In your control.

Nothing leaves your Mac unless you send it.

A screen recorder that runs all day should earn your trust with facts. Here is everything Bugback keeps, every switch you have, and every place data can go.

What it keeps, and for how long.

The rolling buffer
The last minute of your screen (or the length you choose), picture only. It lives in memory, encrypted with AES-256-GCM under a random key that exists only while Bugback is running. Quit or pause and the key and the footage are gone.
Longer buffers
Past five minutes, the older footage moves to an encrypted temporary file that only that run of Bugback can read. It is deleted when you pause or quit.
A saved clip
A plain MP4 in Movies/Bugback, or the folder you pick, so QuickTime and Jira can open it. Saved clips are not encrypted, because they are yours to share. Delete them like any file.
What you did
Off by default. If you turn it on, a list of your clicks, shortcuts or typing is kept in memory next to the buffer, and wiped when you pause or quit. It goes into a ticket only after you have read it in the review window and removed anything you would rather not share. Keys typed into password fields are never recorded.

What you can switch off.

  • Pause with one click. Nothing is recorded or kept while paused.
  • Record one window instead of a whole screen, and only that app's clicks are listed.
  • Hide apps such as a password manager or chat. They never appear in a clip, and their clicks and keys are never listed.
  • Choose how much of what you do is listed: nothing, clicks, clicks and shortcuts, or everything.
  • Pick the buffer length, from ten seconds to ten minutes. Buffers over 30 seconds are part of Pro.

Where data can go.

Only to Jira, when you connect it or press send, and to Polar, if you buy Pro, to check your licence key. There is no other network traffic: no analytics, no crash reports, no update pings, no account. The licence check sends a key and a short name for your Mac, and never your screen.

auth.atlassian.com and api.atlassian.com
Atlassian's own sign-in and API, to connect your Jira and to look up your projects and tickets.
Your Jira site, yourcompany.atlassian.net
Where the ticket, the video and the notes go when you send them.
api.polar.sh, only with a Pro key
Polar, who sells Pro, checks your licence key when you enter it, when Bugback starts and about once a day. It receives the key, Bugback's organization id and a short name for your Mac made from a random number, and sees your internet address as any website would. The free trial is counted on your Mac and sends nothing.
A small token service
Atlassian will not let a desktop app hold its own secret, so a small service completes the sign-in handshake and renews it. It sees the sign-in codes in transit and keeps nothing. Logging is switched off. It never sees a clip.

Your Jira sign-in is kept in the macOS Keychain. If you connect with an API token instead, that token is kept there too. Disconnecting removes it.

What it asks macOS for.

Screen and system audio recording
To record the screen. Required. Bugback does not record sound.
Input monitoring
Only if you turn on What you did, to see clicks and keys. Declining it changes nothing else.
Notifications
To tell you Bugback is recording a bit longer after a save, or that a clip could not be saved. Optional.

Check it yourself.

Watch Bugback's network traffic with any firewall tool, such as Little Snitch. While it records you should see none, apart from the licence check above if you use a Pro key. Read the full privacy policy, or write to the person who built it.