Reference
Data and privacy
Reviews live in your project folder. Settings live in ~/.movie-ade/, and keys and accounts in the OS user-data folder. Only crash reports reach the developer, through Sentry, and you can turn them off.
#Inside .ade-movie/reviews/
<project>/.ade-movie/reviews/20261003-104500/
├── feedback.md # what the agent reads
├── 01.png, 02.png… # one or more images per finding
├── session.json # review state and edit history
├── events.jsonl # action log (built-in browser only)
├── recording.webm # the video
└── work/ # intermediate audio and frames
When recording starts, .ade-movie/ is appended to .git/info/exclude. Worktrees and submodules are handled. .gitignore is never modified. An interrupted review can be recovered from history if its records survived. The app then warns that the last seconds may be missing.
#Retention
Keep recordings (7 days by default, 30 days, or Forever): on startup, completed reviews older than that lose recording.webm and work/. feedback.md and the finding images are kept. Incomplete reviews are never pruned. Pruning runs at launch, for the last opened project.
#What leaves your machine
| When | Destination | Data |
|---|---|---|
| Transcription: On device (free) | none | — |
| Transcription: OpenAI / compatible | OpenAI or your Base URL | audio chunks |
| Model download | Hugging Face | file request |
| Organize | your Claude Code / Codex CLI, or the LLM endpoint you set in organizer | text and action log only (no images, audio, or video) |
| Acceptance check (decision model, off by default) | your agent, through the local relay, to Ollama / Cloudflare / AI Gateway / TypeSafe / your URL | what the agent sends: finding text, "Done when", and BEFORE/AFTER screenshots (image models only) |
| Send to Agent | the agent in your terminal | one instruction pointing at feedback.md |
| Send to GitHub | GitHub via gh | body text only (no images) |
| Footer usage | Anthropic, ChatGPT | usage request with your own login |
| Check for Updates (manual) | download server (Cloudflare R2) | request for latest.json |
| A crash or error (Send crash reports on) | Sentry | stack trace and OS / CPU / app versions (see Crash reports) |
- The app has no analytics, no performance tracing, and no session replay. The only data it sends without you asking is crash reporting: errors, one session per launch, and slow-startup and freeze warnings, all described below and all controlled by Send crash reports.
- Secret-looking values in URLs (tokens, keys) are redacted before they are written to
feedback.md. - Text captured from the page is marked as data in
feedback.md, so the agent is told not to follow instructions found in it. - This website (not the app) counts page views with Cloudflare Web Analytics: cookie-free, with no cross-site tracking and no personal data.
#Crash reports
When the app crashes or hits an unhandled error, MOVIE-ADE sends a crash report to Sentry (opens in a new tab) so the bug can be fixed. It is on by default. Turn it off in Settings → Privacy → Send crash reports, or with Turn off on the notice shown at first launch. Turning it off takes effect at once. Turning it back on takes effect at the next launch. Development builds (pnpm dev) also send, tagged development, so the developers can fix crashes they hit while working. E2E runs and unit tests never send.
| Sent | Not sent |
|---|---|
|
|
The installed app sends at most 10 reports per launch and only half of JavaScript errors (native crashes are always sent). Development builds send every error, up to 50 per launch. The same error is sent only once per launch. Slow startups (over 5 seconds) and long freezes of the app (over 1 second) are sent as warnings, at most once every 10 minutes. No performance tracing or session replay is used. The app uses Sentry's free plan. If it fills up, extra reports are dropped and nobody is charged.
Building MOVIE-ADE yourself? Set MOVIE_ADE_SENTRY_DSN to your own Sentry DSN, or to an empty string to send nothing. The code is in src/main/telemetry.ts and src/shared/telemetry.ts.