Fair concern but the risk is similar to any tool you give deep access to like Claude, Codex, or even your operating system

Ultimately, it’s up to you what you run and trust

Screenpipe is open source and local-first

You can inspect it and keep your data on-device, with encryption at rest

> Screenpipe is open source and local-first

Source available *

Until some rogue agent decides that it looks pretty useful because there’s a ton of it and uploads it to Claude or Codex.

and what endpoint would it use to upload those files? what's the authentication needed for those endpoints? why would everyone on earth fail to notice these exfiltration endpoints if they exist?

you're being unnecessarily hostile about a threat that almost certainly doesn't exist. And if it does, you can absolutely block those uploads before they even happen. In fact if you don't already block uploads to hosts you don't know about, then you're not really taking anything seriously, are you?