Security
A recorder with agent access has to earn trust.
DemoTake can see your screen and, in DemoTake Agent, operate apps. So privacy is part of the architecture, not a legal-page afterthought. Here's how it's built.
Defaults
Local-first, least privilege, visible control.
Recordings stay on your Mac
Takes are stored locally. Nothing is uploaded unless you explicitly share or use a hosted feature.
Loopback-only MCP
The MCP server binds to 127.0.0.1 and rejects connections that don't originate on this Mac.
Keychain for secrets
API keys and credentials go in the macOS Keychain—never in take files, preferences or logs.
Secret Guard
Detects passwords, one-time codes, API keys, access tokens, card and bank numbers, emails and phone numbers, and masks them before render or AI.
You see when an agent has control
Foreground mouse and keyboard control is off by default. When enabled, a visible indicator shows the agent is in control.
macOS permissions, explained
Screen Recording is required for capture. Accessibility is only requested by DemoTake Agent, and only for agent control.
Signed and sandboxed where it counts
DemoTake Studio runs in the App Sandbox. DemoTake Agent is Developer ID signed, notarized by Apple and uses the Hardened Runtime.
Analytics off by default
Anonymous usage analytics are opt-in. DemoTake works fully without them.
Data flow
What can leave your Mac, and when.
In Manual and BYO Agent modes, DemoTake itself sends nothing to a model. Everything below is opt-in.
| Feature | What's sent | To |
|---|---|---|
| Assist / Director | Redacted structured text; snapshots only if minimal context is off | DemoTake AI, via the AI providers on our subprocessor list |
| BYOK | Same as above, billed to your key | Your own OpenRouter API key |
| DemoTake Web | Cloud browser sessions you start, and the takes and exports in your cloud library | DemoTake Cloud (cloud browser and storage) |
| Sharing & sync | Only the takes and exports you choose to upload | DemoTake Cloud (storage) |
| Your MCP agent | Whatever your agent requests via MCP, e.g. snapshots or UI state | Your agent's own provider, under your agreement with them |
Responsible disclosure
Found a vulnerability?
Please email security@demotake.my (not yet live) with steps to reproduce. We'll acknowledge your report, keep you updated and credit you if you'd like. Please don't access other people's data or degrade our services while testing.
An important caveat about agents