Skip to content
DemoTake

Security

A recorder with agent access has to earn trust.

DemoTake can see your screen and, in DemoTake Agent, operate apps. So privacy is part of the architecture, not a legal-page afterthought. Here's how it's built.

Defaults

Local-first, least privilege, visible control.

Recordings stay on your Mac

Takes are stored locally. Nothing is uploaded unless you explicitly share or use a hosted feature.

Loopback-only MCP

The MCP server binds to 127.0.0.1 and rejects connections that don't originate on this Mac.

Keychain for secrets

API keys and credentials go in the macOS Keychain—never in take files, preferences or logs.

Secret Guard

Detects passwords, one-time codes, API keys, access tokens, card and bank numbers, emails and phone numbers, and masks them before render or AI.

You see when an agent has control

Foreground mouse and keyboard control is off by default. When enabled, a visible indicator shows the agent is in control.

macOS permissions, explained

Screen Recording is required for capture. Accessibility is only requested by DemoTake Agent, and only for agent control.

Signed and sandboxed where it counts

DemoTake Studio runs in the App Sandbox. DemoTake Agent is Developer ID signed, notarized by Apple and uses the Hardened Runtime.

Analytics off by default

Anonymous usage analytics are opt-in. DemoTake works fully without them.

Data flow

What can leave your Mac, and when.

In Manual and BYO Agent modes, DemoTake itself sends nothing to a model. Everything below is opt-in.

Data that may leave the device, by feature
FeatureWhat's sentTo
Assist / DirectorRedacted structured text; snapshots only if minimal context is offDemoTake AI, via the AI providers on our subprocessor list
BYOKSame as above, billed to your keyYour own OpenRouter API key
DemoTake WebCloud browser sessions you start, and the takes and exports in your cloud libraryDemoTake Cloud (cloud browser and storage)
Sharing & syncOnly the takes and exports you choose to uploadDemoTake Cloud (storage)
Your MCP agentWhatever your agent requests via MCP, e.g. snapshots or UI stateYour agent's own provider, under your agreement with them

Responsible disclosure

Found a vulnerability?

Please email security@demotake.my (not yet live) with steps to reproduce. We'll acknowledge your report, keep you updated and credit you if you'd like. Please don't access other people's data or degrade our services while testing.

An important caveat about agents

When you connect an external agent, that agent—and its provider—can see whatever it asks DemoTake for, such as window snapshots. DemoTake can't control what a third-party agent does with that data. Review your agent provider's terms, and use Secret Guard and demo accounts for anything sensitive.