Privacy & your files
Your videos stay on your device: the repair runs entirely in your browser and we never receive your files. What the anonymous usage stats do and do not record.
Local processing
Section titled “Local processing”rsv.repair runs entirely in your browser. Your .rsv file and output video are read and written on your machine. We do not upload your media to our servers as part of the repair flow. A reference clip, if you provide one, is also processed in your browser and is not uploaded as part of the repair.
Anonymous usage stats
Section titled “Anonymous usage stats”We keep an anonymous count of how often previews and repairs run and whether they succeed, so we know what’s working and which cameras to support next. For each step we record the outcome and how long it took, plus the codec, resolution, frame rate, audio track count, and container format, and the camera model (for example ILME-FX30). We never record the camera serial number, the recording timecode, your file name, your IP address, or any video/audio content. Events for one file are grouped by an anonymous hash of the file (truncated, so it can’t be traced back to the exact file or to you), not by any identifier for you or your device. There are no cookies, and the only thing rsv.repair stores on your device is the language you pick in the switcher. Because these stats are anonymous and aren’t tied to you, there’s nothing to opt in or out of.
If the recovery engine itself crashes in your browser, that one event also sends us a short technical report so the bug can be found: the internal error text and the code location it came from, whether it happened while building the preview or while saving, how much memory the engine had in use, and your file’s extension and size plus your browser version. No file name, no content, and nothing that identifies you.
When you pay for a recovery
Section titled “When you pay for a recovery”Saving a full recovery is paid, and that adds exactly one record on our side: a keyed hash of your file’s first 8 MB, with the Stripe session id, the amount, and the time. That hash is what lets the same file recover again later, on any machine, without an account and without charging you twice. It is stored as an HMAC, so the stored value cannot be used to test whether we have seen a particular file, and it is not the same value the anonymous stats use.
We do not store your name, email, address, card details, or IP against it.
Nothing about the file itself goes to Stripe with the payment: not its name, not its size, and none of what the preview detected about the camera or the footage. The checkout page briefly described the file so you could see which recovery you were paying for; that line is gone for now, and only the keyed hash above travels with the session.
The payment itself is handled by Stripe. Stripe holds the buyer details a payment needs: your name, email and payment details, plus any tax collected. Those live in Stripe’s systems under their privacy policy, and they are visible to us in the Stripe dashboard the way any seller sees their own orders. We do not copy them into rsv.repair, and we do not use them to email you anything you did not ask for. You can ask Stripe to delete your data, which removes it from those records too.
Sharing a sample (optional)
Section titled “Sharing a sample (optional)”If a file can’t be recovered, you may choose to upload a small sample so we can add support for your camera. This is strictly opt-in: nothing is uploaded unless you click the upload button.
When you do, we upload:
- the first 64 MB of your
.rsv— enough to study the file’s structure, and which includes the opening few seconds of footage; - if the recording was an interrupted take you combined with its matching
.MXFhalf, the first 64 MB of that half too (the two halves are one recording, and neither reproduces alone); - if you supplied a reference clip, a small head and tail slice of it (so we capture its codec setup);
- a short details file (file names and sizes, the detected camera/codec/resolution, the error, and an optional email if you leave one).
There is one tick-box next to that upload: send the files in full instead of those slices, which uploads every file the recovery used, whole: your .rsv, the matching .MXF half if you combined an interrupted take, and your reference clip if you supplied one. Some faults only appear late in a long recording, where the first 64 MB shows nothing. It is off by default, it is the same strictly opt-in upload, and you can cancel it while it runs.
We use these samples only to add support for the camera/file variant and to reply to you if you left an email. Don’t upload a sample if your footage is confidential. For removal, contact support@ottomatic.io.
Support chat (optional)
Section titled “Support chat (optional)”If you use Intercom support chat, that service may process messages and technical data under their policies. You can accept or decline chat cookies when prompted.
Trademarks
Section titled “Trademarks”rsv.repair is made by OTTOMATIC and is not affiliated with, endorsed by, or sponsored by Sony. “Sony” and product names such as FX3, FX30, FX6, FX9, FR7, a6700, a7C II, a7S III, a7 V, a7R V, and a7R III are trademarks of Sony Group Corporation, used here only to describe file compatibility.
Questions
Section titled “Questions”For privacy questions, contact support@ottomatic.io.