Reference

Data and privacy

Reviews live in your project folder. App settings live in the OS user-data folder. Only crash reports reach the developer, through Sentry, and you can turn them off.

#Inside .ade-movie/reviews/

<project>/.ade-movie/reviews/20261003-104500/
├── feedback.md      # what the agent reads
├── 01.png, 02.png…  # one or more images per finding
├── session.json     # review state and edit history
├── events.jsonl     # action log (built-in browser only)
├── recording.webm   # the video
└── work/            # intermediate audio and frames

When recording starts, .ade-movie/ is appended to .git/info/exclude. Worktrees and submodules are handled. .gitignore is never modified. An interrupted review can be recovered from history if its records survived. The app then warns that the last seconds may be missing.

#Retention

Keep recordings (7 days by default, 30 days, or Forever): on startup, completed reviews older than that lose recording.webm and work/. feedback.md and the finding images are kept. Incomplete reviews are never pruned. Pruning runs at launch, for the last opened project.

#What leaves your machine

WhenDestinationData
Transcription: On device (free)none—
Transcription: OpenAI / compatibleOpenAI or your Base URLaudio chunks
Model downloadHugging Facefile request
Organizeyour Claude Code / Codex CLItext and action log only (no images, audio, or video)
Send to Agentthe agent in your terminalone instruction pointing at feedback.md
Send to GitHubGitHub via ghbody text only (no images)
Footer usageAnthropic, ChatGPTusage request with your own login
Check for Updates (manual)download server (Cloudflare R2)request for latest.json
A crash or error (installed app, Send crash reports on)Sentrystack trace and OS / CPU / app versions (see Crash reports)
  • No analytics or usage tracking. Crash reports are the only thing sent without you asking, and you can turn them off.
  • Secret-looking values in URLs (tokens, keys) are redacted before they are written to feedback.md.
  • Text captured from the page is marked as data in feedback.md, so the agent is told not to follow instructions found in it.

#Crash reports

When the installed app crashes or hits an unhandled error, MOVIE-ADE sends a crash report to Sentry so the bug can be fixed. It is on by default. Turn it off in Settings → Privacy → Send crash reports, or with Turn off on the notice shown at first launch. Turning it off takes effect at once. Turning it back on takes effect at the next launch. Development builds (pnpm dev) and E2E runs never send.

SentNot sent
  • Error type and message, with home-folder paths shown as ~
  • Stack trace (where in MOVIE-ADE's code it happened)
  • For native crashes: the minidump (thread stacks of the crashed process)
  • OS name and version, CPU architecture, Electron / Chrome / Node versions, app version, screen size, memory size
  • App lifecycle events right before the error (for example app.ready)
  • Your project folder path and file names (replaced with <project>)
  • URLs opened in the built-in browser, and any other web address (replaced with <url>)
  • Terminal output, transcripts, findings, page text, screenshots
  • Email addresses and API keys or tokens (replaced)
  • Your name, device name, IP address (not stored), cookies, local variables
  • Clicks, console logs, network requests

At most 10 reports are sent per launch, the same error only once, and only half of JavaScript errors (native crashes are always sent). No performance tracing or session replay is used. The app uses Sentry's free plan. If it fills up, extra reports are dropped and nobody is charged.

Building MOVIE-ADE yourself? Set MOVIE_ADE_SENTRY_DSN to your own Sentry DSN, or to an empty string to send nothing. The code is in src/main/telemetry.ts and src/shared/telemetry.ts.

Edit this page on GitHub