Last updated: 24 September 2026.
Privacy contact: privacy@screenrec.com.
ScreenRec's desktop features can process screenshots, screen recordings, system audio, microphone audio and camera images that you select or enable. These can contain information about you and other people. The application also uses account, licensing, application and technical information needed for enabled features. Operating-system permissions control the access they describe; granting a system permission is not consent to unrelated marketing.
When Instant Share Link is enabled, ScreenRec automatically uploads your recorded videos to our servers to provide a shareable link. Screenshots are uploaded when you click Share. Local recordings and cloud copies are separate; uninstalling does not automatically close an account or erase cloud files. Review your active account, capture inputs and sharing controls. If your account joins a company space, company account-holder impersonation can expose pre-existing content, as explained in P4 below.
TeddySoft OOD, company number 203070568, VAT BG203070568, 91 Bul. Hristo Botev Street, Plovdiv 4000, Bulgaria, provides the brand identified at the beginning of this notice. Headquarters and contracting seat are in Bulgaria. Contact its privacy team using the email above. This notice covers our website, accounts, panel, customer support and Services, including viewers and other people whose information is processed through enabled features. It explains processing; reading it or accepting service terms is not consent to optional tracking, marketing or every use of personal data.
We act as controller when we determine why and how information is used for purposes such as administering our customer relationship, billing, our website, security and our own lawful marketing. An organization normally controls its personnel's use of its account and its decisions to record or publish their information.
For personal data in Content, viewer forms and customer-directed analytics that we process on a customer's instructions, we generally act as processor, or subprocessor where the customer acts for another controller. That processing is governed by the DPA and customer instructions. The customer's privacy notice explains its purposes and legal grounds. We remain controller for any separate purpose we actually determine; our roles depend on the processing, not merely its label. A viewer can contact the publisher first about publisher-controlled data, or contact us for help identifying the responsible customer.
Depending on your relationship with us and the features used, relevant information includes:
| Category | Examples and sources |
| Account and organization | Name, email, login and authentication information, organization, membership, role, settings, invitations and subscription details supplied by you, your organization or an authorized identity provider. |
| Transactions | Billing identity and address, tax information, plan, invoices, payment references, payment status and processor-provided information. The payment provider collects payment details through its payment flow. |
| Customer Content | Video, screenshots, audio, streams, uploaded files, text, captions, transcripts, comments and metadata provided by you or your organization, including personal information about people recorded or depicted. |
| Viewer and publishing data | IP address, browser/device and connection information, video identifiers, playback events, timestamps and viewing activity; and names, contact details, form responses or transaction information where a publisher enables forms, registrations or monetization. |
| Technical and usage information | Requests, service events, diagnostics, error reports, device/application/OS versions, approximate location derived from IP address, licensing and usage information, and cookie or similar identifiers where used. |
| Communications | Support requests, attachments, feedback and correspondence you send, and information necessary to respond. Do not include sensitive content unless necessary for the request. |
| Website, marketing and integrations | Website interactions and preferences, information provided when requesting material or communications, permitted partner/referral information, and data exchanged through integrations you authorize. |
Not every category is collected from every person. We do not treat precise geolocation, microphone access, session replay or full payment-card storage as enabled merely by listing a broad data category.
For processing subject to the GDPR where we are controller:
| Purpose | Information used | Legal ground |
| Create and operate an individual customer's account, provide purchased features and support | Account, transaction, Content and technical data necessary for the request | Performance of our contract with that individual, or steps requested before contracting. |
| Administer an organization's customer relationship and communicate with its representatives | Business contact, role, membership and account activity | Legitimate interests in providing and administering business services; the organization is the contracting party. |
| Billing, accounting and required records | Transaction, identity and tax information | Contract where relevant and compliance with applicable accounting/tax obligations. |
| Protect accounts, prevent fraud and abuse, investigate faults and defend claims | Necessary account, technical, transaction, communication and incident records | Legitimate interests in secure and reliable services and protecting legal rights; legal obligation for processing a specific law requires. |
| Improve service operation using proportionate diagnostics and usage analysis | Technical events and usage information limited to what is necessary | Legitimate interests after balancing individual rights; consent where device access or the particular processing requires it. This is not permission to reuse customer-controlled Content for unrelated purposes. |
| Send our marketing communications | Contact information and preferences | Consent where required, or an applicable lawful existing-customer marketing basis with an easy opt-out. |
| Optional advertising, tracking or analytics requiring consent | Disclosed identifiers and interaction data | Consent, where required before the relevant tracking. |
| Respond to privacy-rights requests, contract withdrawals and binding legal requirements | Information necessary to identify the person/contract, record and acknowledge the request or withdrawal, respond and comply | Compliance with applicable legal obligations. |
If a purpose uses a legitimate interest, we consider necessity, reasonable expectations and effects on individuals, and do not proceed where their rights override it. You can request further information about the relevant assessment. For data processed on a customer's behalf, the customer determines the legal grounds; the DPA supplies processing instructions, not a new legal basis for the customer.
Required account and transaction fields are needed to supply the relevant Service or meet legal obligations. If you do not provide them, we may be unable to create the account, process the purchase or resolve the request. Optional marketing choices do not determine access to unrelated purchased functionality.
When you accept membership of an organization space that provides impersonation, its company account holder can enter and operate your individual account through that function, without your separate approval for each session or action. Depending on the available functions, this includes viewing, downloading, sharing, modifying and deleting Content, including content already stored in your account before joining. A private-content label does not prevent that access.
The organization is responsible for its purpose and legal grounds for using it and for required personnel notices. Ending membership ends the authority described in the Terms, but does not recall copies already downloaded or undo actions already taken. Contact the organization about its use of your information and us about our processing. Membership does not waive data-protection rights or transfer Content ownership.
We disclose information only for the purposes and on the grounds described in this notice, including to:
Any marketing-partner disclosure, advertising sharing or other use qualifying as a “sale” or “sharing” under applicable privacy law must be specifically identified with the required choices. We do not equate not charging money with not selling or sharing under every privacy law.
Hosting, support and delivery may involve more than one country. A provider's headquarters address is not a complete description of where it processes data.
Where a restricted international transfer occurs, we use the legally applicable mechanism, such as a relevant adequacy decision or properly completed standard contractual clauses with necessary supplementary measures. The EU–US Data Privacy Framework is relevant only for an eligible recipient with current certification covering the transfer. We do not claim that TeddySoft OOD is US-certified or rely on the former Privacy Shield adequacy decision. A person's use of the Services is not blanket consent to international transfers.
You may request information about safeguards and a copy where applicable; we may redact unrelated confidential information. UK or Swiss transfers require the safeguards applicable to that transfer rather than an assumption that EU wording alone is sufficient.
We retain personal information only for the relevant purpose and applicable period. Retention considers contractual supply, customer instructions, applicable legal recordkeeping, proportionate security needs and particular disputes; “business purposes” is not an indefinite retention period.
Customer-controlled Content follows the DPA, customer instructions and the Terms' retention and export provisions. Renewal cancellation is not necessarily account closure or immediate erasure. An authorized member or organization account holder can instruct Content deletion within available permissions. Switching rights can require a separate retrieval period and complete erasure; ordinary backup cycles cannot defeat those obligations.
Legal holds must be purpose-specific, access-restricted and reviewed. Pseudonymized information remains personal data where someone can reasonably be identified; it is not retained indefinitely as if anonymous. Genuinely anonymous statistics that no longer identify a person may be kept without a personal-data retention period.
Service backups are not a promise to restore a deleted file. Keep independent copies of important material. That advice does not reduce our legal obligations or your rights.
If used storage exceeds the allowance under the service plan, some or all media items may be selected for deletion as necessary to bring usage within the allowance. The user has a 14-day grace period to resolve the excess. Email notifications will be sent during that period, on a three-email schedule that includes a final reminder before the deadline. If the excess remains unresolved after the grace period, the selected content will be permanently deleted. Longer periods promised in an existing agreement or notice, and mandatory retrieval or switching rights, remain. We do not guarantee that reminder emails will reach the inbox or be read.
We apply appropriate technical and organizational measures based on the nature and risks of processing and our legal and contractual duties. We do not promise absolute security, uninterrupted service or a certification not actually held. We investigate incidents and notify customers, authorities and individuals when applicable law requires, using the role and threshold relevant to the incident. Reporting an incident to a customer is not postponed solely until every fact is known.
Depending on applicable law and our role, you can request access, correction, deletion, restriction and portability of your personal data; object to processing based on legitimate interests; object to direct marketing; and withdraw consent without affecting processing lawfully performed before withdrawal. Withdrawal concerns the processing relying on consent; we do not retrospectively replace consent with another basis to defeat it.
Contact the privacy team using the email above. We may request proportionate information to verify identity and protect other people. For GDPR requests, we respond without undue delay and ordinarily within one month. Where legally permitted because of complexity or number of requests, an extension of up to two further months may apply; we notify you within the first month and explain why. Requests are ordinarily free, subject to legally permitted exceptions. We explain any refusal and available redress.
Where we act as processor, we forward or help route the request to the responsible customer and assist it under the DPA; we still address any part relating to our own controller processing. Account exports and statutory personal-data portability are distinct from the cloud-switching process.
You can download individual media items and export statistics from tables that provide an export option. That is the current self-service capability; it is not a full-account export of all metadata or configuration.
Switching, assisted data-export and illegal-content reports can be made through the Contact Us page or live chat. Existing confirmed email reporting contacts remain available.
You may complain to the Bulgarian Commission for Personal Data Protection or another competent supervisory authority, including in the country of your habitual residence or workplace where applicable. You do not have to contact us first. Applicable court remedies are unaffected.
Unsubscribe from marketing using the message's link or the privacy contact. Necessary account, transaction and security messages may continue.
Where you enable transcription or AI features, inputs and generated results are processed for that feature under the Terms and DPA. Dictation audio is sent to our servers and processed using Speechmatics. We also use Speechmatics to transcribe on-demand video. For AI metadata generation, transcripts are processed using OpenAI to generate titles, short and long descriptions, and chapters.
Where the Services receive data through Google APIs, our use and transfer of that data will comply with the Google API Services User Data Policy, including its Limited Use requirements where applicable. General organization access or Content permissions do not authorize uses prohibited by those API requirements.
Subscriber accounts are intended for adults. Customer-published videos can nevertheless depict or be viewed by children. Customers must establish lawful notices, permissions and protections for their audiences; an adult-only subscriber rule does not make children's data disappear from the service.
Contact privacy support if you believe we are processing a child's data unlawfully. Customers intending child-directed publishing, sensitive personal-data processing or regulated workloads must assess suitability and the required safeguards and agreements before using those functions. We do not claim that ordinary subscription terms supply parental consent, a healthcare agreement or another special regulatory authorization.
We update this notice when our practices or legal requirements change, identify the revision date and give additional notice where required. A new notice is not retroactive consent. Where a change requires permission, we obtain it before starting the relevant processing. Material changes to the contractual Services follow the Terms; a privacy edit alone does not amend the commercial agreement.
We use this term to include cookies, local storage, pixels, SDK identifiers and similar device-access technologies. Some are needed for functions you request, such as login, security, load balancing or recording your privacy choices. Others support preferences, analytics, advertising or measurement. Classification depends on their actual purpose; analytics or advertising is not “necessary” merely because useful to our business.
Browser settings can block or delete cookies, but that may affect functions that require necessary cookies and does not create a consent choice that our sites currently collect. Third-party opt-out websites do not replace a consent interface where consent is required.
Embedded players and customer websites can have different controllers and choices. A publisher is responsible for its site and its configured tracking, while we remain responsible for our own technology and disclosures.
The service-subprocessor list is in DPA Annex 2.
The following providers are used for TeddySoft OOD's own controller purposes and are not listed as subprocessors:
| Vendor | Description of Services | Entity Location(s) |
| Google Analytics | User activity tracking | Global |
| Intercom | Customer Relationship Manager | USA |
| Sentry.io | Application error tracking and monitoring | USA |
| Status.io | System Status communications | USA |
Previous versions. Privacy published before 24 September 2026. Previous version — may still apply to existing customers.