Last updated: 2026-09-12 — Version v1.1
1. Who we are
Screen Browser is operated by MiCCA OÜ, a private limited company registered in Estonia, registry code 11509095, registered address Tartu, Tartu County, Estonia, VAT number EE101555946 ("MiCCA", "we", "us"). MiCCA is the controller for the personal data described in this policy, unless section 2 says otherwise. Questions about privacy go to [email protected].
This policy covers screenbrowser.com, the app at rec.screenbrowser.com, the API and the MCP endpoint at mcp.screenbrowser.com.
2. Two roles
The Service records your own web application. Two kinds of personal data are involved:
- Account data, such as your name and email address. For this, MiCCA is the controller and this policy applies.
- Data inside your application that appears in a recording, for example names of your users shown on a page. For this, you are the controller and MiCCA is your processor under the Data Processing Addendum. Your own privacy notice governs that data.
3. What we collect
- Account data: name, email address, password (stored hashed), the organisations you belong to and your role in them.
- Organisation data: organisation name, billing contact, plan, invoices and credit balance.
- Guides: the written guides you paste or send through the API, and the steps and narration derived from them.
- Target-application credentials: the username, password and similar secrets you supply so the Service can sign in to your application.
- Recordings and derived artifacts: videos, captions, run reports and run logs.
- Usage logs: which features you use, run timings, API calls, IP address, browser type, and error traces.
- Failure reports: when a run fails and you press Send failure report, the screenshot, page structure and logs of that run. You can withdraw a report, which deletes our copy.
- Payment data: processed by Stripe. MiCCA never stores card numbers; we keep invoices and payment status.
We do not collect special categories of data on purpose. Do not put them in guides.
4. Why we use it and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service: signing in to your application, recording, narrating, delivering videos | guides, credentials, recordings, account and organisation data | performance of a contract |
| Billing, invoices, tax records | organisation and payment data | contract; legal obligation |
| Keeping the Service secure, preventing abuse, enforcing the Acceptable Use Policy | usage logs, attestations | legitimate interest in a secure service |
| Fixing errors and improving the recorder | error traces, failure reports you send | legitimate interest; failure reports only with your action |
| Transactional email: sign-in, receipts, run finished, low balance | email address | contract |
| Product analytics | pseudonymous usage events | consent, which you can withdraw at any time |
| Responding to your requests and legal obligations | whatever the request concerns | legal obligation; legitimate interest |
We do not sell personal data.
5. How credentials are handled
Target-application credentials are encrypted at rest. They are decrypted only for the duration of a run, inside the isolated environment that performs it, and are typed only into your application's browser. They are never sent to any AI provider and never written to logs. That environment is destroyed after the run.
6. AI providers
To turn a guide into a video, the text of your guide, the text content of the pages being recorded and the narration may be sent to the AI providers listed below. Credentials are never included. Avoid putting personal data in guides that you do not want processed by these providers.
7. Sub-processors
We use the following providers. Each processes only what it needs for its purpose.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | application hosting | Germany |
| Cloudflare, Inc. | network, security and file storage | EU / US |
| Daytona | compute for recordings | United States |
| Google LLC | AI language services; never credentials | United States |
| ElevenLabs, Inc. | AI speech services | United States |
| Stripe, Inc. | payments | United States |
| Resend, Inc. | transactional email | United States |
| Sentry | error monitoring | United States |
| Google LLC (Google Analytics) | visit and conversion statistics, only with your consent | United States |
We tell customers at least 30 days before adding or replacing a sub-processor, as the DPA provides.
8. International transfers
Our application and its storage run in the EU. Daytona, Google, ElevenLabs, Stripe, Resend and Sentry are based in the United States. Where personal data leaves the European Economic Area we rely on the EU Standard Contractual Clauses, together with any additional safeguards the transfer requires, and on adequacy decisions of the European Commission where they apply. You can ask [email protected] for a copy of the relevant clauses.
9. How long we keep data
- Run artifacts (videos, captions, run reports and logs) are kept while your account is active, subject to any shorter retention you set in the app, and deleted within 30 days after you delete your account.
- Account and organisation data are kept while the account is active and deleted within 30 days of deletion, except records we must keep for tax and accounting law, which we keep for the period that law requires.
- Credentials are deleted when you remove them from a project or delete the project or the account.
- Usage logs and error traces are kept for a limited period needed for security and debugging and then deleted.
- Backups rotate on a 30-day window, so deleted data can remain in a backup for up to 30 days after deletion.
You can delete projects, runs and your account yourself in the app. You can also ask us to delete your data at [email protected].
10. Cookies and analytics
The app uses essential cookies for sign-in, session security and CSRF protection; these need no consent. Analytics run only if you consent: Google Analytics on the marketing site and on the app's plan-selection and payment pages, so we can tell which pages lead to a subscription. Nothing else in the app is measured by a third party. A choice made on the marketing site is honoured in the app. You can change it at any time through the cookie settings link in the footer. When a payment completes we also record the purchase in Google Analytics from our server, tied to the visit only if you consented; otherwise it is counted without any link to you.
11. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to receive it in a portable format, to restrict or object to its processing, and to withdraw consent where processing is based on consent. Much of this you can do yourself in the app. For anything else, write to [email protected]. We answer within one month, and we may ask you to verify your identity first.
If you believe we have not handled your data lawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live or work.
12. Security
Data is encrypted in transit and at rest. Each recording runs in an isolated environment that is destroyed afterwards. Access to production systems is limited to the people who need it and is logged. If a breach affects your personal data and puts you at risk, we will tell you without undue delay.
13. Changes
We will announce material changes to this policy by email at least 14 days before they take effect. The version and date at the top identify the current text.
14. Contact
MiCCA OÜ, Tartu, Tartu County, Estonia. Privacy: [email protected]. Legal: [email protected].