Last updated July 30, 2026
Privacy
Handback stores recordings of your screen and your voice. This page says exactly what we keep, where it lives, who can reach it, and how to get rid of it.
Who this covers
Handback is operated by Sal Aiello. This policy covers the Handback web app at handback.dev, the Handback Recorder Chrome extension, and the command-line and MCP tools that talk to the same API. Handback is a workspace for teams: almost everything you put into it is visible to the other members of your organization, by design.
What we collect
- Account
- Your email address, your name if you give one, and a hash of your password — never the password itself. Sessions are cookies issued by our own server.
- Organization
- The organizations you create or join, your role in each, and invitations you send or accept.
- Gripes
- The substance of the product. A gripe holds the screen recording video, the keyframe images cut from it, your microphone audio, the machine transcript, and the report generated from them.
- Recording context
- While you record, the extension also captures the URLs and page titles you visit, console and network errors the page produces, and the marks and drawings you make. This is the evidence that makes a gripe useful to an agent — and it can include anything visible in those pages.
- API tokens
- Only a SHA-256 hash of each token, plus when it was last used. The token itself is shown once at creation and never stored.
- Server logs
- Ordinary web request logs — method, path, status, timing. Our hosting provider records connection metadata such as IP addresses as part of running the service.
What we don't do
There are no analytics scripts, advertising tags, or third-party trackers on this site — you can check the page source. We do not sell your data, we do not share it with anyone outside the processors named below, and we do not use your recordings, transcripts, or reports to train AI models.
Where it lives
Files are stored in a private Amazon S3 bucket in the US West (Oregon) region. The bucket blocks all public access; nothing in it is reachable by URL. When you or an authorized agent needs a file, our server issues a presigned link that expires in an hour. Everything else — accounts, organizations, gripe metadata — lives in a PostgreSQL database on our own server in the same region. All traffic runs over HTTPS.
Who can see it
Members of the organization a gripe belongs to, and anyone holding a valid API token issued by that organization. Nobody else — the tenant boundary is enforced on every request, not just in the interface.
Invitation links are the exception worth understanding: the link is the credential. Anyone who has it can join your organization and read its gripes until it expires after seven days. Send them the way you would send a password.
Sal Aiello, as the operator, can technically reach stored data in the course of running and debugging the service. It is not read routinely and it is never shared.
Transcription
Your narration is transcribed one of two ways, and you choose which in the extension's settings:
- On your device
- A speech model runs inside your own browser. Your audio is never sent anywhere for transcription — it stays on your machine.
- By our provider
- The audio track is sent to Groq, which returns a timed transcript. Groq processes it to produce that transcript and for no other purpose.
Either way, the recording itself — video, keyframes, audio — is stored in our S3 bucket as described above.
Processors
- Amazon Web Services
- Hosting, file storage, and the database. US West (Oregon).
- Groq
- Speech-to-text, only when server-side transcription is enabled. Receives the audio track; receives nothing else.
That is the whole list. If it changes, this page changes with it, in the same release as the change itself.
How long we keep it
Gripes are kept until someone deletes them. Deleting a gripe removes its database records and its entire folder of files from S3. Re-recording under the same name replaces the old gripe wholesale — the previous files are deleted, not versioned. Account records persist until the account is deleted.
Deleting your account is not yet a button in the product. Email sal@dested.com and it will be done by hand, along with everything belonging to it.
Your rights
Ask and you will get: a copy of what we hold about you, correction of anything wrong, or deletion of all of it. Depending on where you live you may have these rights by law; we apply them to everyone regardless. One email to sal@dested.com is the whole process.
Children
Handback is a tool for software teams and is not directed at children. Do not create an account if you are under 16.
Changes
When this policy changes, the date at the top of this page changes. If a change materially affects what happens to data you have already stored — a new processor, a new category of collection — you will be told directly, not just quietly re-dated.