IsoBridge

IsoBridge Privacy Policy

Effective date: October 5, 2026
Last updated: October 5, 2026

This Privacy Policy explains how PixelDimension Ltd. ("we", "us") handles personal information when you use the IsoBridge macOS application (the "App") and the online services that support it: the sign-in and license service, the Zoom account-linking service, and the software-update service (together, the "Services").

Controller: PixelDimension Ltd., No. 23, Lane 52, Da'an Street, Xizhi District, New Taipei City 221, Taiwan (新北市汐止區大安街52巷23號). Contact: raymond@pxdim.com. We have not appointed a data protection officer or an EU representative; the App is not offered in the European Union.

1. Summary

2. Information we process

2.1 Information processed by our servers

DataHow we get itWhy we use itHow it is storedHow long we keep it
Email addressYou enter it to sign inIdentify your account; send one-time sign-in codes; security limitsPlain text in our database (Railway PostgreSQL)While your account exists. There is currently no automatic deletion of account records; we delete them on request (Section 7).
One-time sign-in code (4 digits)Generated by our serverVerify that you control the email addressOnly a keyed hash (HMAC-SHA256) is stored; the code itself is sent to you by emailValid 5 minutes; single use; up to 3 attempts. The record is removed when you request a new code, and by an hourly clean-up once it has been expired for 24 hours
Sign-in security countersCreated when you request or enter codesRate limits (60-second cool-down, 5 codes per hour) and lockout after 10 wrong codes within 24 hoursStored with your account recordWhile your account exists; counters reset after a successful sign-in or when their time window passes
Session tokenGenerated by our server after you sign inKeep you signed in on that MacYour Mac keeps the token in the macOS Keychain; our server stores only a SHA-256 hash with an expiry date90 days, or until you sign out or sign in again on the same Mac; expired sessions are deleted by an hourly clean-up
Device IDA random identifier (UUID) created by the App — not a hardware serial number or advertising IDKeep separate sessions for each Mac you useYour Keychain and our session recordDeleted together with the session
IP addressSent with every request to our servicesAbuse prevention (per-address rate limit)Our code stores only a SHA-256 hash of the address with a request counterRemoved by an hourly clean-up once older than one hour
Zoom OAuth access and refresh tokensIssued by Zoom when you authorize the AppObtain a ZAK when you ask the App to join a meeting; refresh access when it expiresEncrypted with AES-256-GCM before storage; the encryption is bound to your session, and the key is held only in server configurationUntil you disconnect Zoom in the App, sign out, sign in again on that Mac, your session expires, or Zoom refuses a token refresh — whichever comes first (see Section 5)
Authorization state and 6-digit confirmation codeGenerated by our server when you link ZoomMake sure the Zoom authorization completed in your browser belongs to the App session that started itStored only as hashesState: 10 minutes, single use. Confirmation code: 10 minutes, 3 attempts; an unconfirmed authorization is deleted after a failed or expired confirmation, or replaced when you start again; otherwise it ends with your session
Zoom Access Key (ZAK)Requested from Zoom each time you joinLets the Zoom Meeting SDK join a meeting as youNot stored by our servers; passed to the App, which keeps it in memory onlyFor the duration of the join request; Zoom documents a 5-minute validity
Meeting SDK authorization token (JWT)Signed by our server when you joinAuthorizes the App's Zoom Meeting SDKNot stored by our servers; kept in App memory onlyValid for 1 hour

We do not enable request logging in our application code or in our Cloudflare Workers. Our hosting providers may keep their own operational logs about connections to their platforms under their own policies.

2.2 Information that stays on your Mac

DataWhere it goesNotes
Meeting details you enter (meeting ID or invite link, passcode, display name, webinar registration email or token)Sent only to Zoom through the Zoom Meeting SDKNot sent to our servers. Meeting passcodes are kept in memory only and are never written to show files, snapshots or logs
Meeting content: participants' video, audio, screen shares and display namesProcessed in memory on your Mac; video and audio are sent as NDI® streams to receivers on your local networkAvailable only after the meeting host grants local-recording permission. Never sent to us. The App writes no recording files. Display names are shown in the App to help you choose sources
Show files and session snapshotsSaved where you choose (show files) or kept in memory until you quit (snapshots)Contain channel and routing settings only — no credentials, tokens, passcodes or full invite links
Connection statistics (round-trip time, jitter, packet loss, NDI receiver count)Kept in memory (up to 3,600 samples); written to a CSV file only when you choose "Export connection log"Contain no names, meeting IDs, passcodes or credentials
Optional customer Meeting SDK credentials ("custom SDK" mode)Used on your Mac to sign a short-lived tokenNever sent to us. The Client Secret is saved in your macOS Keychain only if you tick "remember"; you can remove it in the App ("Forget this SDK")
Preferences (appearance, last-used settings tab and connection mode)macOS user defaultsLocal only

The App does not access your camera or microphone for its own purposes. macOS may ask for microphone and camera permission because the Zoom Meeting SDK requires it; the App joins meetings with your camera off and microphone muted. The App asks for Local Network permission because NDI® uses your local network.

2.3 Software updates

When you choose Check for Updates, the App downloads the update feed and, if you accept, the update package from our update service on Cloudflare. As with any web request, your IP address and the App's user-agent (including its version) are processed by Cloudflare to deliver the files. The App does not check automatically and does not send a system profile. Update packages are verified with a digital signature before installation.

3. Zoom data

When you connect your Zoom account, Zoom asks you to approve the App's access. The App requests only the permission to read your Zoom Access Key (user:read:zak). We use it only to join the meetings you choose, as you. We do not use Zoom data for any other purpose, do not combine it with other data, and do not share it except with Zoom itself. Your use of Zoom, including the meetings the App joins, remains subject to Zoom's own terms and privacy statement. The Zoom Meeting SDK included in the App communicates directly with Zoom; that processing is governed by Zoom's privacy statement.

4. Service providers

We use the following providers to operate the Services. They process personal information on our behalf and under their own security commitments.

ProviderRoleData involved
Cloudflare, Inc.Public entry point for our license service (TLS termination, request filtering); hosting of the update feed and release files (Cloudflare Workers and R2)All requests from the App to our services, including your IP address, email address during sign-in, and session token
Railway CorporationHosting of our license service and databaseEverything listed in Section 2.1
Postmark (ActiveCampaign, LLC)Delivery of sign-in code emails (open and link tracking disabled)Your email address and the one-time code
Zoom Communications, Inc.Zoom authorization, ZAK issuance, and meetings joined by the AppOAuth exchange data and tokens; meeting participation through the Zoom Meeting SDK

Our license service and database run on Railway's cloud infrastructure; Cloudflare operates a global network; Postmark sends email from the United States. These providers may process information outside Taiwan, and we rely on their contractual security and confidentiality commitments.

We may also disclose information if required by law or to protect the rights, safety and security of our users and services.

5. Your choices and controls in the App

Performance of our contract with you (sign-in, Zoom linking, joining meetings, updates); our legitimate interests in keeping the Services secure (rate limiting, lockouts, abuse prevention); your consent for linking your Zoom account, which you can withdraw at any time as described in Section 5.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal information, to receive a copy in a portable format, and to withdraw consent at any time. You may also lodge a complaint with your data-protection authority.

To exercise these rights, email raymond@pxdim.com from the email address you use to sign in (or tell us that address), and state your request. We may need to verify your identity before acting. We will respond within 30 days, or sooner where applicable law requires. Deleting your account removes your email address and security records, all sessions and all stored Zoom tokens from our database.

8. Security

We protect personal information with measures that include: HTTPS for all App-to-service traffic; a Cloudflare entry point that accepts only known API paths and small request bodies; an origin server that rejects any request not carrying a shared secret added by that entry point; hashing of session tokens, sign-in codes, authorization state and IP addresses; AES-256-GCM encryption of Zoom tokens at rest; one-time codes with short expiry, attempt limits and lockouts; storage of your session in the macOS Keychain; and signed, notarized App releases with signature-verified updates. Traffic between Cloudflare and our origin server is also encrypted with TLS. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Children

The App is a professional production tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.

10. Changes

We will post changes to this policy on this page and update the "Last updated" date. If a change materially affects how we use personal information, we will give notice by email to the address you use to sign in, or in the App.

11. Contact

PixelDimension Ltd.
No. 23, Lane 52, Da'an Street, Xizhi District, New Taipei City 221, Taiwan (新北市汐止區大安街52巷23號)
Email: raymond@pxdim.com

NDI® is a registered trademark of Vizrt NDI AB. Zoom is a trademark of Zoom Communications, Inc. Mac and macOS are trademarks of Apple Inc.