Our Privacy Philosophy & Local-First Guarantee
MockaScreen records 100% locally on your computer. Your screen pixels, webcam feed, and audio NEVER leave your device unless you explicitly choose to upload and share a link.
At Mocka, privacy is not a checkbox—it is fundamental to our software architecture. We believe software tools should serve creators without surveillance.
When you record with MockaScreen on macOS, ScreenCaptureKit video encoding, system audio mixing, and Apple Metal export rendering happen entirely locally on your Mac. No background streaming to cloud servers.
We make money solely through transparent Pro subscriptions. We do not sell, rent, monetize, or broker your personal information or recordings to advertisers or data brokers.
Information We Collect (and What We NEVER Collect)
We only collect the minimal data required to run your account, deliver shared video streams, and process payments. We never collect background keystrokes or unshared screen contents.
Here is a comprehensive matrix detailing the data we process versus what we strictly never access:
| Data Category | Status | Purpose & Description | Storage / Retention |
|---|---|---|---|
| Account Email & SSO Profile | Collected | Email address and Google/Apple SSO display name/avatar for account login and billing receipts. | Supabase encrypted DB until account deletion. |
| Shared Cloud Videos & Captures | User-Initiated | Only files you deliberately click "Share to Cloud" to generate a public or password-protected link. | Encrypted S3/Cloudflare edge storage; deleted when you delete the video or link expires. |
| Billing & Transaction Details | Processed | Subscription status, invoice history, tier. (Credit card numbers handled directly by Polar / Stripe). | Polar / Stripe PCI-DSS Level 1 vaults. |
| Local Screen Recordings & Exports | Never Collected | Screen pixels, webcam streams, and audio recorded locally that you do not upload. | Stored 100% locally on your own computer drive. |
| Keystrokes & Clipboard Data | Never Collected | We never log background keystrokes, clipboard text, or passwords typed in other applications. | None. |
How We Use Your Information
Data is used strictly to provide the Mocka service: authenticating your login, streaming shared videos, sending billing receipts, and preventing fraud.
We process personal information only for legitimate business purposes under GDPR Article 6 and applicable data protection regulations:
- Service Delivery & Authentication: Delivering passwordless magic OTP codes, verifying Google & Apple OAuth credentials, and managing subscription entitlements.
- Cloud Transcoding & Video Delivery: Converting uploaded videos into adaptive HLS streaming bitrates so viewers with your link can watch smoothly on mobile, tablet, and desktop.
- Transactional Communications: Sending billing invoices, subscription renewal notices, security alerts, and customer support responses.
- Performance & Bug Diagnosis: Aggregated, anonymized performance metrics (via Vercel Web Analytics) to fix crashes, reduce load latency, and optimize video player buffering without tracking individual identities.
Third-Party Service Providers (Subprocessors)
We only work with industry-standard, GDPR-compliant infrastructure providers (Supabase, Polar/Stripe, Cloudflare/AWS, Vercel).
To deliver high availability and secure infrastructure, Mocka relies on carefully vetted third-party subprocessors:
Provides ISO 27001 / SOC 2 Type II certified database hosting and encrypted session authentication.
PCI-DSS Level 1 compliant payment processing for credit cards, Apple Pay, taxes, and invoicing.
Encrypted edge object storage and global content delivery network for fast HLS video playback.
Serverless edge hosting with privacy-preserving, cookie-free web traffic metrics.
Data Security, Encryption & Storage
All data in transit is protected with TLS 1.3 / HTTPS encryption. All cloud media at rest is encrypted with AES-256.
We implement comprehensive technical and organizational security measures to protect your information:
TLS 1.3 In Transit
All API endpoints and video streams are enforced over HTTPS / TLS 1.3.
AES-256 At Rest
Database records and uploaded media files are encrypted at rest with AES-256.
Password Protection
Shared video passcodes use cryptographic salt & hash algorithms.
Your Privacy Rights (GDPR, CCPA/CPRA & International)
Regardless of your location, you have the right to access, export, modify, or permanently delete your personal data at any time.
We honor privacy rights for users worldwide, including the European Union General Data Protection Regulation (GDPR), United Kingdom GDPR, and California Consumer Privacy Act (CCPA/CPRA):
- Right of Access & Portability: You can request a complete export of all personal information and metadata associated with your account.
- Right to Erasure ("Right to be Forgotten"): You can request permanent deletion of your account and all associated shared videos.
- Right to Rectification: You can update inaccurate email or profile details directly from your dashboard or via support.
- Right to Object & Restrict Processing: You can opt out of non-essential communications or restrict processing of specific records.
- No Discrimination: We will never deny services, charge different prices, or provide a lower quality of service for exercising your privacy rights.
To exercise any of these rights, email our Data Protection team at privacy@mocka.studio. We respond to all verified requests within 24 to 48 hours.
Data Retention & Account Deletion
When you delete a video or close your account, it is wiped permanently from our systems within 48 hours with no ghost copies.
We retain personal data only as long as necessary to provide services and comply with statutory financial accounting laws:
- Active Accounts: Maintained for the duration of your active registration.
- Deleted Videos: When you delete a video from your Mocka Cloud library, all cached transcoded files and thumbnails are purged from our edge CDN within 48 hours.
- Account Deletion: Upon account closure, all associated auth credentials and storage records are permanently destroyed.
Children’s Privacy
Mocka is not designed for children under 13. We do not knowingly collect personal information from minors.
Our services are not targeted at or intended for children under 13 years of age (or under 16 within the EEA/UK). If we become aware that a minor under the applicable age threshold has registered without verified parental consent, we will promptly delete the account and associated records.
Contact Our Data Protection Team
For data requests, privacy inquiries, or security reports, email our dedicated privacy team at privacy@mocka.studio.
If you have questions, feedback, or concerns regarding our privacy practices, please contact us directly:
© 2026 Mocka. All rights reserved.
legal@mocka.studio