What MOVON sees of your footage
Your footage never leaves the Mac. The match runs on MOVON's servers, but only color data is sent; never footage, frames, or project files.
The short version: to run a match, MOVON Match sends color data to MOVON's AI on our servers and brings back LUTs. Your footage, your frame images, and your project files never leave the Mac; only the color data needed to build the match does. This page covers what that means in practice, with the few qualifications worth being honest about.
What happens on a match
When the panel hits Analyze, the work splits between the Mac and MOVON's servers:
- On the Mac: color sampling. The plugin reads color data from the selected clips and the reference on the timeline. That is the only thing it extracts.
- On MOVON's servers: the match. The color data goes to MOVON's AI, which computes how each selected clip's color differs from the reference and generates the 33³ .cube LUTs.
- Back on the Mac: the LUTs. The .cube files come back to the panel and are written wherever the editor exports them.
Because the computation happens on the servers, the match needs an internet connection and a signed-in MOVON account.
What does and does not leave the Mac
Does not leave the Mac:
- Source footage. Never uploaded.
- Frame images. Never uploaded; the plugin extracts color data, not pictures to send.
- Project files and timelines. The plugin does not read scratch disks or clips outside the timeline being analyzed.
- The generated .cube files. Returned to the panel and written to the project folder by default; they go wherever the editor saves them.
Does leave the Mac:
- The color data needed to build the match. Sent to MOVON's servers when Analyze runs, used to compute the match, returned as LUTs.
- Account and connection basics. The sign-in that authorizes the match against a MOVON account, and the build number for compatibility.
- Bad-match reports. If the editor sends a sample via the homepage Contact form (the path documented at Report a bad match), the clips and screenshot the editor chooses to attach reach MOVON Labs. Nothing is auto-uploaded; every byte sent in a report is one the editor explicitly attached and submitted.
There is no analytics on editing behavior, panel usage, or session length.
The account
The match runs on MOVON's servers, so the beta uses a MOVON account and a sign-in in the panel. The account is how a match is authorized; it does not give MOVON access to footage, because footage is never sent in the first place.
NDA work
A lot of MOVON's design choices line up with the reality of NDA work: unreleased films, brand campaigns before launch, confidential events. The questions an NDA-conscious editor asks (where does the footage go, what gets logged, what happens during the analysis) have a consistent answer for MOVON: the footage stays on the Mac. What travels is color data: numbers describing how a camera renders color, not images, audio, or anything a viewer could watch.
What happens to data in bad-match reports
For the reports an editor explicitly submits, the data goes to MOVON Labs and:
- Stays private. Not shared, not resold, not used for advertising.
- May feed the next training cycle, anonymized. Names, timestamps, and metadata are stripped before any clip enters the corpus.
- Is retained only as long as the report is being worked on, and as long as the anonymized clip is useful for training. Identifiable copies are deleted once the report is resolved.
Sending a report is the most direct way to make the next match better for the camera that triggered it, but the choice to send the report stays with the editor.
A summary line for procurement
If a procurement or compliance team needs a one-line statement: *MOVON Match computes the color match on MOVON's servers, but sends only the color data needed to build the match. Footage, frame images, and project files never leave the device. Bad-match reports are user-initiated, attach-only, and never auto-uploaded.*

