I wanted to include my app’s purchase flow in a demo video, so I screen-recorded it on a real device.
When the billing sheet comes up, Google shows a “Choose an account” dialog. Listed there were my real name and address, plus the 3 accounts I keep separate for running my apps.
吉田圭一郎 0512yoshikei@gmail.com
narabuappinfo1@gmail.com
kirokuappinfo1@gmail.com
nemuruappinfo@gmail.com
All 4, fully visible.
Why it’s easy to miss
While recording, you’re looking at the app. “The paywall showed up,” “the plan comparison appeared,” “it went to the purchase sheet” — what you’re checking is UI you built yourself.
What sneaks into the frame is UI you didn’t build. OS dialogs, notifications, keyboard suggestions, the status bar. They’re outside the focus of the recording, so your eyes slide right past them.
On top of that, this dialog always appears in the purchase flow. It’s not an accident; it’s the display working exactly as designed.
How I blacked it out
I overlaid a rectangle with ffmpeg on the 4 affected raw clips.
ffmpeg -i scene5_purchase_raw.mp4 \
-vf "drawbox=x=40:y=595:w=640:h=500:color=black:t=fill" \
-c:a copy out.mp4
In the 720x1600 footage, the account list area was x=40, y=595, w=640, h=500.
I left the dialog’s title, logo, and the consent text in the footer as they were. None of that contains personal information, and blacking out everything makes it look like “a video that’s hiding something,” which is actually more unnatural. Hide exactly what needs hiding, no more and no less.
I overwrote the original files with the processed ones. That way I don’t keep the pre-redaction footage around. If I kept it, the next time I went digging through my clips I’d accidentally grab the original.
What I couldn’t take back
This is the real point of this post.
Of those 4 clips, I’d already shared 2 before I blacked them out. Someone asked to review the footage, so I sent it as-is.
Once you’ve sent a file over chat or email, you can’t go back and fix it. No matter how clean I make things on my end, the pre-redaction file stays wherever I sent it.
All I could do was pass along a note: “If you forward or share these anywhere else, please use the latest redacted files, not the old ones I already sent.”
Publishing isn’t the only way information leaks. Sharing something for review was the path I was least on guard about.
A technical limit I discovered along the way
This recording session taught me one more thing.
With a build sideloaded over USB debugging, you can’t reach Google Play’s real purchase confirmation sheet. I tried 3 times, and every time it stopped at the account selection dialog.
If you want to record the real purchase sheet, you need a proper install, for example through the internal testing track.
In the end, I built that scene of the demo video out of “paywall → plan comparison → account selection (blacked out).” I should have checked the limits of the install path before burning time trying to record something that couldn’t be recorded.
What I decided
I added 3 lines to my recording checklist.
- Before recording, check the account’s display name (if your real name shows up, change it first)
- After recording, do one pass looking only at UI you didn’t build
- Black things out before sharing. No exceptions, even for sharing raw footage
The third is the most important. “I’ll fix it later when I make the public version” assumes there won’t be another chance to share it before it’s published, and that assumption breaks easily.
The other landmines I hit in the same recording session (test ads, IME conversion mistakes, footage that changes resolution partway through) are in how I made a 30-second video with nothing but ffmpeg, and the story of two sessions fighting over the same device is here.