Security
Security starts with not having your footage
Most of what a recorder has to protect is the recording. We removed that problem instead of managing it: your video never leaves the Mac it was made on. Here is what protects everything else.
The short version
The strongest control we have is an absence. There is no bucket of customer recordings here, because there is no route by which one could arrive. Everything below is about the small amount we do hold: an email address, a password nobody can read, and which plan you are on.
Controls
What protects what
Each of these is in the shipped app or the running service today. Nothing on this page is a plan.
Your recordings
- Capture, editing and export all run on your Mac. There is no cloud rendering step and no upload queue.
- We operate no service that can receive video, so no frame of your footage exists on our side to be leaked, subpoenaed or sold.
- Projects are ordinary folders on your disk. You move them, back them up and delete them like any other file.
- The Screen Recording, Camera, Microphone and Input Monitoring permissions are granted by macOS to the app on your machine — never to us.
Your account
- Passwords are stored only as bcrypt hashes. We cannot read yours, and neither could anyone who obtained the database.
- Email codes are stored as hashes too. They expire on their own and stop accepting attempts after a few wrong ones.
- Changing your password invalidates every session that was signed in with the old one.
- Sign-in and reset replies are worded identically whether or not an address has an account, so nobody can use them to find out who our customers are.
- Your signed-in session is held in the Mac’s protected credential store, not in a readable file in your home folder.
Payments
- Paddle is the merchant of record. Card numbers are entered on Paddle’s pages and never reach the app, this website or our servers.
- Purchase notifications from Paddle are rejected unless their signature verifies against the exact bytes we received.
- Even then, the notification is only a hint: we re-read the record from Paddle’s own API before anything about your access changes.
- Repeat deliveries of the same notification are recognised and ignored, so a retry can never grant or revoke something twice.
The service
- Everything between the app, this site and our servers travels over TLS.
- Sign-in, password reset and purchase endpoints are rate-limited well below the volume a brute-force attempt needs.
- The service refuses to start at all if a required secret is missing or too weak — it fails closed rather than running in a weaker mode nobody notices.
- A plan is only ever granted by a price we have explicitly mapped. An unrecognised product grants nothing.
This website
- The site holds no account data and no payment data. It is pages, and it is served over HTTPS with strict transport security.
- Responses carry the standard hardening headers: no content-type sniffing, no framing by other origins, and a referrer policy that does not leak your path to third parties.
- Camera, microphone and location access are switched off for the site by policy, because a marketing page has no business asking for them.
- No advertising network, no remarketing pixel and no cross-site profile. Analytics is limited to counting visits.
Responsible disclosure
Found something? Tell us.
We would far rather hear it from you than read it somewhere else. Report in good faith and we will not take legal action over it — we will fix the problem and credit you if you want the credit.
There is no paid bounty programme today. We will not pretend otherwise to collect free research.
[email protected]Email the details to the address below with “Security report” in the subject.
Tell us what you found, how to reproduce it, and what an attacker could do with it.
We acknowledge every report within two working days and keep you posted while we fix it.
Please give us a reasonable chance to ship a fix before you publish, and please do not access anyone else’s data, degrade the service or run automated scans against it while you look.
If something does go wrong
If an incident affects your data, we will tell you: what happened, what of yours was involved, what we have done about it and what you should do. Where the law sets a deadline for telling a regulator — seventy-two hours under the GDPR — we meet it.
We are small and independent, and there is no audit report to hand you. What we can hand you is the shortest possible answer to “what could you lose of mine?”, and the Privacy Policy lists every field that answer contains.
How local-only recording worksRecord the next one properly
Install it, hit ⌥⌘R, and watch a take that would normally cost you an evening in a timeline come out finished.
macOS 13 Ventura or later · Apple Silicon and Intel