Show It Works

LEGAL

Privacy

Last updated 6 September 2026. This describes what the service actually stores, rather than what a privacy policy usually says.

If you have an account

Signing in with GitHub or Google stores your name, email address, and avatar URL, together with the OAuth tokens the provider issues so the session works. Signing in with both, using the same email address, links them to the same single account. Signing in sets a session cookie, and two short-lived cookies that make the sign-in itself work. Those are the only cookies the service sets; there is no analytics, advertising, or third-party tracking anywhere on the site.

API keys are stored only as a salted hash, so a key cannot be recovered from the database. Invitation links are stored the same way. Each key records when it was created, last used, and revoked.

If you were sent a viewer link

You are not tracked. No account, cookie, or identifier is created for you, and your IP address is not stored.

One thing is recorded: the first time a recording is played through its public link, the service saves a timestamp on that recording. It records that the recording was watched, never who watched it, and only ever the first time. It exists so the operator can tell whether uploaded recordings are being watched at all.

Recordings

Video files are held in private cloud storage and are never publicly listed. Playback works through short-lived signed URLs generated per request, and the agent that uploads a recording never receives storage credentials. Alongside the video the service stores its title, the worktree and task names supplied by the agent, any context the agent attached, and technical details such as file size and format.

Review comments and the reviewed checkbox are private to the account and never appear on a public viewer page.

Recordings are deleted 14 to 60 days after upload, depending on the plan of the project they were uploaded into, or sooner if you delete them. After deletion a non-public marker is kept briefly so that an upload already in flight cannot recreate the file; it holds no video content.

Others who process data for us

The site runs on a hosting provider, stores video in a cloud storage provider, and uses a rate-limiting service that sees request IP addresses in order to block abuse without the service storing them.

If error tracking is enabled on this deployment, errors are forwarded to an error-tracking provider. That covers errors on the server, where the failing request path and method are sent, and errors in your browser, where the error message, the technical stack trace, and the address of the page you were on are sent. A page address includes the identifier of the recording you were viewing. Video content, form contents, and uploaded data are never sent, and because browser reports are relayed through this service rather than sent directly, the provider does not see your IP address.

Your data

You can delete any recording from the dashboard at any time. To ask what is held about you or to have your account removed, write to kolomin.k.w@gmail.com.