Privacy Policy
Last updated: September 4, 2026
1. Introduction
Recordable (“we”, “us”, “our”) provides workflow documentation software. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our website and services at recordable.ai (the “Service”).
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
Recordable is the data controller for the personal data collected through the Service. If you have questions about this policy or your data, contact us at privacy@recordable.ai.
3. What Data We Collect
Account Information
When you create an account, we collect your name and email address. Authentication is handled by our provider Clerk, which may also process device identifiers and session tokens.
Workflow Content
When you record a workflow, our browser extension or desktop app captures screenshots, click positions, and the text you type into form fields. We do not capture audio. Recordings stay on your device until you complete the local review step, where you can blur, exclude, or delete any sensitive content, including entire steps, before anything is uploaded. Once you continue past review, redacted recordings are uploaded to our infrastructure to generate and maintain your workflow documentation.
Payment Information
If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your credit card details. Stripe may collect billing address, card information, and transaction records under their own privacy policy.
Usage Data
We collect basic usage data such as pages visited, features used, and workflow publication events. This helps us improve the Service.
Public Workflow Analytics
When visitors view publicly shared workflows, we may collect anonymous visit counts and step completion progress. We do not store IP addresses, browser fingerprints, or user agent strings for anonymous visitors.
Recording Diagnostics
If a workspace admin enables recording diagnostics, the desktop app can send a short technical summary after a recording: counts and timings, failure categories, and the operating-system class name of the recorded window. It contains no window titles, file names, URLs, keystrokes, screenshots, or raw logs. The recorded application appears only as a number within that session. Summaries are deleted after 90 days.
Recording diagnostics are disabled by default, and you can also disable them on this device. Separately, you can report a problem from within the app. That report contains what you write and anything you explicitly choose to attach; it is deleted after 180 days or with your account, whichever comes first.
4. How We Use Your Data
- To provide, maintain, and improve the Service
- To authenticate your identity and manage your account
- To process payments and manage subscriptions
- To generate AI-powered workflow documentation from your redacted recordings (see §5, AI Processing)
- To translate workflow documentation into other languages
- To send you service-related notifications (e.g., feedback on shared workflows)
- To comply with legal obligations
5. AI Processing
Recordable uses third-party AI providers to turn your recordings into documentation and to power optional autonomous-agent features. We disclose this in detail because the data sent to these providers can include screenshots of your work.
Workflow documentation generation
After you complete the local review step and your redacted screenshots are uploaded, they are sent to Google Cloud (Gemini, optionally routed via Vertex AI) so the model can describe each step. Gemini also handles translation when you publish a workflow in additional languages. We may, at our discretion, route this analysis to other AI providers (currently Anthropic Claude or OpenAI) under equivalent terms; the up-to-date list is in the Processors section below.
Autonomous agents (optional)
If you use the agent feature to delegate browser tasks, the agent sends the screenshots it captures, your instructions, and intermediate model output to its underlying provider (Anthropic, OpenAI, or Google) so the model can decide the next action. Agent runs are clearly initiated by you and the provider is shown before you start.
Redaction is your responsibility
The review step on your device is the only point at which you can remove sensitive information before it leaves the device. Please use it. Once a redacted screenshot has been sent to an AI provider, we cannot retrieve it from that provider on your behalf. We can only delete our own copies.
No model training on your content
We have contractually disabled use of your content for training the providers' foundation models, where that option is offered (currently: Google Cloud Gemini via Vertex AI, Anthropic via the API, OpenAI via the API). We will tell you in this policy if that ever changes.
6. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you signed up for, including account management, workflow processing, and exports.
- Legitimate interest (Art. 6(1)(f)): Improving our Service, anonymous analytics, and security monitoring.
- Consent (Art. 6(1)(a)): Analytics and advertising cookies and other non-essential data collection, which you can accept or decline separately in our cookie banner.
- Customer support access (Art. 6(1)(b)): Where a workspace owner has explicitly enabled support access, our staff may view that workspace on a read-only basis solely to resolve a support request. Access is time-limited, recorded in the workspace’s audit log, and can be revoked at any time.
- Legal obligation (Art. 6(1)(c)): Where required by law (e.g., tax records for payment processing).
7. Third-Party Processors
We share data with the following service providers who process data on our behalf. The country of processing and transfer mechanism for each is listed in §12 (International Transfers).
All processors are bound by data processing agreements and are required to protect your data in accordance with GDPR. View our standard DPA template.
8. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Correct inaccurate personal data via your account settings.
- Right to erasure: Request deletion of your account and all associated data.
- Right to data portability: Export your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: Withdraw consent for analytics or advertising at any time via the cookie settings.
You can exercise your access, portability, and erasure rights directly from the Settings page in your account. For other requests, contact us at privacy@recordable.ai. We will respond within 30 days.
9. Cookies
We use the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| cookie-consent | Stores your cookie preference | 1 year |
| NEXT_LOCALE | Stores your language preference | 1 year |
| __session, __client_uat | Authentication (set by Clerk) | Session |
Authentication and language preference cookies are strictly necessary for the Service to function. Analytics and advertising data collection each require your consent, which you can manage via the cookie banner shown on your first visit. The Cookie Policy lists every cookie in full.
10. Data Retention
We retain your personal data for as long as your account is active. When you delete your account, all associated data (profile, workflows, recordings, exports) is permanently deleted within 30 days. Anonymized usage data may be retained for analytical purposes.
Payment records are retained as required by tax law (typically 7 years) and are managed by Stripe.
Recording diagnostic summaries are deleted after 90 days. Problem reports and optional screenshots are deleted after 180 days or with your account, whichever comes first. When you delete your account, diagnostic summaries are unlinked from you and remain only until they expire.
11. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), access controls, and regular security reviews. While we work to protect your data, no method of electronic transmission or storage is 100% secure.
12. International Transfers
Some of our processors handle data outside the European Economic Area (EEA). Where that happens, transfers are protected by EU Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework (DPF) where the processor is certified, or an adequacy decision. The table below lists where each processor handles data and which mechanism applies. We review processor regions and certifications at least annually.
| Processor | Region(s) of processing | Transfer mechanism |
|---|---|---|
| Clerk | United States | EU SCCs (2021/914) + EU-US DPF |
| Stripe | United States and EU (Ireland) | EU SCCs + EU-US DPF |
| Google Cloud (Gemini / Vertex AI) | EU (configurable via Vertex AI) and United States | EU SCCs + EU-US DPF |
| Anthropic | United States | EU SCCs (used only when this provider is selected) |
| OpenAI | United States | EU SCCs (used only when this provider is selected) |
| Modal Labs | United States | EU SCCs |
| Cloudflare R2 | EU (default region selected for the bucket) | Processed within the EEA, no transfer mechanism required |
| Cloudflare (Turnstile, edge) | Global edge network (request served from the closest PoP) | EU SCCs + EU-US DPF |
| Neon | EU (Frankfurt) | Processed within the EEA, no transfer mechanism required |
| Resend | United States | EU SCCs |
If you require an EEA-only data residency commitment for an enterprise contract, contact us at privacy@recordable.ai and we will work with you on a tailored deployment.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Continued use of the Service after changes constitutes acceptance.
14. Contact
For privacy-related questions, requests, or complaints, contact us at:
You also have the right to lodge a complaint with your local data protection supervisory authority.