Privacy Policy
Replayable is designed around local capture. Your saved recordings stay on your computer unless you choose to share them.
Last updated: September 22, 2026
Information Replayable collects
Replayable collects only the information used to operate the website, sign-in, beta access and technical support workflows. The website does not upload or store your Replayable recordings, screen captures, system audio, microphone audio or other personal files.
Google account information
When you sign in with Google, Replayable receives information provided through Google sign-in, including your Google account identifier, verified email address, name and profile picture URL. Replayable stores the account identifier, email, name and profile picture URL in its user account record. Google handles your Google account and its sign-in process under Google's own privacy policy. Replayable does not receive or store your Google password.
Beta registration
A signed-in account is registered with Replayable and may be marked for beta access. Beta records can include an email address, name, account identifier, invitation status and the administrator or account records associated with the invitation. This information is used to determine whether you can view and download beta builds.
Technical error logs
The Windows application can send technical error reports to Replayable. These reports may contain app version, Windows version, error type, error message, stack trace, submission IP address, user-agent information and the supplied timestamp. The endpoint accepts technical fields only; recordings, screenshots and personal files are not accepted or stored as part of these reports. Replayable may also keep limited server-side diagnostic logs, such as request, authentication and session troubleshooting events, when diagnostic logging is enabled. Do not include secrets or unrelated personal information in an error message or stack trace.
How and why information is used
Replayable uses collected information to:
- authenticate your account through Google;
- display your account name, email and profile picture;
- maintain beta registration and control access to beta releases;
- provide, protect and troubleshoot the website and sign-in flow; and
- diagnose crashes and other technical problems in the Windows application.
Information is collected for these operational purposes, not to upload or analyze local recordings. Replayable does not currently use this information for targeted advertising or sell it to data brokers.
Data retention
Account, beta and release records are retained while they are needed to operate the account and beta program. Technical error logs and diagnostic logs are kept for troubleshooting and operational needs. Replayable does not currently publish a fixed retention schedule for these records. Database-backed login sessions are temporary and are removed after their configured expiry during session cleanup. Retention can therefore vary by record type and operational need.
Third-party services
Replayable uses Google sign-in and Google's OAuth and user-information endpoints to authenticate accounts and obtain the profile information described above. Replayable also relies on its hosting provider and database infrastructure to operate the website and store its server-side records. Those providers may process information as needed to provide infrastructure services under their own terms and privacy policies.
Payment processing
Replayable uses Dodo Payments to create hosted checkout sessions for Replayable Pro. When a signed-in user starts checkout, Replayable sends Dodo the customer's email address and name, along with checkout metadata such as the Replayable user ID, device ID, product ID and checkout source. The checkout page is hosted by Dodo rather than by Replayable.
Replayable receives verified payment and subscription webhook events from Dodo. The website stores provider customer, payment and subscription identifiers when provided, the associated Replayable user ID and customer email when available, event type, verification and processing status, and the webhook event payload in its payment-event audit record. It also stores a normalized provider customer ID, provider subscription or payment identifier, plan, status and current period end in its subscription record.
Replayable's own server-side records are designed for payment workflow and account entitlement tracking. The code in this project does not show a separate collection path for card numbers, CVV values, bank account details or other raw payment-instrument data; those details are handled by Dodo as the payment provider. Replayable stores Dodo identifiers and webhook metadata needed to verify and grant access to Pro, not an internal card or banking record.
Optional product and update emails
Replayable may offer optional emails about Replayable product updates, announcements and related product information. Choosing to receive these emails is optional and is not automatic when you create or use an account. Users can withdraw consent at any time using the unsubscribe link in an email or by contacting Replayable at support@replayable.in.
Account and service emails are different from optional product/update emails. Service emails may include sign-in or account notices, beta access updates, support communication and operational notices. Optional product or announcement emails are separate and only sent when the user has opted in.
External download providers
Replayable release files are hosted by external download providers. The website stores and displays an external download URL; release files are not stored on Replayable's website. When you follow a download link, the external provider may collect information under its own privacy policy. Review that provider's terms before downloading.
Cookies and sessions
Replayable uses a necessary session cookie named replayable_session for login state, CSRF protection and other session data. The cookie is configured as HttpOnly and SameSite=Lax and is marked Secure when the request uses HTTPS. Server-side session data is stored in the database when configured, and expired sessions are cleaned up. Google sign-in may also set its own cookies or browser storage as part of Google's sign-in flow. Replayable does not currently describe or use an analytics or advertising cookie system.
Security
Replayable uses measures including HTTPS-aware secure session cookies, server-side validation of Google tokens and issuer, CSRF checks, prepared database statements, authenticated app API requests and restricted administrative access. No method of transmission or storage is completely secure, so Replayable cannot guarantee absolute security.
Your rights and account deletion
You may ask what account information Replayable holds about you, request correction of inaccurate account information, or request deletion of your account information. Replayable does not currently provide a self-service account deletion button or a formal automated rights-request portal. To make a request, contact the Replayable operator using the contact details associated with the website and include the Google account email used for Replayable. Requests may need verification, and some records may be retained where necessary for security, fraud prevention, legal obligations or unresolved technical matters.
Replayable has not represented that it is GDPR- or CCPA-compliant and this policy does not make that claim.
Children's privacy
Replayable is not directed to children and does not knowingly request personal information from children. If you believe a child has provided account information to Replayable, contact the operator so the information can be reviewed and deleted where appropriate.
Policy changes
Replayable may update this policy when its information practices or services change. The updated version will be posted on this page with a revised "Last updated" date. Continued use of Replayable after an update means the updated policy applies to future use; material changes will be described on this page where appropriate.
Contact
For privacy questions, account deletion requests or concerns about information handling, contact the Replayable operator using the contact details provided with the website or service. Replayable currently does not expose a public privacy email address or contact form in this site. Include enough information to identify your account, but do not send your Google password, OAuth tokens or other secrets.