TakeOne is a screen recorder for product demos made by Abyssinia Labs LLC. This page says what it stores about you, where that lives, who else touches it, and how you get it out.
What we store
Your account. You sign in with Google or Apple. We keep the name and email address it gives us, Google's profile picture, and a session so you stay signed in. If you ask Apple to hide your email, we only ever see the address Apple forwards from. We never see your Google or Apple password.
Your recordings. The screen, camera and audio files of each take, its poster and any export you publish, with the title, description, script, edits and share settings you give it. While you record, the take is also written to your own browser’s storage; that copy is cleared a day after it has uploaded.
Transcripts and clicks. A transcript, when you or your agent add one. If your own app runs the TakeOne beacon while you record, where the pointer moved and clicked during the take.
The Chrome extension. It records the tab you start it on, with that tab’s sound when you ask, your microphone and camera when you turn them on (both start off), and, when Clicks and cursor is on, where the pointer moved and clicked in that tab; nothing from other tabs, and nothing while no take runs. The take stays in the extension’s own storage on your computer until it has uploaded, then that copy goes. It uses your takeone.dev sign-in: it asks takeone.dev for a short-lived token for that sign-in and keeps it in the browser’s session storage, which is cleared when the browser closes, and it watches the takeone.dev sign-in cookie and no other, so signing out on takeone.dev signs it out. It sends nothing anywhere but TakeOne.
Share links. You choose who can watch each link. We count views as a number and keep no record of who watched. A link’s password is stored hashed, and a viewer who unlocks a link gets a session that expires.
What you connect. API tokens, stored hashed so only you ever see the value; apps you connected with a sign-in, with the name each app your agents use gives itself (Claude Code, Cursor) so you can see and stop it; and webhooks, with the addresses we send to. When a token or an app calls the API, the call, its time and that app’s name are logged for 30 days, and so is each webhook delivery. A request an agent makes for you to record keeps its title and script until a month after it expires.
Payments. If you pay for a plan, Stripe takes the payment and holds your card details; we never see or store a card number. We keep your plan, its status and renewal date, and the ids Stripe gives your customer record and subscription.
Feedback and errors. Notes you send from the Feedback dialog, with your account and, if you chose, the page you sent them from. When something fails in the app, the step that failed, the error message and your browser’s version, so we can fix it.
Cookies. A session cookie for sign-in, a preference for whether the sidebar is collapsed, and short-lived cookies while you connect an app. No advertising, no analytics, no tracking pixels.
Where it lives
Your account, your recordings’ details and the logs are in Convex. The files, and the app itself, run on Cloudflare, which also controls access to the app. Sign-in is by Google or Apple, and payments are processed by Stripe.
When you publish through the API and no TakeOne tab of yours is open, the export is rendered on a GitHub Actions runner that fetches the files through short-lived links. If you connect an agent through the MCP server, MCPCloud holds the token or connection for you, encrypted, and uses it only for the calls you allowed; signing in to MCPCloud from TakeOne shares your name, email address and account id with it.
TakeOne sends your recordings to no AI service. An agent you connect does what you ask with the access you gave it. No data is sold, and none is used to train anything.
Who can see your recordings
You; anyone with a link you shared, within the protection you set; and any agent or app you gave a token or a connection. We look at recordings only to run the service or when you ask for help, and never publish them.
Keeping and deleting
Deleting a recording removes its files at once. Its details stay for 30 days so a mistaken delete can be undone, then they go too. The API log and webhook deliveries are kept for 30 days. Download a recording’s files from its page at any time.
To delete your account and everything in it, open Account and settings from the account menu and choose Delete account. Every recording and its files, your share links, tokens, webhooks and settings go, and any subscription is cancelled. It cannot be undone. You can also write to the address below from the email you signed in with, and we will do it for you within 30 days.
Contact
Abyssinia Labs LLC, support@takeone.dev