According to the website, it sends the keystrokes to an API endpoint in the internet. While nice, I‘d be concerned about the security implications of using this tool. I mean it could also „accidentally“ be sending env variables etc.?
I think it only records the terminal output(along with other metadata like timing) and not what you type(input). If you enter a password in a prompt that does not echo/display it back, it shouldn't be recorded.