Reference

Data and privacy

Reviews live in your project folder. Settings live in ~/.movie-ade/, and keys and accounts in the OS user-data folder. Only crash reports reach the developer, through Sentry, and you can turn them off.

#Inside .ade-movie/reviews/

<project>/.ade-movie/reviews/20261003-104500/
├── feedback.md      # what the agent reads
├── 01.png, 02.png…  # one or more images per finding
├── session.json     # review state and edit history
├── events.jsonl     # action log (built-in browser only)
├── recording.webm   # the video
└── work/            # intermediate audio and frames

When recording starts, .ade-movie/ is appended to .git/info/exclude. Worktrees and submodules are handled. .gitignore is never modified. An interrupted review can be recovered from history if its records survived. The app then warns that the last seconds may be missing.

#Retention

Keep recordings (7 days by default, 30 days, or Forever): on startup, completed reviews older than that lose recording.webm and work/. feedback.md and the finding images are kept. Incomplete reviews are never pruned. Pruning runs at launch, for the last opened project.

#What leaves your machine

WhenDestinationData
Transcription: On device (free)none—
Transcription: OpenAI / compatibleOpenAI or your Base URLaudio chunks
Model downloadHugging Facefile request
Organizeyour Claude Code / Codex CLI, or the LLM endpoint you set in organizertext and action log only (no images, audio, or video)
Acceptance check (decision model, off by default)your agent, through the local relay, to Ollama / Cloudflare / AI Gateway / TypeSafe / your URLwhat the agent sends: finding text, "Done when", and BEFORE/AFTER screenshots (image models only)
Send to Agentthe agent in your terminalone instruction pointing at feedback.md
Send to GitHubGitHub via ghbody text only (no images)
Footer usageAnthropic, ChatGPTusage request with your own login
Check for Updates (manual)download server (Cloudflare R2)request for latest.json
A crash or error (Send crash reports on)Sentrystack trace and OS / CPU / app versions (see Crash reports)
  • The app has no analytics, no performance tracing, and no session replay. The only data it sends without you asking is crash reporting: errors, one session per launch, and slow-startup and freeze warnings, all described below and all controlled by Send crash reports.
  • Secret-looking values in URLs (tokens, keys) are redacted before they are written to feedback.md.
  • Text captured from the page is marked as data in feedback.md, so the agent is told not to follow instructions found in it.
  • This website (not the app) counts page views with Cloudflare Web Analytics: cookie-free, with no cross-site tracking and no personal data.

#Crash reports

When the app crashes or hits an unhandled error, MOVIE-ADE sends a crash report to Sentry (opens in a new tab) so the bug can be fixed. It is on by default. Turn it off in Settings → Privacy → Send crash reports, or with Turn off on the notice shown at first launch. Turning it off takes effect at once. Turning it back on takes effect at the next launch. Development builds (pnpm dev) also send, tagged development, so the developers can fix crashes they hit while working. E2E runs and unit tests never send.

SentNot sent
  • Error type and message, with home-folder paths shown as ~
  • Stack trace (where in MOVIE-ADE's code it happened)
  • For native crashes: the minidump (thread stacks of the crashed process)
  • OS name and version, CPU architecture, Electron / Chrome / Node versions, app version, screen size, memory size
  • App lifecycle events right before the error (for example app.ready), and startup failures
  • Which part of the app failed: a screen area that could not render (and its React component names), an IPC call, a terminal that could not start, a crashed or hung process, or a page of the app that failed to load
  • Where you were in the app: editor or feedback mode, the open tab (Browser, Findings, Settings, or just file), and whether a recording was running
  • One session per launch (started, ended normally, or crashed), so the crash-free rate of each version can be measured
  • A random install ID (created on first launch and kept in the app's settings folder), so the number of affected installs can be counted. It is not linked to your name, email, or device
  • For crashes only: the last 50 of MOVIE-ADE's own log lines (such as [startup] and [recording]), shortened and with paths, URLs, emails, and keys removed
  • Your project folder path and file names (replaced with <project>)
  • URLs opened in the built-in browser, and any other web address (replaced with <url>)
  • Terminal output, transcripts, findings, page text, screenshots
  • Email addresses and API keys or tokens (replaced)
  • Your name, device name, IP address (not stored), cookies, local variables
  • Clicks, network requests, and any log line that isn't one of MOVIE-ADE's own

The installed app sends at most 10 reports per launch and only half of JavaScript errors (native crashes are always sent). Development builds send every error, up to 50 per launch. The same error is sent only once per launch. Slow startups (over 5 seconds) and long freezes of the app (over 1 second) are sent as warnings, at most once every 10 minutes. No performance tracing or session replay is used. The app uses Sentry's free plan. If it fills up, extra reports are dropped and nobody is charged.

Building MOVIE-ADE yourself? Set MOVIE_ADE_SENTRY_DSN to your own Sentry DSN, or to an empty string to send nothing. The code is in src/main/telemetry.ts and src/shared/telemetry.ts.

Edit this page on GitHub (opens in a new tab)