Privacy
In short
The B-ROLL website sets no cookies, loads no third-party scripts and runs no analytics. The B-ROLL app has no account or telemetry: it talks to YouTube for your downloads, checks GitHub for updates, fetches its tools on first launch, and keeps settings, history and any cookies.txt on your PC, sent only to YouTube.
What the B-ROLL website collects
The B-ROLL website collects nothing about you: no cookies, no analytics, no tracking pixels, no local storage and no consent banner, because there is nothing to consent to. Fonts and images are served from this site, so your browser makes no requests to third parties while you read.
The site is hosted on Cloudflare Pages, which keeps standard server logs under Cloudflare's own privacy policy. The one script on the site belongs to the search page, where the search index runs in your browser.
What the B-ROLL app connects to
The B-ROLL app has no account, no telemetry, no analytics and no ads; the table lists every destination the app contacts, and when.
| Destination | When | Purpose |
|---|---|---|
| YouTube and Google video servers | Downloads, title, bitrate, credits and subtitle lookups, search, channel lists, the preview, and one public test video at every launch as a warm-up | The actual work, through yt-dlp |
| i.ytimg.com | Search results and channel lists | Thumbnails |
| api.github.com | 4 seconds after every launch, and Check for updates | Asks for the latest B-ROLL release |
| github.com, the B-ROLL release file | Only after you press Update now | Downloads the new installer |
| github.com, yt-dlp releases | First launch, then an update check at every launch, and Force update yt-dlp | yt-dlp, updated to the latest nightly build |
| github.com, yt-dlp/FFmpeg-Builds and denoland/deno | First launch, and Reinstall tools | ffmpeg and Deno |
| github.com and the npm registry | First launch | The local helper yt-dlp uses with YouTube (bgutil-ytdlp-pot-provider) |
| 127.0.0.1, port 4416 | While the helper runs | Local only: the helper listens on your own PC |
Some links open in your browser only when you click them: the PayPal donation page, youtube.com, mozilla.org, the Chrome Web Store search for a cookies.txt extension, the GitHub release page, channel pages and the open-source project sites.
How B-ROLL uses your YouTube login
B-ROLL uses your YouTube login only to make requests to YouTube as you. With Use browser login for age-restricted videos on (the default) and no cookies.txt set, yt-dlp reads your browser's YouTube cookies for lookups, such as titles, bitrate, credits, subtitles and the preview, and after a sign-in error. The browsers it tries are Firefox, Edge, Brave, Chrome, Vivaldi and Opera.
The download itself uses cookies only when you set a cookies.txt or after YouTube asks for a sign-in. Cookies stay on your PC, where yt-dlp reads them, and go only to YouTube with its own requests. To stop this, turn the setting off in Settings; to remove a cookies.txt you set, press Reset next to Cookies file. The whole flow is explained in YouTube cookies.txt: export, use and refresh it.
To find a cookies.txt you have just exported, B-ROLL reads the first 8 KB of recent .txt files in Downloads, Desktop, the OneDrive Downloads and Desktop folders and your download folder. It does this after a sign-in error and when the sign-in wizard or Settings open, on your PC only.
What B-ROLL stores on your PC
B-ROLL keeps its data in %LOCALAPPDATA%\Broll and uploads none of it. The folder holds the tools, config.json with your settings and the last 200 finished downloads (link, file path and title), and, if you set one, a plain-text copy of your cookies.txt.
The download log lives only in memory for the session. Open B-ROLL at login, when you turn it on, adds one value to your Windows startup list. Uninstalling leaves the folder behind; delete it by hand for a full removal, as the uninstall steps show.
What a B-ROLL bug report contains
Report a bug opens your own email app with a message to info@emazamboni.it. It contains your text, the app version, the Windows version and, with Include the download log ticked (the default), the last 4,000 characters of the log. Nothing is sent unless you send that email yourself.
Donations to B-ROLL
Donations go through PayPal and are handled under PayPal's privacy policy. The donation page links to PayPal; neither this site nor the app sees your payment details.
Privacy questions about B-ROLL
Email info@emazamboni.it with any privacy question about the site or the app. This page changes when the site or the app changes what it collects or contacts, and the date at the top shows the last change.