Fair concern but the risk is similar to any tool you give deep access to like Claude, Codex, or even your operating system
Ultimately, it’s up to you what you run and trust
Screenpipe is open source and local-first
You can inspect it and keep your data on-device, with encryption at rest