RecBaba

Trust

Security at RecBaba

Last updated: September 18, 2026

In short: recording and editing never leave your device. Uploads only happen when you choose to share, sent securely, and we keep as little data about you as possible. The rest of this page is the technical detail for security reviewers. For a product-level walkthrough, see how privacy works.

Local-first by design

Recording and editing happen entirely in your browser. Video data is written to your computer — in your browser’s local storage — and is never transmitted to our servers unless you explicitly choose to upload and share. This dramatically reduces the attack surface — there is no central recording vault to breach for content you never upload.

Encryption in transit

All communication between your browser and our servers uses HTTPS (TLS). Uploads go directly to object storage via signed URLs — recording bytes do not pass through our application servers.

Authentication

You can sign in with Google or with an email and password. We never store your Google password, and we never store an email password in plain text — only a one-way hash. Sign-in cookies are httpOnly. You can sign out everywhere from Settings → Security.

Minimal Google Drive access

If you connect Google Drive, we request only the drive.file scope — access limited to files this application creates. The upload happens in your browser, directly to Google; we never receive the file. An encrypted refresh token is stored on our servers so this browser can request a short-lived access token when you save. Access tokens stay in tab memory. We never request broad access to your existing Drive contents. You can disconnect at any time from Settings, which revokes the grant with Google.

Chrome extension

Recording writes the file to this browser’s private storage on your computer (OPFS). The overlay is injected only into the page you are recording. Capture handles, when available, identify the chosen tab to this extension alone. No recording is uploaded unless you later click Share in the editor. The extension does not load remote scripts.

Share link security

Share links use long, randomly generated tokens (~95 bits of entropy) — not sequential or guessable IDs. You can add password protection, set expiration dates, and revoke links at any time. Shared pages are marked so search engines don’t index them.

Privacy-preserving logging

We never store raw IP addresses. Session and share-access logs use one-way HMAC hashes instead. We do not sell data or use third-party advertising trackers.

Responsible disclosure

If you discover a security vulnerability, please report it responsibly via our contact form or email support@recbaba.com. We will acknowledge reports promptly and work to resolve confirmed issues.

This page describes our current security practices. It is not a formal audit or certification. Replace with counsel-reviewed content before relying on it for enterprise procurement.