Legal

Privacy Policy

MacVisor · Last updated: October 4, 2026

The short version

Your virtual machines, their disks, snapshots, and network traffic never leave your Mac. MacVisor contains no analytics, no telemetry, and no crash reporting. On its own it makes two kinds of network request: checking your license with Polar, and checking whether a new version exists. Everything else it downloads — Linux cloud images, macOS installers — it downloads only when you ask, from the vendor, and verifies before use.

1. Overview

This Privacy Policy explains how MacVisor, a macOS application developed by ScaleNinja Software LLP ("we", "us", or "our"), handles data. It covers the app, its background service, the per-VM runner processes, the mvz command-line tool, the network helper, and the MacVisor Agent that runs inside guests.

MacVisor is a local-first application. We cannot see which VMs you run, what is on their disks, which snapshots you take, or how often you use it.

2. What MacVisor sends over the network on its own

  • License checks (api.polar.sh). When you activate or deactivate a key, once after each MacVisor update, about once a week, and at the end of an Enterprise term. Each request carries your license key, this Mac's hardware UUID (so Polar can tell your Macs apart and count activations), and — at activation — the Mac's computer name, so you can recognise it in Polar's customer portal. Polar answers with the key's status, its expiry, and the email on the order, which MacVisor shows in Settings. Nothing about your VMs is included. A Mac that cannot reach Polar keeps working for 30 days; see Activate your license.
  • Update checks (scaleninja.com). Once a day, if automatic checks are on, MacVisor downloads a signed release feed using Sparkle. The request carries no identifier for you or your Mac beyond what any HTTPS request reveals, such as your IP address; Sparkle's system profiling is off. Updates are never installed without asking. Turn checks off in Settings → Updates.

There is no third destination of ours. MacVisor sends no analytics, no crash reports, no usage pings, and no record of your VMs. The catalogue of cloud images and installers ships inside the app and is never fetched.

Downloads you start

When you create a VM from a cloud image or installer, or run mvz images pull, MacVisor downloads the file from its vendor over HTTPS and verifies it against the vendor's checksum: Linux images and their checksum lists from the distributions' own servers, macOS installers from Apple's CDN, and the nerdctl tool from its GitHub releases. Asking for the newest macOS (macos-latest) asks Apple which build that is. These requests happen only when you ask for the image, and carry nothing about you. The catalogue names every source.

Your guests' own traffic

A VM is a computer on your network. A Linux guest set up by cloud-init installs packages from its distribution's repositories and, if you chose Docker or k3s, from download.docker.com or get.k3s.io; a macOS guest talks to Apple as any Mac does. That traffic belongs to the guest, goes through your network, and never passes through anything of ours. Host-only networks and the per-network firewall let you restrict it; see Security model.

3. What stays on your Mac

  • VMs. Each .macvisor package — configuration, disks, snapshots, saved state — lives in a storage location you choose, as ordinary files. Templates and downloaded macOS installers sit beside them.
  • Provisioning data. A Linux VM made from a cloud image is configured with your Mac user name and UID, your SSH public keys, and any #cloud-config you provide; these are stored in the VM's configuration. A macOS VM with automatic setup stores the chosen account password in its configuration until the first boot has created the account. Protect VM storage accordingly.
  • Licensing state. Your key and its activation record are stored, signed, under ~/Library/Application Support/MacVisor.
  • SSH material. MacVisor keeps a generated SSH configuration with each VM's pinned host key under ~/.macvisor/ssh, and its own key for setting up macOS 27 guests. Per-VM sockets live under ~/.macvisor/run while a VM runs.
  • Logs. The app, the service, and each VM runner write logs under ~/Library/Application Support/MacVisor/logs. They are never sent to us.

4. Problem reports

Logs → Report a Problem… builds a zip you save wherever you choose. It contains the logs above and a summary: MacVisor and macOS versions, service status, licensing phase, and the name, id, OS, state, and resource settings of each VM and the names of your custom networks. Nothing is uploaded; you read it first and send it to us yourself if you want help.

5. macOS permissions

MacVisor asks macOS for a background-item approval, one administrator password to install the network helper, Local Network access for the app and the VM runner (to reach your VMs' addresses), Files and Folders access when VMs live on removable or network volumes, and the microphone only for a VM configured to use it. These permissions apply to your Mac's copy of MacVisor; they grant nothing to us. The network helper is the only component that runs as root, and it handles firewall rules, VLAN interfaces, the mvz link, and the .macvisor name resolver — no data.

6. The MacVisor Agent inside guests

The agent talks only to its VM runner, over a virtual socket, to provide shells, clipboard sync, file transfer, port tunnels, and guest information you ask for. It contacts no servers and reports nothing to us. Guest-initiated requests — files, URLs, port forwards — always need your approval on the host.

7. What we see when you buy or start a trial

Polar.sh is our Merchant of Record. When you buy a license or take the free trial key, Polar shares your name and email address with us so we can deliver the key, provide support, and send important product and security notices. Payment-card details are processed by Polar's payment provider and never reach our systems.

8. Support communications

If you email us, we keep your address and the message history so we can help and follow up. We do not ask for, and do not want, your VM disks or snapshots.

9. Website analytics

The ScaleNinja website uses Umami and Google Analytics to understand basic traffic and button usage. This is separate from the app, which contains no analytics code. See the main Privacy Policy for website analytics, cookies, retention, and your rights.

10. Children

MacVisor is not directed at children under 13, and we do not knowingly collect personal information from them.

11. Changes to this policy

We may update this policy as MacVisor changes. Material changes will be reflected in the "Last updated" date above.

12. Contact us

Back to MacVisor