Security
Your footage stays on your machine.
Last updated August 13, 2026
Design: local-first
Reframe is built around a simple property: your recordings, transcripts, and exported videos never leave your device as part of normal use. Recording, transcription, AI cleanup, and export all run locally. There is no cloud video pipeline, no upload-wait-edit loop, and no copy of your footage on our servers.
What runs on our side
- Authentication (Kinde). Sign-in and account identity are handled by Kinde using industry-standard OIDC. Tokens are exchanged server-side; we never see or store your password.
- Entitlement checks. The desktop app checks your plan status against our API before export. This exchange covers account and plan status only — never the contents of your recordings.
- Newsletter (Resend). Only the email address you opt in with.
- Billing. Payments are processed by our Merchant of Record (Lemon Squeezy). We never see or store full card numbers.
Transmission & storage
All traffic to reframelab.app and the auth/entitlement APIs is served over TLS (HTTPS). Tokens stored by the desktop app are encrypted with your operating system's secure storage. We keep account and billing data only as long as needed, as described in our privacy policy.
Reporting a vulnerability
If you've found a security issue in the Reframe website, desktop app, or any of our services, please report it privately to [email protected]. Please don't open a public issue or share details on social media before we've had a chance to respond.
We aim to acknowledge reports within 48 hours and keep you updated as we triage and fix the issue. We appreciate good-faith research and won't take action against researchers who follow responsible disclosure. Our machine-readable disclosure policy is at /.well-known/security.txt.