# RecBaba Security — Encryption and Local Recording

> How RecBaba protects your data: screen recordings stay on your device until you share, with encryption in transit and minimal Google permissions.

Recording and editing never leave the device. Uploads happen only when you choose to share.

- HTTPS (TLS) for all browser-to-server traffic. Uploads go to object storage via signed URLs; recording bytes do not pass through application servers.
- Chrome extension: overlay on the page you record; OPFS on this device; no remote code; capture handles identify the chosen tab to this extension only.
- Sign-in with Google or email and password. Password hashes are one-way. Sign-in cookies are httpOnly.
- Drive uses drive.file scope only. Encrypted refresh token on RecBaba servers; access tokens stay in the browser tab.
- Share tokens are long and random (~95 bits). Optional password, expiry, revoke. Share pages are noindex.
- No raw IP addresses. Session and share-access logs use HMAC hashes. No ad trackers.

Report vulnerabilities via /contact.md or support@recbaba.com.
