FrostByte Privacy Notice
FrostByte is provided by Blackfrost Softwares Corp, operating as Blackfrost_AI. This notice separates what stays on your devices from what is sent to the services you choose and what the website needs to deliver beta installers after terms acceptance.
1. Data on your computer
The app stores settings, download destinations, catalog and library entries, torrent metadata and identifiers, transfer progress, HuggingFace repository and file information, and saved Spark connection details so it can restore your session. The desktop app also stores your accepted terms and privacy-notice versions, local acceptance time, and separate optional diagnostics choice in a local privacy record. Interface preferences such as theme, density, and the last open tab are stored in the app’s local browser storage.
On macOS, application records normally live under ~/Library/Application Support/frostbyte, with Electron interface data under ~/Library/Application Support/Frost/Byte. On Windows, app records normally live under %APPDATA%\frostbyte; Electron also maintains interface storage in its application profile. Default downloads go to ~/FrostByte on Mac or %USERPROFILE%\FrostByte on Windows, unless you choose another folder. Local records such as filenames, paths, connection hostnames, and transfer history are not all encrypted.
The beta can produce operational messages and error logs that include filenames, repository names, device information, or paths. Operating systems, browsers, dependencies, and connected services may also create diagnostic records. Review a support attachment before sharing it.
2. HuggingFace tokens and Spark credentials
New HuggingFace tokens and pairing private SSH keys are saved as encrypted values using Electron’s safeStorage. On macOS, this uses Keychain-backed encryption. On Windows, it uses DPAPI tied to the Windows user account; it does not protect credentials from other apps running as that same user. New secret storage is refused when the required secure storage is unavailable. Encryption is protection for stored credentials, not a guarantee against a compromised device or authorized software with access to them.
The app also retains HuggingFace account name and token role metadata. Older app profiles may contain legacy token records; clearing the token in Settings removes the app’s stored token fields, and saving a token again uses the current secure-storage path. Revoking a token at HuggingFace is a separate action.
For password-based Spark setup, the password is used in memory for the connection and setup session; the app does not save it as a reconnect credential. After approval, pairing adds a dedicated public key to Spark’s SSH authorized keys and keeps the matching encrypted private key on your computer. The saved profile includes the device address, username, port, trusted host key, and public key. An existing SSH alias uses the SSH configuration and credentials already available on your computer.
App updates, macOS Keychain permissions, or changes to the Windows user account can affect access to encrypted values. See Electron’s secure-storage documentation and Hugging Face’s token controls.
3. Data sent when you use download features
| Feature | Data and recipients |
|---|---|
| HuggingFace | Search terms, filters, repository identifiers, revisions, filenames, and download requests go to HuggingFace and its delivery infrastructure. Relevant authenticated requests include your token. Those services receive the requesting device’s network address and ordinary request metadata. |
| BitTorrent | Peers, trackers, DHT nodes, and local discovery participants may receive IP addresses, ports, peer identifiers, torrent infohashes, transfer information, and shared file pieces. Downloads may also upload and continue seeding. |
| Catalogs and links | A catalog URL you import or a link you open contacts that host. Its operator receives normal network and request information under its own policies. |
| Router discovery | Local peer discovery and enabled router port-mapping features communicate with devices on your network. Settings affect which discovery and sharing features are used. |
The network address is generally that of the device doing the transfer: your Mac or PC for a local download, or your Spark for a remote download. FrostByte does not provide an anonymity guarantee. Review the BitTorrent protocol, DHT specification, and Hugging Face Privacy Policy for those services and protocols.
4. Data and permissions on your Spark
Spark commands and responses travel over the SSH connection you approve. Setup inspects device and prerequisite information and can install a companion, add a pairing public key, and register selected storage folders. Folder browsing reads directory names and paths. The companion can read and write its registered folders and operate the downloads and sharing you request.
Transfer state, repository and file identifiers, torrent metadata, storage identities, and downloaded files are stored on Spark. When you start or resume an authenticated HuggingFace download on Spark, the desktop app sends the required token over SSH. The current companion keeps that token in memory for the job and excludes it from its saved download records.
The companion operates independently of the desktop app and may remain active after your computer disconnects or the app is removed. Spark administrators and other processes with sufficient permissions may access the companion’s files and state. Deleting the desktop app does not remove Spark downloads, the companion, or its authorized SSH key.
5. Download access, cookies, and installer delivery
The public beta is open to everyone without an invite code, account or email signup. Before downloading, you accept the displayed beta terms and acknowledge this notice. The public download flow does not collect an invite code or register an account.
Acceptance sets an opaque fb_beta_session cookie for the FrostByte area of this site. It is HttpOnly, SameSite=Strict, host-only, and Secure in production. The session lasts at most 72 hours. The database stores a hash of its random token, its expiry, the accepted terms version and server-recorded acceptance time, and that it is a public download session. The raw token stays in the browser cookie. End download session revokes the server session and clears the cookie.
For abuse prevention, the service stores hashed network identifiers and access-attempt counts in 15-minute windows, plus global and per-session limits. Rate-limit records are marked for deletion after 24 hours; database cleanup can occur later. Application code does not deliberately log raw IP addresses for this limiter. This differs from infrastructure logs described below.
After acceptance, a download request redirects your browser to a signed URL for a fixed Google Cloud Storage release object. The URL lasts no more than 10 minutes, or the remaining session lifetime if shorter. A previously issued link can remain usable until expiry after you end the browser session. Share the official download page to give others a stable address.
Google Cloud and Firebase support hosting, session records and installer delivery. Their infrastructure may process or log IP addresses, browser or user-agent information, URLs, timestamps, response codes and delivery details. The application does not create a separate per-download authorization audit record in its access database. These website delivery records do not contain the model or torrent files you download with the app. See the main site privacy policy for wider website practices.
Beta.16’s bundled v3 notice describes the earlier invite-only website. This v4 website notice describes the current public download service; the app’s local data handling and optional diagnostics remain as described. Older invitation administration records may remain for operations and security, but public download sessions are not linked to an invite.
If you contact support, we receive your email address and whatever you include. Do not send passwords, SSH keys, tokens, private models or sensitive files.
6. Optional diagnostics and feedback
Starting with beta.7, basic app and connection diagnostics are optional and off by default. Accepting the beta terms does not enable them. You can decline without losing app access, review the report fields in Settings → Privacy & Feedback, and turn reporting off at any time. Older beta.6 builds do not have this reporting feature.
If enabled, the app sends its version, platform, CPU architecture and OS kernel major version, plus aggregate counts of app starts, connection successes and failures, broad timing ranges, transfer completion or resume outcomes, and selected error categories such as timeout or unavailable storage. These diagnostic reports exclude filenames, model or repository names, searches, torrent hashes, magnet links, URLs, filesystem paths, hostnames, peer addresses, credentials and file contents. They contain no persistent device identifier, account, email or invite identity. Each report has a new random identifier used to avoid duplicate submissions.
Reports are sent over HTTPS to Blackfrost_AI’s Firebase/Google Cloud backend at most once every 15 minutes while the desktop app is open. Counters are held in memory, capped, and expire after at most 24 hours. Closing the app or turning diagnostics off clears unsent counters and cancels outstanding automatic requests where possible. A report already received cannot be recalled by turning the switch off. Spark does not independently send diagnostics to Blackfrost_AI. No raw logs, network captures, crash dumps, screenshots or screen recordings are automatically submitted.
Manual feedback is separate and works with diagnostics off. We receive the category and text you choose to submit, plus an email only if you provide one. You may separately attach the basic diagnostic fields shown in the preview for that report only; this does not enable automatic diagnostics. Review the full report before sending. Your own text may contain personal or sensitive information, so do not include private filenames, models, links, credentials or secrets. Sending feedback does not automatically send an email to anyone or guarantee a reply.
Reports are private and available to authorized Blackfrost operators for troubleshooting and improving the service. Diagnostic reports are scheduled for deletion after 30 days and feedback after 90 days; database TTL cleanup is asynchronous and can occur later. Expired reports are excluded from the reporting tool. We do not use these reports for advertising, sale of personal information, or profiles of what you download.
To protect the reporting endpoint from abuse, a separate rate limiter retains a hash of a network identifier scoped to a 15-minute window, with a 24-hour deletion target. It is not attached to report records. Firebase and Google Cloud infrastructure may still process or log request IP addresses, user agents, timestamps and response information, and may retain operational logs or backups under their configured policies. These reports are therefore not described as fully anonymous. Your report reference can help support locate a submitted report for a privacy request; local acceptance records remain on your own device.
7. Retention and your choices
- Local app data: remains until cleared or removed on the device. Removing a transfer or uninstalling the app does not necessarily delete downloaded files, stored settings, backups, or Spark state.
- Credentials: clear the HuggingFace token in app Settings and revoke it at HuggingFace if needed. Remove an unused pairing public key from Spark’s SSH authorized keys and remove the associated local profile when retiring that connection. Ask your device administrator or support if you need help locating the right records.
- Website access: the session cookie expires within 72 hours. Use “End download session” to revoke the server session and clear the cookie. Clearing this site’s browser data also removes the cookie, but does not itself revoke a server session; it expires or can be revoked separately. After clearing browser data or ending a session, you can accept the current terms again without a code or account.
- Access records: session expiry and sign-out revocation are enforced even if database cleanup has not run yet. Session records, including their terms acceptance record, are scheduled for TTL deletion at session expiry; rate-limit records have the 24-hour deletion target described above. TTL deletion is asynchronous and may occur later. Invite administration records, support correspondence, backups, and infrastructure logs may be retained as needed for operations, security, resolving requests, or legal obligations. We do not promise that all these systems share one fixed deletion deadline.
You can choose not to connect Spark, not to save a HuggingFace token, and to pause or stop torrent sharing. Necessary download requests still reach their destinations, and prior sharing cannot be recalled from other peers.
Depending on where you live, you may have rights to information, access, correction, deletion, restriction, objection, or other remedies regarding personal data we control. Contact us to make a request. We may need proportionate information to verify it; we cannot directly erase data on independently operated peers or your own devices.
8. Contact and updates
Contact Blackfrost Softwares Corp, operating as Blackfrost_AI, at support@blackfrostai.com with privacy questions or requests. Describe the issue without sending secrets. This notice will be updated when the beta’s relevant data handling changes; the effective date above identifies this version.
IPFS transfers and AEON device tools
IPFS participants can receive requested content identifiers, network addresses, connection information and files you explicitly share. Previewing a CID makes a network request. These protocol exchanges are separate from optional diagnostics. FrostByte stores transfer records, selected filenames, verification data and IPFS cache blocks on the device doing the transfer. A separate publishing cache contains the collections selected for IPFS sharing. Completed files remain in your chosen download folder when transfer rows or unneeded cache blocks are cleared.
An AEON-enabled Pi reports a small image/capability record over your approved companion connection. It contains the image identifier/version, supported console tools and console port. The theme does not enable telemetry or identify you to AEON. Opening an AEON console or its public X profile contacts that destination in your browser under its own policies. Your AEON login is handled there. No model/download identifiers, filenames, paths, IPFS CIDs or AEON account credentials are added to optional FrostByte diagnostics.
Publisher identity and recovery
Creating or importing a publisher identity is optional. FrostByte stores its public key, chosen display name, creation time, backup confirmation, and encrypted private key locally. The private key is protected by a password and the operating system key store. The password and recovery phrase are not included in optional diagnostics or uploaded by the identity setup flow.
A recovery phrase restores the same identity. Save it privately; anyone with it can reproduce the key. Recovery views clear on navigation or focus loss and expire after 60 seconds. If you choose Copy, your clipboard and any clipboard-history software may retain the phrase. Removing the identity removes the app’s stored record, but cannot erase copies you saved elsewhere. Creating an identity does not publish files or a community listing.