How GlideClip handles your data
GlideClip finds and blurs sensitive text in screen recordings and adds training callouts. It runs the video work entirely in the user's web browser. Videos are never uploaded.
- Screen recording stays local too. When a user records in GlideClip, the browser asks what to share and for the microphone; the recording is written to this browser's own storage on disk and opened in the editor. It is never sent anywhere.
- The video never leaves the computer. It is opened from disk into the browser tab's memory, processed there, and the result is saved back to disk.
- Offline and self-hosted editions: no server, no database, no accounts, no analytics, no cookies. GlideClip is a set of static files on your own web server.
- Hosted edition (glideclip.com): sign-in and billing are on a separate account page (Clerk, with Stripe). The editor page loads neither. GlideClip's server keeps: monthly counts of AI requests and tokens per account (numbers only); for Pro, the account's synced settings (brand kits, series and usual choices; never videos, scans, transcripts or projects), which can be deleted from the account page; and for Enterprise companies, the settings an admin saves (blur rules, brand kit, templates, AI data fields, limits) and the company's AI key, encrypted. It never receives video, frames, audio or transcripts.
- Outbound traffic is limited by the browser itself. A Content Security Policy only allows downloads of the app's code libraries and the speech model, plus the optional AI service. Any other request, including any attempt to send data elsewhere, is blocked by the browser.
- The only optional outbound data is text, for AI-suggested callouts and summaries. It is off by default and has every detected sensitive item replaced by
[REDACTED]. Offline and self-hosted editions: it goes from the browser to the AI service with the user's own API key, and IT can remove it with one setting. Hosted edition: it goes through GlideClip's relay (GlideClip's key for Pro, the company's key for Enterprise), which forwards and counts it and stores neither the text nor the reply; a company admin can switch it off.
What happens to each kind of data
| Data | Where it goes |
|---|---|
| The video file | Read from disk into the browser tab. Never uploaded. Released when the tab closes. |
| Text on screen (detection) | Read by an OCR engine (Tesseract.js) running in background workers inside the tab. Stays in memory. |
| Narration audio | Transcribed by a speech model (Whisper) running in a background worker inside the tab. Stays in memory. |
| Blurred copy, blur plan, project file, redaction report | Created in the tab and saved to the user's computer as ordinary downloads. The project and blur-plan files contain no video. The report masks blurred values (first two characters only). |
| Optional AI suggestions | Only if the user switches it on (Offline and self-hosted: and enters an Anthropic API key; hosted: through GlideClip's relay): the transcript text, on-screen labels and the user's pasted script are sent to api.anthropic.com, with every value GlideClip found (emails, phone numbers, web addresses, IDs, listed names) replaced by [REDACTED], even values the user chose to leave visible in the video; only the user's own "never blur" list is kept. No video, images or audio are ever sent. |
Network connections
These are the only hosts the app can contact. All but the last are downloads into the browser (code and model files); no user data is sent to them.
| Host | Purpose | When |
|---|---|---|
cdn.jsdelivr.net | Code libraries: Tesseract.js 5.1.1 (OCR), transformers.js 3.0.2 with ONNX Runtime (speech), Mediabunny 1.59.1 (reading and writing MP4 for the final render), Anthropic SDK 0.128.0. Pinned versions. | First use, then cached by the browser |
huggingface.co, *.hf.co | Speech model weights (Whisper base.en, about 80 MB). | First transcription, then cached |
api.anthropic.com | Optional AI suggestions (text only, redacted). | Only when the user turns it on |
Everything is fetched over HTTPS. There is no telemetry, tracking or crash reporting.
Licensing
A paid license is a small signed text file, license.txt, placed next to index.html. The
browser checks its digital signature (Ed25519) locally against a key built into the app, and checks that it was
issued for this site's host name. Checking a license makes no network connection and sends nothing. Without a valid
license the app runs as the free edition. Scanning, review, blurring and the redaction report work in every edition,
so a lapsed license can never stop someone finishing a safe video. The license check needs HTTPS (or
localhost) and a current Chrome, Edge, Firefox or Safari.
Hosted GlideClip website with sign-in. Sign-in and billing happen on a separate account page (Clerk, with Stripe). After sign-in, that page gives the editor a weekly signed license through the browser's own storage; the editor page loads no sign-in code and checks the license itself, as above.
| What is sent (hosted edition) | When |
|---|---|
| The user's sign-in details (an email address), to the sign-in service, from the account page only | Signing in |
| Nothing from the app. Payment happens on the payment provider's own form | Subscribing or managing billing |
| The redacted text described above, relayed to Anthropic and not stored | Only when the user asks for AI suggestions |
| The account's settings (no video, scans, transcripts or projects), to GlideClip's server | Pro: shortly after settings change, and when the editor opens |
| A request for the company's settings, signed like the license; nothing from the user's work | Enterprise members: when the editor opens |
| The company's settings and AI key, from the admin page | Enterprise admins: when they save |
Video, frames and audio are never sent, in any edition.
How this is enforced
The page carries a Content Security Policy, and hosts should also send it as an HTTP header (the included
_headers file does this on Cloudflare Pages and Netlify). The header version also applies to the
background workers. Blocked requests fail inside the browser before anything leaves the computer.
default-src 'self'; script-src 'self' https://cdn.jsdelivr.net 'wasm-unsafe-eval' blob:; worker-src 'self' blob: https://cdn.jsdelivr.net; connect-src 'self' blob: data: https://cdn.jsdelivr.net https://huggingface.co https://*.huggingface.co https://*.hf.co https://api.anthropic.com; img-src 'self' blob: data:; media-src 'self' blob:; style-src 'self' 'unsafe-inline'; font-src 'self'; object-src 'none'; base-uri 'none'; form-action 'none'; frame-ancestors 'none'
Other headers sent: X-Content-Type-Options: nosniff, Referrer-Policy: no-referrer,
Permissions-Policy (camera, location, payment and USB disabled; microphone and screen capture allowed only for GlideClip's own page, and only when the user starts a screen recording and grants them in the browser),
Cross-Origin-Opener-Policy: same-origin.
How to verify it yourself
- Open GlideClip, press F12 and open the Network tab (tick “Preserve log”).
- Load a test recording, scan it, transcribe it and export a safe copy.
- Filter out the app's own origin. Only GET requests to the library and model hosts above should appear; the video file itself never appears as an outgoing request.
- To confirm the lock works, run
fetch("https://example.com", {method: "POST", body: "test"})in the Console. The browser refuses it with a Content Security Policy error.
Admin settings
Edit config.js on the server that hosts GlideClip:
| Setting | Effect |
|---|---|
allowAI: false | Removes the AI switch. To enforce it at the browser level too, delete https://api.anthropic.com from the policy in index.html and _headers. |
allowTranscription: false | Removes transcription; the speech model is never downloaded. Callout suggestions then need the AI switch or are entered manually. |
defaultLevel | The sharing level selected on open: internal, partner, public or custom. |
Two editions. The Standard edition (about 35 KB) loads its libraries from the public
hosts above. The Offline edition (about 105 MB) ships the libraries and speech model with the app in a
vendor folder, so it needs no internet connection; its policy allows only the app's own site plus,
optionally, api.anthropic.com.
What's stored on the user's computer
- The browser's normal cache of the library and model files.
- The Anthropic API key, in the browser's local storage, only if the user enters one for AI suggestions. It stays in that browser profile and is sent only to
api.anthropic.com. - Files the user chooses to download (safe copy, report, blur plan, project file).
- Work in progress, so the user can pick up where they left off: for each of the last 12 videos, the callouts, edits and settings, plus the scan results (the text that was found, so it can be blurred again) and the transcript. It is kept in the browser's own storage (IndexedDB) on that computer only, never sent anywhere, and can be cleared with “forget work saved in this browser” in the app. A company policy can turn it off.
In the hosted edition, also: the weekly license, a copy of the synced settings (Pro) and a copy of the company's settings (Enterprise), in the browser's local storage. The account page uses the sign-in service's cookies.
Offline and self-hosted editions: nothing else, no cookies, no accounts, no server-side storage.
Hosting
The Offline and self-hosted editions are plain static files (HTML, CSS, JavaScript). Any web server can host
them: an internal intranet server, SharePoint or IIS, or a static host such as Cloudflare Pages. There is no
server-side code: deploy the package folder as it is. (The hosted edition at glideclip.com adds the account page
and a small API, run by GlideClip.) The serve.py file and the test-media folder are
development tools and should not be deployed.
Developer test shortcuts only work on localhost.
The Offline edition adds a vendor folder and a web.config that registers the file types
it serves on IIS (.wasm, .mjs, .onnx, .gz). One model file is
52 MB, larger than some static hosts allow per file (Cloudflare Pages allows 25 MB), so host the Offline edition on
an internal web server or IIS.
Limitations: a person must review
Automatic detection reduces work; it does not guarantee that everything sensitive is found.
- Very small, blurry, low-contrast or fast-scrolling text can be misread or missed. Text inside images, handwriting and non-English text are not reliably detected.
- Names and company-specific values are only found if they are listed in “Names or words to always blur”.
- The app is built around review: every finding is listed and shown on the timeline, the user can add blur boxes by hand, and the redaction report records what was blurred and what was left visible.
- The “Who will see this video?” setting changes what is hidden by default. Internal mode leaves record IDs and web addresses readable.
Third-party components
| Component | Used for | License |
|---|---|---|
| Tesseract.js 5.1.1 and tesseract.js-core | Reading text on screen | Apache-2.0 |
| Tesseract English language data | OCR model | Apache-2.0 |
| transformers.js 3.0.2 | Running the speech model | Apache-2.0 |
| ONNX Runtime Web | Model execution engine | MIT |
| Whisper base.en (ONNX build) | Speech recognition model | MIT |
| Mediabunny 1.59.1 | Reading the recording and writing the final MP4 (in-browser render) | MPL-2.0 |
| Anthropic TypeScript SDK 0.128.0 | Optional AI suggestions | MIT |
Optional AI: data handling
When used, AI suggestions call the Claude model claude-opus-5-5 through Anthropic's API. Only
redacted text is sent.
- Offline and self-hosted: with the API key the user provides, from the browser. Requests are
covered by the key holder's agreement with Anthropic (for an organization key, the organization's commercial
terms). Organizations that do not permit this should set
allowAI: falseand removeapi.anthropic.comfrom the policy. - Hosted, Pro: through GlideClip's relay with GlideClip's key, under GlideClip's agreement with Anthropic. The relay stores neither the text nor the reply, only counts.
- Hosted, Enterprise: through the relay with the company's own key, which the company's admin saves on the admin page. It is stored encrypted on GlideClip's server and used only for that company's requests, under the company's agreement with Anthropic. GlideClip's server has to decrypt it to make those requests, so the company trusts GlideClip with the key; an admin can remove it, or switch AI off, at any time.
Questions
For security reviews and anything on this page: support@glideclip.com.
The open-source libraries, fonts and model GlideClip uses, with their licences: Third-party notices.