Skip to content

Privacy policy

Effective 16 September 2026.

SceneRecap is a screen-recording and explanation service operated by Neurotech AI Solutions GmbH, Lückstr. 24, 10317 Berlin, Germany (“we”, “us”; see the Imprint). We are the controller within the meaning of Art. 4(7) GDPR for the processing described in this policy. Where customers use SceneRecap to process personal data of other people contained in their recordings, they are the controller of that data and we process it on their behalf under our data processing addendum.

This policy explains what we collect when you use the SceneRecap website, dashboard, API and Chrome extension, how we use it, how long we keep it, and the rights you have.

The short version

  • We only record when you press record. The extension has no background capture and no access to tabs you did not choose.
  • We never log what you type. Password and payment fields are masked in the recording and their contents are never captured; the event log stores only that a sensitive field was interacted with.
  • Recordings are private by default. You choose when and how to share.
  • You can delete any recording at any time, and you can have your whole account deleted; deletion removes the video, derived files and AI outputs from storage.
  • The service is hosted on Google Cloud in the European Union.

What we collect and why

Account data

Your email address (used for magic-link sign-in and transactional email), display name, workspace memberships and billing status. Payment card details are collected and processed by Stripe and never touch our servers. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

Recordings and interaction events

When you record, the extension captures the video (and audio, if you enable your microphone) of the tab, window or screen you selected, plus an interaction event log: click positions, scrolling, navigation paths (query strings stripped by default), page titles, tab switches, and — in Bug Report mode — console errors and failed network requests (method, path and status only; no request or response bodies, no authentication headers). Keyboard input is limited to modifier combinations and non-text keys (Enter, Escape, ⌘C); plain-text typing is never captured. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

AI processing

To produce the explanation, guide, bug report, recap, transcript or narration you request, we send sampled video frames, the event log and any audio transcript to Google’s Gemini API. Outputs are stored with your recording. We do not use your recordings to train models, and our Gemini usage runs under Google’s paid-API terms, which exclude customer data from Google’s model training. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

Reproduction runs (Repro Agent)

If you ask us to check whether a bug report still reproduces, we re-run the recorded flow in a browser on our infrastructure against an origin your workspace has verified. A run stores per-step screenshots of the pages our browser rendered, together with the console errors and failed requests it observed; these are kept with the recording, are covered by the same sharing controls, and are deleted with it. To plan the run and judge the result we send the recording’s event log, the bug report and the run’s observations to the same Gemini API described above, under the same no-training terms. Runs happen only when you request them. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Where you ask us to re-perform a recorded flow and keep the result, the run additionally records a video of the pages our browser rendered; it is stored as a private draft until you approve it into a recording (or discard it, which deletes it), and once approved is handled and deleted exactly like any other recording.

Usage data and diagnostics

Server logs (IP address, user agent, timestamps, request paths) are retained for 30 days for security, abuse prevention and debugging. Product analytics are first-party, server-side and pseudonymous: a small number of milestone events (account created, first recording ready, first share viewed, checkout completed) keyed to your account id, with no IP address, browser details or page content. Legal basis: our legitimate interest in operating, securing and improving the service (Art. 6(1)(f) GDPR).

Website analytics

On our public pages (not the app and not your recordings) we use Plausible Analytics, a cookieless service operated by Plausible Insights OÜ (Estonia) and hosted in the EU. It counts page views and referrers in aggregate; it does not use cookies, fingerprinting or cross-site tracking and stores no personal data. The app itself (/dashboard, /admin) is not measured by Plausible; public share pages are counted by URL path only (the share id, never the recording content). Legal basis: our legitimate interest in measuring the reach of our website (Art. 6(1)(f) GDPR).

Only if you allow it in the consent banner, we additionally use Google Analytics to understand how the website and the web app are used; see Cookies, local storage and your choices.

Campaign attribution

If you arrive from a campaign or referral link and you allow it, we keep the campaign parameters (utm_*), the referring site’s hostname and the landing page in your browser’s local storage for 30 days, so that if you create an account in a later visit we can still credit the channel that brought you. It is first-party, sets no identifier, uses no cookies, and is never read on any other site. It stays on your device and reaches us only when you request a sign-in link; after that we hold it on the resulting account-created event. A partner’s referral code is the one exception — see Partner links below.

We ask before storing it and the site works exactly the same if you decline. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which you can withdraw at any time under Privacy choices in the footer — withdrawing deletes the record from your browser. If you decline, nothing is stored: the campaign parameters exist only in the page you have open, and are sent to us only if you request a sign-in link during that same visit.

Partner links

If you arrive through a link from one of our affiliate partners (/r/… or a ?ref= code), your browser asks our server whether the code belongs to an approved partner as soon as the page opens. If it does, we count one visit for that partner: the code, the page you landed on (its path only), the referring site’s hostname, the time and — where our hosting network supplies it — the country the visit came from. That count holds no IP address, no browser details and nothing that identifies you or your device (our ordinary server logs, described above, still apply). Whether the code is also remembered on your device follows your choice for campaign attribution above: only with your consent, for 30 days, in local storage, never in a cookie.

If you then create an account, we record that the partner referred it. For as long as you hold a paid subscription we apply the partner discount at checkout and work out the partner’s commission from your payments, and reduce it if a payment is refunded or disputed. The partner sees an anonymous reference (such as R-4F9701), the dates, whether you became a paying customer and how much commission that earned them — never your name or email address. If your account is deleted, the referral stays in our accounting records without the link to your account.

Legal bases and retention. Counting partner visits, and recording which partner referred an account, rest on our legitimate interest in running and auditing the partner programme (Art. 6(1)(f) GDPR): the visit count contains nothing that identifies you, and the referral record links your account to a partner code only. Working out and paying the partner’s commission rests on our contract with the partner and on our accounting obligations (Art. 6(1)(b) and (c) GDPR); the partner sees only an anonymous reference, dates and amounts — never who you are — so nothing about you is disclosed to them. Storing the code on your device rests on your consent (Art. 6(1)(a) GDPR, § 25 (1) TDDDG), which you can withdraw at any time under Privacy choices in the footer. Referral and commission records are kept for the partner’s commission period and the payouts that follow, and afterwards only within the accounting records the HGB, AO and UStG require us to keep (currently up to ten years); once your account is deleted they no longer link to it.

How we use your data

  • To provide the service: process, store, play back, analyse, explain and share your recordings as you direct.
  • To operate accounts, workspaces and billing, and to send transactional email (sign-in links, invitations, processing-complete notices, billing notices).
  • To secure the service, prevent abuse and comply with legal obligations.

We do not sell personal data, we do not show third-party advertising in the product, and we do not use your recordings for any purpose other than providing the service to you.

Sharing and recipients

Recordings are visible only to you and your workspace members unless you create a share link. Public and unlisted links are viewable by anyone who has the URL; password-protected, workspace-only and email-restricted links enforce access as configured. If you connect an integration (Slack, GitHub, Linear, Jira, Notion), we send that provider only the content you explicitly file or export to it.

We use a small number of service providers (processors) to run SceneRecap: Google Cloud (hosting, storage and Gemini AI), Stripe (payments), Resend (transactional email), Plausible (website analytics, EU), Google Ireland Ltd. (Google Analytics and Google Ads, only with your consent) and, when error monitoring is enabled, Sentry. The current list, including regions, is maintained at /legal/subprocessors. We disclose data to authorities only where legally required.

International transfers

The service is hosted in Google Cloud’s EU regions: compute and databases in europe-west1 (Belgium) and media storage in europe-west3 (Frankfurt, Germany). Some providers (Stripe, Resend, Sentry, Google) may process limited data in the United States; such transfers are safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses.

Retention and deletion

  • Recordings persist until you delete them. Deleted recordings go to a 30-day trash and are then permanently removed, including all derived files (posters, keyframes, AI outputs, transcripts, exports).
  • When you apply redactions (trim, blur or mute in the editor on the upload page), the original, unredacted upload is deleted from storage once the redacted transcode exists and only the redacted version is kept. Moments you cut are also removed from the recording’s interaction event log. If you apply no redactions, the file you uploaded is the one we hold until you delete the recording.
  • Server logs are retained for 30 days.
  • To delete your account entirely, email contact@scenerecap.com from your account address; we complete deletion of your personal data and all recordings you own within 30 days, except where we must retain records to comply with legal obligations (for example invoices under tax law).

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. Depending on where you live, similar rights may apply under other laws (for example the CCPA). To exercise your rights, use the controls in the product or email contact@scenerecap.com. You also have the right to lodge a complaint with a data protection supervisory authority — in Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Cookies, local storage and your choices

Strictly necessary: a session cookie and an access token keep you signed in to the web app; alongside them your browser holds the workspace you have selected, the dismissal of the getting-started checklist, the token for a recording you started without an account, and the record of the choices you make here. None of these set tracking identifiers, none are read on other sites, and none need consent (§ 25(2) TDDDG).

Analytics without cookies: public pages use Plausible Analytics (EU-hosted). It stores no cookies and no personal data in the browser; it counts visits and referrers in aggregate.

Campaign attribution (only with your consent): if you allow it, your browser keeps the campaign parameters, the referring site’s hostname and the landing page in local storage for 30 days, so that a sign-up in a later visit is still credited to the channel that sent you. If you came through a partner’s link, that includes the partner’s referral code. No cookie, no identifier, first-party only, never read on other sites. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Declining stores nothing and changes nothing else about the site.

Google Analytics (only with your consent): if you allow “Analytics” in the consent banner, we load Google Analytics 4 (gtag.js, Google Ireland Ltd.) on our website and in the web app — never on shared recordings, in embeds or in our admin area — to understand how they are used: which pages are viewed, where visits come from, and whether they lead to a sign-up, a recording or a purchase (including the purchase amount). Google sets cookies such as _ga and _ga_<id> (up to two years) and processes device, browser and usage data; it uses your IP address only to derive an approximate location and does not store it. As with the ads tag, Google is told which page you are on but not the page’s query string, and email addresses are redacted from what it receives. Event data is kept for two months. Transfers to the United States rely on the EU–US Data Privacy Framework and standard contractual clauses. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); nothing is loaded before you allow it, and you can withdraw at any time via Privacy choices in the footer.

Google Ads (only with your consent): if you allow it in the consent banner, we load the Google Ads tag (gtag.js, Google Ireland Ltd.) to measure whether our advertising campaigns lead to sign-ups, recordings or purchases (including the purchase amount) and to show relevant ads. The tag is told which page you are on, but not the page’s query string apart from the click identifier Google adds to its own ad links, and it is never loaded on shared recordings. When a sign-up, recording or purchase is reported and you are signed in, the tag also detects the email address of your account on the page and sends it to Google in hashed (SHA-256) form, so Google can match the conversion to an ad interaction (“enhanced conversions”); Google uses it only for that matching. Google may then set cookies such as _gcl_au (90 days) and process identifiers and usage data, including transfers to the United States under the EU–US Data Privacy Framework and standard contractual clauses. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). We use Google Consent Mode v2: nothing is loaded before you choose, and “Reject” keeps the site fully usable. You can withdraw or change your choice at any time via Privacy choices in the footer; your choice is stored locally for six months. More: Google’s advertising policies.

Chrome extension disclosure

The SceneRecap extension’s single purpose is recording your screen and interactions to produce an AI explanation. Its use of data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: we only use captured data to provide the features you invoke; we do not sell it, use it for advertising, or transfer it except to provide the service or as required by law.

Changes and contact

We will announce material changes to this policy in the product and update the effective date above. Questions and privacy requests: contact@scenerecap.com, or by post to Neurotech AI Solutions GmbH, Lückstr. 24, 10317 Berlin, Germany.