ClipFactory runs locally and talks only to the AI providers you configure. Still, it stores provider API keys (.env) and processes files you upload.
Please do not open a public issue for security problems. Use GitHub's private vulnerability reporting on this repository, or DM the maintainer on X/Twitter: @feyzili. Include steps to reproduce and the affected version/commit. We aim to acknowledge within 72 hours.
- Keys come from the Setup page (stored in the
app_settingstable of the local Postgres volume, plain text) or from.env; they are never logged and the UI only shows the last 4 characters. Anyone with access to the database volume or the API port can read them — keep both local. - The API has no authentication — it is meant to run on your machine/LAN. Do not expose ports 8000/3000 to the internet without a reverse proxy with auth.
- Uploaded clips and generated media stay under
assets/andstorage/; sampled frames/images are sent to the AI providers only for the features you trigger (AI autocomplete, AI Lab). - Dependencies: Python via
backend/requirements.lock.txt, Node viafrontend/package-lock.json.