What we do with your recordings
By default your recording stays on your device. It only leaves your device in two cases you control: when you use AI Notes (the recording is uploaded to our server to create your transcript and notes; we keep them so the extension can re-open and re-download your notes, and delete them on request), and when a share link is created (the file is end-to-end encrypted on your device before it is uploaded, and erased from our server after 15 minutes).
01The short version
We record the active browser tab to a file in your Downloads folder, and also keep a
copy in the browser's private storage so you can replay and share it from inside the
extension. If you use AI Notes, we send the audio to our server, transcribe and
summarize it, and send you a .docx; the recording, transcript and notes
stay on our server so you can re-open your notes later, and we delete them on request.
If you share a recording, the file is encrypted on your device before
it is uploaded, and the encrypted copy is erased from our server after 15 minutes.
We do not ask for your name, email, or any account. We do not train AI on your
recordings.
02What we record
When you press Record, the extension captures audio and video from the active browser
tab using Chrome's tabCapture API. The recording is written directly to
your Downloads folder as an .m4a or .mp4 file, and a copy is
also kept in the browser's private on-device storage (OPFS) so the extension can offer
an in-app player and sharing (see sections 05 and 06). This file stays on your device -
we never see it - unless you choose to use AI Notes on it (section 04) or create a share
link for it (section 05).
03What we do not record
We do not access your camera. The microphone is captured only when you select the "Audio + Mic" mode, and only for the duration of that recording. We do not capture other tabs, your screen outside the tab, your typing, your clipboard, or your browsing history. We do not read the content of the pages you visit at all. The recorder itself only runs while you press Record and stops the moment you press Stop.
04AI Notes
AI Notes is enabled by default. If you recorded in Audio + Mic mode, the audio uploaded here includes your microphone track - your own voice and any sounds your microphone picked up (for example, other people speaking in the room) are part of what is sent for transcription. Tab-audio recordings contain only the sound of the tab you chose. After you stop recording, here is exactly what happens:
- The audio file is uploaded over HTTPS to our backend server. If the upload is interrupted before it finishes (for example, you close the browser mid-upload), the extension will automatically retry it once on the next browser start, re-uploading the audio from the on-device copy. No new data category is involved - it is the same AI Notes audio you had already chosen to process.
- The audio is sent to our transcription sub-processor. Their API is configured with zero data retention - they do not store or train on submitted audio.
- The transcript is sent to our summary sub-processor. Their API does not train on submitted data.
-
We assemble a
.docxfile with Summary on top and Transcript below, and send it back to your browser, which saves it to your Downloads folder. -
After the
.docxis returned, the recording, the transcript and your generated notes stay on our server so the extension can re-open and re-download your notes later. You can have them deleted at any time (section 12).
We do not use your recordings, transcripts, or summaries to train our models. Our sub-processors - a speech-to-text transcription provider and a large-language-model summarization provider - are contractually prohibited from doing so. If we add or change a vendor, we will update this policy first. To request the current, named list of sub-processors, email us at the address in section 15.
05Share links (end-to-end encrypted)
Lecture Recorder can turn a recording into a private link (and a QR code) so you can open it on your phone or send it to someone. This is the only case where your recording's content leaves your device - and even then, we cannot read it.
A share link is created two ways:
- Automatically, right after a recording finishes, if the popup is open and the file is 100 MB or smaller. The extension prepares the link so it is ready if you want to share.
- Manually, from the "Share" button in the extension's library side panel.
Here is exactly how it works:
- The recording is encrypted on your device using AES-GCM with a 256-bit key. Your browser generates the key; it never leaves your device except inside the link itself.
-
Only the encrypted (unreadable) file is uploaded over HTTPS to our
share service at
share.lecture-recorder.app(a Cloudflare Worker backed by Cloudflare R2 storage). -
The decryption key is placed in the link's URL fragment (the part
after the
#). By web design, the fragment is never sent to our server - it stays in the browser of whoever opens the link. That is what makes the share end-to-end encrypted: our server only ever holds ciphertext it has no key for. - Anyone who opens the link (including via the QR code) downloads the encrypted file and decrypts it locally in their browser using the key from the fragment.
- The encrypted file is automatically deleted from our server 15 minutes after it is created. After that the link stops working.
What our share service can and cannot see: it cannot read the content of your recording (it only holds an encrypted blob with no key). It does observe, as any web server does, the size of the encrypted blob, the time it was uploaded, and the IP address of the device that uploaded it (in standard server request logs). We do not use these to build a profile and they are not linked to your identity.
06On-device recordings library
So the extension can offer an in-app player and the share feature above, your recordings are kept in the browser's private storage (the Origin Private File System, OPFS) on your own device. This storage is private to the extension - it is not the cloud, and these files are never uploaded anywhere on their own.
The library is capped at about 3 GB. When it fills up, the oldest recording's library copy is automatically removed to make room (your separately downloaded file in your Downloads folder is not affected). You can also press Delete on any recording to remove its library copy at any time - again, this never touches the file you downloaded.
07The 300-minute monthly limit
To prevent abuse of the free service, each installation can use up to 300 minutes of AI Notes per rolling 30 days. We track this with:
-
An anonymous
install_id- a random UUID generated on first run, stored inchrome.storage.localon your device. -
A counter on our server keyed only to that
install_idand the total minutes recorded in the rolling window.
The install_id is not linked to your name, email, IP address (which we
discard after each request), Google account, or any other personally identifiable
information. Uninstalling and reinstalling the extension generates a new
install_id and a new quota.
When you hit the limit: the recording still works and the media file is
still saved to Downloads. We just do not generate the .docx for that
session. The widget shows the reset date.
08No accounts, no sign-in
Lecture Recorder has no accounts and no sign-in. You never create a
login, and we never receive a Google account, name, or email in order for you to use the
extension. Everything is keyed to the anonymous install_id described above,
which is not tied to your identity.
Anonymous product analytics. The extension sends small first-party events when it is installed or updated, opened, starts/completes/fails recording or AI Notes, and when you use Share, Copy link, or QR. Safe fields can include the extension version, broad feature and outcome category, recording mode, file format, interface entry point, language code, operation time and approximate byte or item count. They never include your recording, transcript, notes, filename, page address, Share link, Share token, clipboard content, name, email, or account.
Events carry the random install_id, a short-lived random session number, a
random event number used to remove retry duplicates and, when present, a random
acquisition number used to connect an install redirect with the Welcome page. Our
Cloudflare Worker validates them and stores only one-way hashes of the install, session,
acquisition and temporary Share identifiers. The random event number is stored only for
deduplication. Cloudflare derives the request country at the edge; product analytics
does not store raw IP addresses or full browser User-Agent strings.
We use this data to measure active installations, feature adoption, reliability, retention, versions, broad geography, and the Share/Copy/QR funnel. It is not used for ads, cross-site tracking, credit decisions, sale, or personal profiling. Cloudflare Analytics Engine keeps event data for up to three months; aggregate reports without identifiers may be kept longer. We do not use session replay inside the extension or Share recipient page.
The welcome page and the hosted goodbye and rating pages carry analytics used to count installs and removals by country. The welcome page opens once after the first installation and sends the install count through this site, which derives the country from the connection and stores nothing.
09Permissions used
tabCapture- to record audio and video of the active tab.-
offscreen- to run the recorder, the audio pipeline, and share uploads in a background document (required by Chrome Manifest V3, so recording continues while you switch tabs). -
downloads- to save the recording (and the.docx) to your Downloads folder. activeTab- to identify and capture the tab you chose to record.-
storageandunlimitedStorage- to remember your settings, yourinstall_id, and your remaining quota, and to hold your on-device recordings library (section 06). sidePanel- to show the library and summaries in a side panel.-
idleandalarms- to manage recording timers and to run the one-time AI Notes retry (section 04). -
notifications- to tell you when a recording or your notes are ready.
We do not request tabs, history, cookies,
webRequest, or any host_permissions for browsing data. The
extension does not inject scripts into the pages you visit and runs no content scripts
on them at all.
10Data retention summary
| Data | Where | Kept for |
|---|---|---|
| Recording (.m4a / .mp4) | Your device (Downloads) | Until you delete it |
| Recording copy in the in-app library | Your device (browser private storage) | Until you delete it, or auto-evicted at the ~3 GB cap (oldest first) |
| Notes (.docx) | Your device | Until you delete it |
| Audio uploaded for AI Notes | Our server | Until you ask us to delete it (section 12) |
| Transcript and generated notes | Our server | Kept so you can re-open your notes; deleted on request (section 12) |
| Encrypted file for a share link | Our share server (ciphertext only - we hold no key) | 15 minutes, then deleted |
| install_id + quota counter | Our server | Until you uninstall (deletable on request) |
| Anonymous product events + hashed identifiers | Cloudflare Analytics Engine | 3 months; identifier-free aggregate reports may be kept longer |
| Server access logs (incl. IP) | Our server | 14 days |
11Ratings & feedback links
The extension shows a small "Rate us" prompt and, when you uninstall, opens a short feedback page. These are just links. Ratings of one to three stars open our hosted rating page. Ratings of four or five stars open our page on the Chrome Web Store. Removing the extension opens our hosted uninstall feedback page. The extension itself does not collect any rating or feedback data.
If you send optional feedback after a low rating, or from the page that opens after you remove the extension, we receive the reason you picked, any comment you typed, the extension version, and the interface language. We do not collect your email, your name, an install identifier, or your IP address. Comments are delivered to us through Telegram so we can read them. Submissions without a comment are stored only as counts. We do not sell this information.
12Your rights (GDPR, UK GDPR, CCPA)
Even though we hold almost nothing, you can:
- Ask what we have linked to your
install_id - Ask us to delete it
- Object to processing
Email support@lecture-recorder.app with your
install_id (visible in extension Settings → About). We respond within 30
days. There is nothing to "log in" to.
Legal basis for processing (GDPR Art. 6):
- AI Notes processing - your consent (granted when you keep AI Notes enabled in Settings).
-
install_id+ quota counter - our legitimate interest in preventing service abuse. - Bounded anonymous product events - our legitimate interest in measuring reliability, feature use and retention without collecting user content or account identity.
13Children
Lecture Recorder is intended for users 13 and older. We do not knowingly collect data
from children under 13. Since we do not collect names, emails, or IP-linked profiles in
the first place, we have no way to identify a child user. If you are a parent and
believe we have data tied to your child's install_id, email us and we will
delete it.
14Changes to this policy
If we change this policy, we will update the "Last updated" date at the top of this page and post a notice in the extension before the change takes effect.
15Contact
support@lecture-recorder.app