Skip to content
BAROMEDIA / WINDOWS
BaroMedia Pro· €19.99RU
PRODUCTION TERMS · IN EFFECT

BARO · LEGAL

Privacy policy

The data BaroMedia actually processes, why it is used, and which providers receive it.

Version
1.1
Updated
August 23, 2026
Status
Supplier and contact address published
CONTENTS01. Who is responsible02. Data processed03. Local-first processing04. Purposes and legal bases05. Providers and transfers06. Diagnostics07. Retention08. User rights09. Security and changes
01

Who is responsible

Version 1.1 dated August 23, 2026. The product supplier, licensor, and data controller is MARK PUOLAKAINEN, an individual operating under the Baro brand. Address for legal notices: Kalevipoja tn 10, 13625 Tallinn, Estonia. Paddle accepts payment as Merchant of Record. Current installers are published without an Authenticode signature, with a clear warning and SHA-256 checksum; automatic updating with unsigned files is disabled.

The BaroMedia data controller is MARK PUOLAKAINEN, an individual operating under the Baro brand, with an address for legal notices at Kalevipoja tn 10, 13625 Tallinn, Estonia. Data-subject questions and requests use support@baro.ee. Paddle is independently responsible for payment data it processes as Merchant of Record under its own privacy policy.

02

Data processed

Account and sign-in: email address, selected language, account creation and verification timestamps, one-time authentication requests, token hashes, and hashed IP address and User-Agent data for abuse prevention and session security. One-time links are valid for 15 minutes; web and app sessions are valid for up to 30 days.

Purchase and licensing: checkout and order identifiers, buyer email, product, generation, price, currency, payment or refund status, entitlements, license number, activation state, device name and platform, hashed device fingerprint, and last-seen timestamps.

Support: messages sent to support@baro.ee and, only after separate consent, a manifest and private diagnostic bundle. BaroMedia does not receive raw card details or a complete card number.

03

Local-first processing

User videos, projects, file names, and file paths are processed locally by the desktop app and are not uploaded during ordinary player use. The site has no advertising trackers or marketing profiling. A media file is never added to a diagnostic archive automatically; any future request for a sample file requires separate explicit consent and a separate transfer method.

04

Purposes and legal bases

Account, order, and licensing data is needed to perform the contract: sign-in, digital delivery, purchase recovery, device activation, and support. Security hashes, operational logs, and rate limits serve the legitimate interest of preventing fraud and protecting the service. Financial records are kept to meet accounting, tax, and legal duties. A diagnostic archive is uploaded only with separate consent, which can be refused without losing ordinary product access.

05

Providers and transfers

Amazon Web Services provides the EC2 server running the site, API, and primary SQLite database, private S3 backup storage, and Secrets Manager for operational secrets. Resend delivers sign-in and transactional email; Paddle handles checkout, tax, payment, receipts, refunds, and related verification. Each provider receives only the information needed for its function. Their infrastructure may process data outside the user's country using legally recognized transfer safeguards.

06

Diagnostics

Built-in diagnostic bundle upload is currently disabled in production: ordinary product use cannot send such an archive to the server. When needed, a user may attach materials they have reviewed themselves to a message sent to support@baro.ee.

Before built-in upload is enabled, Baro will deploy separate express consent and a preview of the redacted manifest, private AWS storage with no public object URL, SHA-256 verification, role-limited access, access auditing, and automatic deletion no later than 14 days after upload. A material change to this process will be published in a new policy version before activation.

07

Retention

Authentication codes stop working after 15 minutes, checkout sessions after 30 minutes, and web and app sessions after 30 days. Built-in diagnostic bundle upload is disabled, so no retention period for such archives currently begins. If the feature is enabled later, a bundle will be retained for no more than 14 days, while a minimal record of consent, upload time, and deletion may be kept for up to 12 months for security auditing. Order, refund, and license history is kept as long as needed to perform the purchase, restore access, resolve disputes, and meet mandatory financial-record duties. Security and technical records are deleted or anonymized after they no longer have a practical or legal purpose.

08

User rights

Depending on applicable law, users may request access, correction, deletion, restriction, or portability; object to processing; or withdraw consent. Send the request from the account email to support@baro.ee. Some financial, antifraud, and contractual records cannot be deleted immediately where retention is legally required. Users may also complain to a competent data-protection authority.

09

Security and changes

Tokens and sensitive identifiers are stored as cryptographic hashes, backups are held in private S3 storage, and built-in diagnostic archive upload is disabled. Material policy changes receive a new date and, where required, are communicated before taking effect.

BAROMEDIA / WINDOWS

BaroMedia turns the useful actions missing from ordinary video players into direct keyboard commands.

BaroMedia

OverviewBuy ProDownload FreePricing

Resources

DownloadsChangelogDocumentationSupportStatus

Legal

TermsPrivacyRefundsEULA
© 2026 Baro. Your files remain yours.Russian version