Cineplot

Privacy policy: Cineplot Recorder

The Cineplot Recorder is a browser extension that watches you perform a workflow in a web application once, and uploads a structured record of it to a Cineplot studio you have connected it to, so that the studio can record a clean version of that workflow for a video. This policy says what the extension reads, when, where it goes, and what it never touches.

Who receives the data

Everything the extension uploads goes to one place: the Cineplot studio whose address you entered in the extension and whose extension token you connected with. That studio is run by the organization that gave you the token, and it is the only recipient. The extension sends nothing to its authors, to a browser vendor, to an analytics service, or to any other third party, and it contains no tracking of any kind.

When it reads anything at all

A freshly installed extension can read nothing. It reads a page only while a recording you started is running, only in the tab you started it in, and only on the web addresses of the recording target you chose, which the studio's operator authorized in advance. The extension asks the browser for permission to read those addresses when you start a session, and never for any others. Stop the recording and it stops reading.

What it collects while you record

  • What you did. The kind of each action such as a click, typing, or a choice from a list, the

address and title of the page it happened on, and a description of the control you used: its role, accessible name, visible text, test id, a short selector, and where it sat on screen.

  • A screenshot at each action. Taken of the tab you are recording in, and only while that tab

is the one on screen. If you switch to another tab or window, nothing is photographed.

  • The shape of what you typed, not the text. Müller GmbH is uploaded as aaaaaa aaaa,

2026-08-19 as 9999-99-99. Choices from a dropdown, checkbox, or radio button are kept as they are, because they are options the application itself offered.

  • Your spoken explanation, if you asked for it. Only when you tick "Record my explanation" does

the extension record the microphone, and it stops when the recording stops. The audio is transcribed by the studio to help it understand why each step exists. It is never used as the narration of a video.

What it never collects

  • Passwords and anything that names a secret. Password fields, one-time codes, card numbers,

and any field whose name, label, or placeholder mentions a password, token, key, card, IBAN, or PIN are dropped entirely, not masked.

  • The text you type, as described above.
  • Credentials in web addresses. Parameters named token, code, access_token, and similar

are removed, and the fragment of an address is removed entirely.

  • Anything outside the authorized addresses. If the application navigates somewhere the target

does not authorize, the extension stops describing the page rather than describing it.

  • Your browsing history, other tabs, other windows, and other websites. None of these are read.
  • Cookies and local storage, except in the one case described next, which you trigger

yourself.

Saving a replay session

Separately from recording, the extension offers a button labelled "Save this session for replay". When you press it, the extension asks the browser for permission to read cookies, reads the cookies and local storage that this browser holds for the recording target's addresses and for no other site, uploads them, and gives the cookie permission back the moment the upload finishes or fails. The studio filters what arrives down to the target's authorized addresses before storing it, encrypts it, and uses it for one purpose: to open its own recording browser already signed in as the account you saved, so that a login never has to be replayed. You can delete a saved session at any time from the extension or from the studio's settings, and saving a new one replaces the old.

Where the data is kept, and for how long

The uploaded recording, its screenshots, and any audio are stored by the studio you connected to and are deleted automatically thirty days after they were made, whether or not anyone signs in. The studio's operator can delete them earlier at any time. What survives a deletion is the list of steps a person approved and the clean recording the studio made from them; the original recording cannot be read again once it is gone.

On your own computer the extension keeps only your extension token, the session you have open, and a recording that is in progress or waiting to be uploaded, in the browser's extension storage. Disconnecting removes the token. Discarding a recording removes it before anything is uploaded.

Permissions, and why each one exists

PermissionWhy
storageThe extension token, the open session, and a recording in progress.
activeTabReading the current tab's address and taking a screenshot of it while you record.
scriptingPlacing the recorder into the page you are demonstrating, on authorized addresses only.
offscreenRecording the microphone when you ask for it, which the extension cannot do from its background.
https://*/* (optional)Requested when you start a session, for exactly the addresses of the recording target you chose.
cookies (optional)Requested when you save a replay session, and released as soon as the upload finishes or fails.

The extension loads no code from the internet. Everything it runs is contained in the package you installed, unminified, so that it can be read.

Sharing and selling

The data is not sold, not shared with third parties, not used for advertising, and not used to determine creditworthiness or for lending. It is used only to produce the video you are recording for, inside the studio you connected to.

Your choices

  • Disconnect the extension at any time from its popup, which removes the token from your browser.
  • Revoke the token from the studio's settings, which stops that installation without affecting

anything else.

  • Discard a recording before it uploads, or delete recordings from the studio afterwards.
  • Forget a saved replay session from the extension or from the studio's settings.
  • Uninstall the extension, which removes everything it kept on your computer.

Changes to this policy

This page is published by the studio you connected to, at its own address, and reflects the version of the extension that studio distributes. Material changes are noted here.

Contact

The controller responsible for this processing is the organization that operates the Cineplot studio you connected the extension to, which issued your extension token. Its name, postal address, and email address are on the imprint of that studio. Questions about this policy, and requests concerning your data under the GDPR, go there.