Privacy Policy

Last updated 7 September 2026

StageGlass makes the screens you see in films and television shows. This policy covers the StageGlass apps — PropPlayer for iPhone and iPad, PropPlayer Remote for Mac, and the other StageGlass products — and the stageglass.app website.

The short version: PropPlayer and PropPlayer Remote have no StageGlass accounts and use no analytics, advertising, or tracking SDKs. Show and scene data, photos, and media stay on your devices, in files you control, and—when iCloud is available—in your private iCloud database. The stageglass.app website separately uses Vercel Web Analytics. PropPlayer can receive authored shows, scenes, characters, and associated media from your private iCloud database and keep received scene assets available offline; it also synchronizes Home Screen layouts and device-library metadata. As PropPlayer ships, remote control runs over your local network and the app contacts no StageGlass server; the internet Relay is turned off, and there is no control in the app that turns it on. If an operator deliberately enables it on a device, control traffic for that session is routed through a relay server we run — described in full below.

Website analytics

This website uses Vercel Web Analytics to count visits and page views. It records aggregated details such as the page, referrer, approximate location, browser, operating system, and device type. Vercel Web Analytics does not use cookies or associate this data with a person or IP address. Its daily visitor identifier expires after 24 hours.

We use this information only to improve the website. We do not use it for advertising, visitor profiles, or cross-site tracking, and the website never sends show files, scene files, photos, or production media to Vercel Web Analytics. See Vercel's Web Analytics privacy documentation.

What stays under your control

Shows, scenes, characters, conversations, contacts, photos, media, and other prop-device details are written to storage on the device where you author them. Show and scene packages you export are ordinary files that you move yourself. When iCloud sync is off, this production content stays on your devices and in files you control. StageGlass servers do not receive those files or their media.

PropPlayer can receive authored-library records—including show manifests, scenes, characters, device information, revision history, and referenced media—from your private iCloud database. Compact proxy media can download automatically. Full-resolution assets may download when you open a show or choose Available Offline. PropPlayer also synchronizes Home Screen layouts and device-library metadata through iCloud. Apple operates iCloud; StageGlass servers do not receive this data.

When devices talk to each other

A production usually runs several devices together: an operator cues a scene from a second iPhone, an iPad, or a Mac, and prop phones follow along. As PropPlayer ships they connect over your local network; there is a second path, the internet Relay, that is off and that no control in the app turns on.

On the same network

The apps find each other over your local network and talk directly, device to device. That traffic — control commands, device state, the beat rundown, which scene is loaded and where in it a device is, the device's name and status, and authored values such as message text and character names — stays between your devices and does not reach us. Screen video for a live monitor travels the same way, over your local network only. iOS asks your permission before an app can use the local network.

The internet Relay, and why you will not meet it

Sets are not always cooperative: a location can block traffic between devices, or an operator may not be on the same network as the phone. The StageGlass Relay exists for that case — it routes control traffic between two of your devices through a server we run, instead of across your local network.

In PropPlayer as it ships, the Relay is off, and no control in the app turns it on. The app draws no code-entry screen, the "Connect a phone" sheet offers only "Find nearby phones," and a relay code is refused outright rather than sent anywhere. Turning it on takes a deliberate act outside the app — a device configuration key or a launch argument — which is how we run our own tests. Every beat can also be advanced by tapping the phone screen, so the Relay is never needed to run a scene.

If someone does enable it and joins a room by code, then for the length of that session the messages that would have crossed your local network are routed through our relay server instead. Those messages can include a device identifier and the device's name, control commands, device state and the beat rundown, which scene is loaded and where in it the device is, device status such as battery level, and authored values carried inside a cue — including message text and character names. The Relay forwards that traffic in real time and does not store the messages themselves; they pass between the two devices and are never written to disk. It does hold, briefly, what it needs to run and secure the session: the pairing code, the session's access tokens, connection state, the edge location, and timestamps. Those are deleted when the session ends, when pairing is rejected, or after a short reconnect grace expires with both devices disconnected. It also keeps bounded, short-lived rate-limiting state, derived from the connecting IP address, in memory. No account is attached to any of it, because there are no StageGlass accounts. The Relay never transfers show or scene packages or media, and screen video never goes through it at all.

This is the collection our App Store privacy disclosure covers when it declares a device identifier and session metadata: it happens only on a device where the Relay has been deliberately enabled and a room joined. If you never enable it, your devices never contact our servers.

Permissions the apps may ask for

Permission-based access is requested when it is needed, and system pickers keep each choice under your control.

Children

StageGlass is a professional tool for film and television production. It is not directed at children, and nothing in it is designed to gather information about the people who use it.

Payments

PropPlayer works without a purchase: building a scene and rehearsing it are free. Playback without a subscription carries a StageGlass watermark, and the VFX plate stays clean. StageGlass Unlock is an auto-renewable subscription handled entirely by Apple through StoreKit — $9.99 per week or $29.99 per month in the United States. StageGlass servers receive no payment details and no purchase records, and there is no StageGlass account attached to a subscription. The Terms of Use and Support pages explain how to manage, cancel, and restore it.

Your rights

We hold no StageGlass account or profile about you. Vercel holds the anonymous website measurements described above, and Apple holds whatever your iCloud and App Store settings put in its hands.

On a device where the Relay has been enabled, two different things reach our relay server, and they are worth keeping apart. What is retained, briefly, is the session's credentials and metadata — the pairing code, access tokens, connection state, edge location and timestamps — which expire on their own. What is forwarded is the live control traffic itself, which can carry authored content such as message text and character names; it passes between your two devices in real time and is never written to disk. Both are described in full above.

"No account" is not the same as "anonymous", and our App Store privacy disclosure reflects that: while a session is open, a device identifier and the session metadata are linked to that device and session, which is why we declare them as linked rather than claiming otherwise. What we do not have is any StageGlass account, profile, or way to connect a session to you as a person — and none of it is used for tracking or advertising, or sold to anyone.

Deleting the app removes its local data, but it does not automatically remove Home Screen layouts already synced to iCloud; you manage that data through Apple's iCloud storage controls.

Changes

If we change how the apps or website handle data, we will update this page and change the date at the top before the change ships. We will describe any new collection here before we enable it.

Contact

Questions about privacy, or anything else: support@stageglass.app.