Skip to content

Privacy Controls

modelBridge is local-first: your media files, your generated results and your project stay on your machine, and none of them ever go to modelBridge’s own servers. What travels is the work you send to the two services you bring keys for — Anthropic for the agent, fal.ai for generations — plus a short list of things that reach modelBridge itself, chiefly your licence key. This page is the exact list of all three.

Where your video goes (and where it doesn’t)

Section titled “Where your video goes (and where it doesn’t)”

Every editing tool — silence removal, cuts, timeline work — runs on your machine. Two things send imagery, and they are not the same: chatting while a clip is selected sends a few frames of that clip automatically, and visual scan and the Generate tab only run when you ask. The section below separates them, because the difference matters most to the people who most need to know.

FeatureWhere it runs
Silence detection & timeline cleanupYour computer, via ffmpeg
Timeline edits (cuts, ripple, trim)Premiere, on your machine
Timeline scans (offline media, gap detection, LUT consistency, dailies prep)Reads project metadata locally — no media content leaves
Agent chat about editingRuns the edit locally. What goes to Anthropic on your own key: your messages, and the project details the agent reads — timecodes, clip, bin, sequence and project names, file paths, marker comments, effect values. Plus a few frames of the clip you have selected — see below. Your video file itself never goes.
License checks & error reportsNo media. No prompts. No timeline content.

Health Monitor reads source-media metadata locally for its media checks.

The editing work itself never uploads footage. The one thing to know is the frame sampling in the next section — it is tied to having a clip selected, not to running any particular feature.

FeatureWhat it sendsWhen
Agent chat with a clip selected3–12 sampled frames of that clip, to Anthropic (3 for a clip under 5s, 5 under 15s, 8 under a minute, 12 above)Automatically, on every message you send — this one is on by default. Settings → Privacy → “Timeline frames to the agent” turns it off permanently; deselecting the clip stops it for that message
Visual scan (looking inside a clip with Claude)Up to ~100 sampled frames — never the full clipOnly when you explicitly ask Claude to look at footage
Generative AI (Generate tab)Your media, to fal.aiOnly when you use the Generate tab

Visual scan and the Generate tab are opt-in per action, and skipping them does not disable anything else. The frame sampling in the first row is the one thing that is on by default — it is what lets the agent answer “what’s wrong with this shot?” without a separate step. Two ways to stop it: switch off Settings → Privacy → “Timeline frames to the agent”, which is permanent and leaves the rest of the agent working — it still reads your timeline, just never the pictures — or deselect the clip before you chat, which works for as long as you remember to.

A still image behaves differently from video: it is sent whole (downscaled if it is very large) rather than sampled, because there is nothing to sample. An audio clip sends no audio data at all.

Sometimes you want Claude to actually look at your footage — “find shots where the subject is smiling,” “pick the takes with the best lighting.” modelBridge’s visual scan handles that. When you run it, up to a hundred sampled frames go to Anthropic for the scan — never the full video file. Anthropic doesn’t store them. You decide when it runs, on which clips, and with which prompt.

For NDA work, switch off Settings → Privacy → “Timeline frames to the agent” and skip visual scan — those are the two things that send imagery. Every cleanup feature still works; none of them needs to see your footage. Consider turning on NDA mode in the same panel as well (see below). See the NDA editing guide for a full feature-by-feature safety card and a paragraph you can hand to legal.

What reaches modelBridge, and what never does

Section titled “What reaches modelBridge, and what never does”

modelBridge runs no server in the path of your work — your generations go straight from your machine to fal.ai, and your agent conversations straight to Anthropic. But we do operate two small services, and it is fairer to name what they receive than to imply the number is zero.

What reaches us:

  • Your licence key and a device identifier — sent to our licence service when you activate, when it re-validates, and when you release a device. It is how the plugin knows your subscription is active. Retention and deletion →
  • The catalog, news and model insights the panel fetches — ordinary requests carrying only your plugin version and platform.
  • Anything you choose to send: a bug report or feature request (with your message, and your email if you fill it in), and — if you use Mobile Preview — a link to your fal.ai-hosted result plus the model’s name, so your phone can play it. The media itself is never uploaded to us.
  • Opt-in error reports and analytics, if you switch them on. Both are off by default.

What never reaches us, regardless of any setting — it goes to the services you hold keys for, or nowhere at all:

  • Your prompts or negative prompts
  • File paths or file names
  • Your generated media itself — the bytes never leave your machine for us (Mobile Preview sends a link to fal.ai’s copy, not the file)
  • API keys (fal.ai or Anthropic)
  • Project or sequence names
  • Search queries
  • Chat messages (Agent Mode conversations go to Anthropic via your own API key — never through modelBridge servers)
  • Your footage, in any form

Read that list for what it says: it is about us, not about Anthropic and fal.ai. File paths, clip names and project names do travel to Anthropic inside an agent conversation, on your key — that is the section above.

Everything above is controlled from Settings → Privacy. There are six switches; five are off until you turn them on.

SettingDefaultWhat it does
Timeline frames to the agentOnSends 3–12 still frames of the selected clip to Anthropic with each Agent Mode message. Turn it off and the agent still reads your timeline — names, timecodes, settings — but never the pictures. The frames you send yourself, by attaching them, are unaffected
Error reportingOffAnonymous error reports when something unexpected happens. No prompts, no media, no personal data
Usage analyticsOffAnonymous counts of which features get used
Product analyticsOffAnonymous counts of how the plugin is navigated
Share anonymous aggregatesOffContributes your anonymised figures to catalogue-wide aggregates
NDA modeOffFor work under a non-disclosure agreement — see below

Timeline frames to the agent is the only one that is on by default, and it is the only one that sends anything derived from your footage. That is why it is first in the list and first in this page.

Turning on NDA mode switches off Product analytics and Share anonymous aggregates, and stops modelBridge recording anything about your generations on that machine.

It deliberately does not touch three things, because each is a separate decision with its own switch directly above it: Timeline frames to the agent, Error reporting and Usage analytics. If you are working on protected footage, turn the frames switch off yourself — NDA mode will not do it for you.

When something goes wrong during a generation, modelBridge can send a minimal error report to help improve the plugin. This is off by default — you must explicitly enable it in Settings.

  • Error type and source (e.g., “validation error from fal.ai”)
  • HTTP status code
  • A truncated error message (maximum 300 characters)
  • Model ID (which model was involved)
  • Whether the error was retryable
  • Plugin version, host app version, and platform (macOS)

Before any error report is sent, PII is automatically removed:

  • Email addresses
  • URLs and file paths
  • API tokens and keys

Go to Settings in the plugin. The error telemetry toggle controls whether error reports are sent. Turning it off stops all error reporting immediately — no data is queued or sent retroactively.

Separate from error telemetry, modelBridge offers behavioral analytics that track usage patterns — which features you use, how often, and in what order. This is also off by default.

  • Feature usage events (e.g., “opened Dual Mode”, “exported CSV”)
  • Event timestamps
  • An anonymous installation ID (a hash derived from browser signals — not linked to your identity, fal.ai account, or license)
  • Prompt content, file content, or media
  • API keys, license keys, or account identifiers
  • Model outputs or generation results

Toggle behavioral analytics in Settings. When disabled, no events are collected, queued, or transmitted.

If you enable behavioral analytics, modelBridge generates an anonymous installation ID — a 16-character hex string derived from a SHA-256 hash of stable browser signals. This ID:

  • Cannot be traced back to you, your fal.ai account, or your license
  • Is stored locally in your browser’s localStorage
  • Is only transmitted if behavioral analytics is enabled
  • Changes if you clear your browser data

All modelBridge data is stored locally:

DataStorageSurvives updates
Installed modelslocalStorage + disk fileYes
Generation historylocalStorage + disk fileYes
Cost historylocalStorage + disk fileYes
Learned constraintslocalStorage + disk fileYes
Settings & preferenceslocalStorage + disk fileYes
API keysLocal .env file (fal.ai) / localStorage (Anthropic)Yes
License statelocalStorage + disk fileYes

Disk files are stored in a data directory outside the extension folder, so they survive plugin updates and CEP cache clears.

You can request deletion of any data modelBridge holds about you. Since almost all data is local, you control it directly. For server-side data (if you’ve opted into telemetry), email info@modelbridge.app to request deletion, or use the DELETE /api/user-data endpoint documented in the Privacy Policy.

The plugin does not use cookies, does not fingerprint users, and does not share data with third parties beyond fal.ai (for generation) and Anthropic (for Agent Mode, using your own key).