Privacy policy

Last updated: [DATE]

This policy explains what personal data [COMPANY NAME] ("we") collects when you visit this website, join the waitlist or use SafeRewind, and what we do with it. We are the controller of this data. Questions go to [PRIVACY EMAIL].

The short version

  • We never receive your recordings or reports. The extension records, reviews and builds reports on your computer. They go only where you send them.
  • We collect what we need to run accounts, licenses and billing, and to answer you. We don't sell it.
  • This website uses no advertising or tracking cookies.

The extension and your reports

On the sites you allow, the extension keeps the last 30 seconds of a tab in your computer's memory: the video, the steps taken, console messages and network requests. Passwords, card numbers and one-time codes are never read, and login headers, cookies and tokens are removed as they're recorded. When you press Save, this becomes a report that you can review, edit and download.

None of this is sent to us. The extension contacts our server for your license and, if your organisation set up ticket destinations, to get ready to send a report. In exactly these ways:

  • Signing in. The extension opens our website in a window, where you sign in. The website then hands the extension a one-time code, which the extension sends back to us once to get its own sign-in key.
  • Renewing the license, about once a day. The extension sends its sign-in key. We answer with your license: your name and email address, your organisation, its plan, and when the license ends.
  • Signing out. The extension sends its sign-in key so we can delete it.
  • Listing destinations. When a report opens for review, the extension sends its sign-in key. We answer with the names of the places your organisation's admin set up (a GitHub repository, a Linear team or a Jira project).
  • Sending a report. When you press "Send to …", the extension sends its sign-in key and the destination you picked. We answer with a key for that tracker that works for a short time, and your name. The extension then sends the report, its title and text straight to GitHub, Linear or Jira. The report never passes through our server.

For each browser you sign in from, we keep the browser's name and version (from its user agent), when you signed in and when its license was last renewed, so you can see your signed-in browsers and sign one out. The extension's security settings let it contact no other server than ours and the trackers' (GitHub, Linear and Atlassian, only when you press Send), and we check that every time we build it.

A report can contain personal data that was on screen. Your organisation decides what is recorded and who gets a report, so for that data your organisation is the controller, and we have no access to it.

What we collect, and why

Waitlist

Your email address, and if you give them, your company name and team size. We use them to invite you to a trial and to tell you about SafeRewind's launch. Legal basis: your consent, which you can withdraw at any time by emailing us.

Accounts

Your name, email address, password (stored only as a one-way hash), organisation, role and seat, the browsers you're signed in from, and sign-in records (time, IP address and browser, also used to slow down password guessing). If you sign in with Google or GitHub, we receive your name, email address and profile picture from them. We use this data to provide the service and the license check. Legal basis: performing our contract with your organisation.

Connected trackers

When an admin connects GitHub, Linear or Jira, we store the tracker's keys (encrypted), the account or workspace name, who connected it, and the destinations they add. We use them only to give your organisation's extensions short-lived keys for sending reports. Legal basis: performing our contract with your organisation.

Billing

Paddle, our reseller and merchant of record, collects payment details and billing addresses under its own privacy policy. We receive your plan, seat count, invoices and subscription status, but never your card details. Legal basis: contract, and our legal duty to keep financial records.

Website visits

Our hosting provider records technical data such as IP address, browser and pages requested, to deliver the site and keep it secure. Legal basis: our legitimate interest in running a secure website. The site stores your light or dark mode choice in your browser; that's not sent to us.

Emails with us

What you write to us and our replies, to help you. Legal basis: legitimate interest, or contract if you're a customer.

Who processes data for us

  • Netlify: website hosting and waitlist form submissions.
  • Neon: the account database, hosted in the EU.
  • Paddle: checkout, payments, invoices and sales tax.
  • Resend: sending account and invitation emails.
  • Google and GitHub: only if you choose to sign in with them.
  • GitHub, Linear and Atlassian: only if your organisation connects them; reports you send go to them under your organisation's own agreement with them.

Account data is stored in the European Union. Where a provider handles data outside the EU or UK, it's covered by the European Commission's standard contractual clauses or an equivalent safeguard.

How long we keep it

  • Waitlist entries: until you're invited and decide not to sign up, or until you ask us to delete them, and at most 2 years.
  • Account data: while your organisation's account is open, and up to 90 days after it closes.
  • A signed-in browser's record: until you sign it out, from the extension or the website.
  • A connected tracker's keys: until an admin disconnects it, or the organisation's account data is deleted.
  • Billing records: as long as tax law requires, usually up to 10 years.
  • Hosting logs: up to 30 days.

Your rights

You can ask us for a copy of your data, to correct or delete it, to limit or object to how we use it, or to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. Email [PRIVACY EMAIL] and we'll answer within a month. You can also complain to your data protection authority.

Changes

We'll update this page when what we collect changes, and email account admins about changes that matter. The date at the top shows the latest version.

Contact

[COMPANY NAME], [REGISTERED ADDRESS], [COUNTRY]. Email: [PRIVACY EMAIL].