Security

Where your recordings go

Short version: nowhere. ZoomCap records, edits and exports on your own computer. Here is exactly what does leave your device, and how to check it yourself.

Last updated: September 29, 2026

Data flow

WhatWhere it goesDetails
Screen recordings and audioYour computer onlyThe CLI writes to ~/Movies/ZoomCap and hands the file to the editor over localhost. The browser recorder keeps the recording in your browser's local storage (IndexedDB). Neither sends video to our servers.
Editing and exportYour browser, on your computerZooms, cursor, captions and encoding to MP4 or GIF all run locally. There is no cloud render queue.
Automatic captionsYour browserSpeech-to-text (Whisper) runs in the browser on your machine; audio is not sent to a transcription service. The model file is downloaded once, nothing is uploaded.
KeystrokesTiming only, on your computerOnly when keys were pressed, to drive typing zoom. Which keys were pressed is never captured or stored.
Account (email, account ID)Google FirebaseNeeded to sign in and to know which plan you have.
PaymentDodo PaymentsDodo processes your card. We receive only whether your licence or subscription is active.
Mockup image (optional AI tools only)kie.aiOnly if you use the paid AI mockup tools: the mockup image you choose is sent to generate the animation or background. Screen recordings are never sent.
Page visits (marketing pages only)Google Analytics 4Visit counts on the website and blog. Ad signals off. It never loads in the recorder, editor or export screens.

Check it yourself

You don't have to trust this page. In Chrome or Edge:

  1. Open the editor, then open DevTools (F12) and choose the Network tab.
  2. Record a short clip, edit it, and export it.
  3. Sort the Network tab by size. You will see the app's own code and fonts load, and small sign-in and licence checks, but no request carrying your video.

With the CLI, the recording is a normal file in ~/Movies/ZoomCap, and the editor reads it over localhost, which never leaves your machine.

Permissions the CLI asks for

  • macOS: Screen Recording (to capture the screen) and Accessibility or Input Monitoring (to see clicks and key timing for automatic zoom). Microphone if you record your voice.
  • Linux (X11): no system permission prompt; capture uses ffmpeg and click tracking uses the uiohook library.

npx zoomcap doctor lists which permissions are granted and which are missing.

Payments and refunds

Checkout is run by Dodo Payments, so ZoomCap never sees or stores card numbers. If ZoomCap doesn't work for you and we can't fix it, email us within 14 days for a refund: see the refund terms.

Deleting your data

Recordings are files on your computer, so you delete them like any other file. To delete your account and licence record, contact us from the account's email address.

Reporting a security issue

If you find a vulnerability, please email us before disclosing it publicly. We'll confirm receipt and tell you what we're doing about it. The full legal detail is in the privacy policy.