Security & trust
High-level overview — not a substitute for your security review
Accounts
The Screenfly application uses industry-standard hosted authentication (Supabase Auth). Sessions are issued by the identity provider; we do not store your third-party passwords for providers such as Google.
Data storage
Recordings, baked outputs, narration assets, and related media you create are stored in your account on our cloud infrastructure (including object storage and databases) with access controlled by application-level authorization and row-level security policies scoped to your user identity.
Billing
Paid subscriptions are processed by Stripe. Screenfly does not store full payment card numbers on its own servers; Stripe handles card data according to its compliance programs. You manage invoices and cancellation through the customer billing portal where enabled.
Share links
Public share viewers are designed to expose only the assets you explicitly publish via a share token. Treat share URLs like credentials for that asset: anyone with the link may be able to view the published content for as long as the link remains valid.
Processing
Bake and optional cloud features (such as remote browser or Auto flows where offered) run on our cloud providers. Jobs operate on the minimum data needed to complete the task and write outputs back to your account storage.
For data subject requests or security questions, use the contact channel listed on Contact.
