Skip to content

Privacy & your files

Your videos stay on your device: the repair runs entirely in your browser and we never receive your files. What the anonymous usage stats do and do not record.

Local processing

rsv.repair runs entirely in your browser. Your .rsv file and the repaired video are read and written on your machine. We do not upload your media to our servers as part of the repair. A reference clip, if you provide one, is also processed in your browser and is not uploaded as part of the repair.

Anonymous usage stats

We keep an anonymous count of how often previews and repairs run and whether they succeed, so we know what's working and which cameras to support next. For each step we record the outcome and how long it took, plus technical facts about the recording (its codec, resolution, frame rate, frame count, audio tracks, container format, and the size of the repaired file), the camera model, and the country the request came from (the two-letter code our host adds, so we can see where a camera or a failure is common, never a finer location). With each step we also record your browser and operating system family (for example Edge on Windows, never a version), so we can see whether a repair works as well in every browser, and when the preview is shown, whether your browser could play it, because some browsers can't decode some cameras' formats and we need to know which. If you arrived from one of our ads, we record which campaign and ad it was, never anything about you. We also record whether the page could show Stripe's payment form itself or had to open Stripe's page in a new tab, which depends on your browser. If you close the payment with Not now, we record that, and, only if you tap one, which of a few fixed reasons stopped you (such as "too expensive"); nothing you type, because there's nothing to type. We never record the camera serial number, the recording timecode, your file name, your IP address, or any video/audio content. Events for one file are grouped by an anonymous hash of the file (truncated, so it can't be traced back to the exact file or to you), not by any identifier for you or your device. rsv.repair sets no cookies of its own, and the only thing it stores on your device is the language you pick in the switcher (Stripe's, when you pay, are below). Because these stats are anonymous and aren't tied to you, there's nothing to opt in or out of.

If the repair engine itself crashes in your browser, that one event also sends us a short technical report so the bug can be found: the internal error text and the code location it came from, whether it happened while building the preview or while saving, how much memory the engine had in use, and your file's extension and size plus your browser version. No file name, no content, and nothing that identifies you.

Page views

Page views are counted with Cloudflare Web Analytics, which uses no cookies and does not follow you across sites.

When you pay for a recovery

Saving a full recovery is paid, and that adds exactly one record on our side: a keyed hash of your file's first 8 MB, with the Stripe session id, the amount, and the time. That hash is what lets the same file recover again later, on any machine, without an account and without charging you twice. It is stored as an HMAC, so the stored value cannot be used to test whether we have seen a particular file, and it is not the same value the anonymous stats use.

We do not store your name, email, address, card details, or IP against it.

Nothing about the file itself goes to Stripe with the payment: not its name, not its size, and none of what the preview detected about the camera or the footage. Only the keyed hash above travels with the session.

The payment itself is handled by Stripe. Stripe holds the buyer details a payment needs: your name, email and payment details, plus any tax collected. Those live in Stripe's systems under their privacy policy, and they are visible to us in the Stripe dashboard the way any seller sees their own orders. We do not copy them into rsv.repair, and we do not use them to email you anything you did not ask for. You can ask Stripe to delete your data, which removes it from those records too.

In some browsers the payment form sits on this page instead of opening Stripe's own in a new tab. Stripe's script is only loaded when you click to pay, never before, and it then sets Stripe's own cookies (such as __stripe_mid and __stripe_sid) that Stripe needs to process the payment and prevent fraud. They're needed for the payment you asked for, so there's nothing to consent to separately, and they're covered by Stripe's cookie policy. If you never click to pay, Stripe's script never loads.

Sharing a sample (optional)

If a file can't be recovered, you may choose to upload a small sample so we can add support for your camera. This is strictly opt-in: nothing is uploaded unless you press the upload button. There are two versions of this offer, and they send different amounts: the sample below, and the whole-file analysis further down.

When you do, we upload:

  • the first 64 MB of your .rsv: enough to study the file's structure, and it includes the opening few seconds of footage;
  • if the recording was an interrupted take you combined with its matching .MXF half, the first 64 MB of that half too (the two halves are one recording, and neither reproduces alone);
  • if you supplied a reference clip, a small head and tail slice of it (so we capture its codec setup);
  • a short details file (file names and sizes, the detected camera/codec/resolution, the error, and an optional email if you leave one).

There is one tick-box next to that upload: send the files in full instead of those slices, which uploads every file the recovery used, whole: your .rsv, the matching .MXF half if you combined an interrupted take, and your reference clip if you supplied one. Some faults only appear late in a long recording, where the first 64 MB shows nothing. It is off by default, it is the same strictly opt-in upload, and you can cancel it while it runs.

Sending a file we couldn't read

Some files aren't recordings we can read yet, and some look complete to us while you can see that they're broken. We can't repair either one today, so instead of turning you away we offer to study the file: the formats we don't support yet get built from exactly these. It is the same strictly opt-in upload: nothing leaves your machine until you press the button, and we never offer you a recovery we can't deliver.

This offer differs from the sample above in three ways:

  • it sends the file whole, always, with no slice option and no tick-box. We don't know the format yet, so we can't know which part of it matters, and a slice we can't rebuild from is one we'd have to ask you for twice;
  • the file need not be a .rsv. It is whatever you dropped: an MP4, a MOV, or a format we don't recognise at all. If you add a reference clip that recorded correctly, that goes whole too;
  • it includes a short description you write yourself, saying what's wrong with the file. On a file we couldn't read, or one that looks fine to us, that sentence is the only account of the fault we have. It is free text, so please don't put anything in it you wouldn't want us to read.

An email is required here, because this is a help request rather than a background donation, and we use it to tell you what we found.

We use these uploads only to add support for the camera or file variant and to reply to you if you left an email. When one arrives, a notice with the file's name, the details above and your email (if you left one) goes to our team's chat so that someone looks at it. Uploaded files are deleted after 7 days, unless we are still working on your case or keep the file to add support for your camera. Don't upload a sample if your footage is confidential. For removal, contact support@ottomatic.io.

Leaving a note (optional)

After a repair you can leave a note for others. It is read by a person before it appears on the site, and it is shown with the clip's length, size, camera model and codec, and the name you give, if any.

Live support sessions

When a file won't recover and the reason isn't in its first 64 MB, we may send you a link that opens a live support session instead of asking you to upload the whole file. It is only ever offered by a person you are already talking to, and nothing happens until you press Start.

While the session runs, your browser tab keeps the file open and answers our requests for specific parts of it. Two kinds of request exist:

  • a read of a byte range, which sends exactly those bytes to us;
  • a check that runs in your tab, such as finding which regions of the file are empty, where a byte pattern occurs, or running our recovery over the file to see where it stops. Only the answer is sent, not the footage it was computed from, and such a run saves nothing: no recovered file is written, on your computer or anywhere else.

The tab shows a running count of the parts read and the amount sent, so you can see what has left your machine. We cannot change, move or delete the file: the browser gives the page read access to the file you chose and nothing else on your computer.

The bytes we read pass through our server on their way to us and are not stored there. What the server keeps for the session is the file's name and size, your country as Cloudflare reports it, the read counters, and the answers to the checks, and it deletes all of it an hour after the session ends. We may keep the parts we read for as long as we are working on your case, under the same terms as a sample above.

A session ends when you press Stop or close the tab, and ends by itself after six hours. The parts we read can include footage, so don't start one if your footage is confidential.

Support chat (optional)

If you use Intercom support chat, that service may process messages and technical data under their policies. It loads only after you agree to it, and you can withdraw that at any time from the chat button.

Trademarks

rsv.repair is made by OTTOMATIC and is not affiliated with, endorsed by, or sponsored by Sony. "Sony" and product names such as FX3, FX30, FX6, FX9, FR7, a6700, a7C II, a7S III, a7 V, a7R V, and a7R III are trademarks of Sony Group Corporation, used here only to describe file compatibility.

Questions

rsv.repair is run by OTTOMATIC GmbH; our address is in the footer. For privacy questions, contact support@ottomatic.io.