, or replaced when you start again; otherwise it ends with your session |
| Zoom Access Key (ZAK) | Requested from Zoom each time you join | Lets the Zoom Meeting SDK join a meeting as you | Not stored by our servers; passed to the App, which keeps it in memory only | For the duration of the join request; Zoom documents a 5-minute validity |
| Meeting SDK authorization token (JWT) | Signed by our server when you join | Authorizes the App's Zoom Meeting SDK | Not stored by our servers; kept in App memory only | Valid for 1 hour |
We do not enable request logging in our application code or in our Cloudflare Workers. Our hosting providers may keep their own operational logs about connections to their platforms under their own policies.
2.2 Information that stays on your Mac
| Data | Where it goes | Notes |
|---|---|---|
| Meeting details you enter (meeting ID or invite link, passcode, display name, webinar registration email or token) | Sent only to Zoom through the Zoom Meeting SDK | Not sent to our servers. Meeting passcodes are kept in memory only and are never written to show files, snapshots or logs |
| Meeting content: participants' video, audio, screen shares and display names | Processed in memory on your Mac; video and audio are sent as NDI® streams to receivers on your local network | Available only after the meeting host grants local-recording permission. Never sent to us. The App writes no recording files. Display names are shown in the App to help you choose sources |
| Show files and session snapshots | Saved where you choose (show files) or kept in memory until you quit (snapshots) | Contain channel and routing settings only — no credentials, tokens, passcodes or full invite links |
| Connection statistics (round-trip time, jitter, packet loss, NDI receiver count) | Kept in memory (up to 3,600 samples); written to a CSV file only when you choose "Export connection log" | Contain no names, meeting IDs, passcodes or credentials |
| Optional customer Meeting SDK credentials ("custom SDK" mode) | Used on your Mac to sign a short-lived token | Never sent to us. The Client Secret is saved in your macOS Keychain only if you tick "remember"; you can remove it in the App ("Forget this SDK") |
| Preferences (appearance, last-used settings tab and connection mode) | macOS user defaults | Local only |
The App does not access your camera or microphone for its own purposes. macOS may ask for microphone and camera permission because the Zoom Meeting SDK requires it; the App joins meetings with your camera off and microphone muted. The App asks for Local Network permission because NDI® uses your local network.
2.3 Software updates
When you choose Check for Updates, the App downloads the update feed and, if you accept, the update package from our update service on Cloudflare. As with any web request, your IP address and the App's user-agent (including its version) are processed by Cloudflare to deliver the files. The App does not check automatically and does not send a system profile. Update packages are verified with a digital signature before installation.
3. Zoom data
When you connect your Zoom account, Zoom asks you to approve the App's access. The App requests only the permission to read your Zoom Access Key (user:read:zak). We use it only to join the meetings you choose, as you. We do not use Zoom data for any other purpose, do not combine it with other data, and do not share it except with Zoom itself. Your use of Zoom, including the meetings the App joins, remains subject to Zoom's own terms and privacy statement. The Zoom Meeting SDK included in the App communicates directly with Zoom; that processing is governed by Zoom's privacy statement.
4. Service providers
We use the following providers to operate the Services. They process personal information on our behalf and under their own security commitments.
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. | Public entry point for our license service (TLS termination, request filtering); hosting of the update feed and release files (Cloudflare Workers and R2) | All requests from the App to our services, including your IP address, email address during sign-in, and session token |
| Railway Corporation | Hosting of our license service and database | Everything listed in Section 2.1 |
| Postmark (ActiveCampaign, LLC) | Delivery of sign-in code emails (open and link tracking disabled) | Your email address and the one-time code |
| Zoom Communications, Inc. | Zoom authorization, ZAK issuance, and meetings joined by the App | OAuth exchange data and tokens; meeting participation through the Zoom Meeting SDK |
Our license service and database run on Railway's cloud infrastructure; Cloudflare operates a global network; Postmark sends email from the United States. These providers may process information outside Taiwan, and we rely on their contractual security and confidentiality commitments.
We may also disclose information if required by law or to protect the rights, safety and security of our users and services.
5. Your choices and controls in the App
- Disconnect Zoom (Settings → Account & Connection): immediately deletes your Zoom tokens and any pending authorization from our servers. It does not remove the authorization inside your Zoom account; to do that, remove the App in the Zoom App Marketplace (Manage → Added Apps → Remove).
- Remove the App in Zoom: Zoom invalidates the tokens. The encrypted copies we hold can no longer be used and are deleted the next time the App tries to use them, when you disconnect Zoom or sign out, or when your session expires (at most 90 days). To delete them immediately, also use Disconnect Zoom or contact us.
- Sign out: deletes the session and any Zoom tokens linked to it from our servers and removes the saved sign-in from your Keychain.
- Uninstall: see the App documentation for removing the App and its Keychain entries from your Mac.
6. Legal bases (EEA/UK users)
Performance of our contract with you (sign-in, Zoom linking, joining meetings, updates); our legitimate interests in keeping the Services secure (rate limiting, lockouts, abuse prevention); your consent for linking your Zoom account, which you can withdraw at any time as described in Section 5.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal information, to receive a copy in a portable format, and to withdraw consent at any time. You may also lodge a complaint with your data-protection authority.
To exercise these rights, email raymond@pxdim.com from the email address you use to sign in (or tell us that address), and state your request. We may need to verify your identity before acting. We will respond within 30 days, or sooner where applicable law requires. Deleting your account removes your email address and security records, all sessions and all stored Zoom tokens from our database.
8. Security
We protect personal information with measures that include: HTTPS for all App-to-service traffic; a Cloudflare entry point that accepts only known API paths and small request bodies; an origin server that rejects any request not carrying a shared secret added by that entry point; hashing of session tokens, sign-in codes, authorization state and IP addresses; AES-256-GCM encryption of Zoom tokens at rest; one-time codes with short expiry, attempt limits and lockouts; storage of your session in the macOS Keychain; and signed, notarized App releases with signature-verified updates. Traffic between Cloudflare and our origin server is also encrypted with TLS. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children
The App is a professional production tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.
10. Changes
We will post changes to this policy on this page and update the "Last updated" date. If a change materially affects how we use personal information, we will give notice by email to the address you use to sign in, or in the App.
11. Contact
PixelDimension Ltd.
No. 23, Lane 52, Da'an Street, Xizhi District, New Taipei City 221, Taiwan (新北市汐止區大安街52巷23號)
Email: raymond@pxdim.com
NDI® is a registered trademark of Vizrt NDI AB. Zoom is a trademark of Zoom Communications, Inc. Mac and macOS are trademarks of Apple Inc.