Draft — not legal advice, and not yet reviewed by legal counsel.
This document was written by the people who built the product, to describe what the software actually does. It has not been reviewed by a lawyer, and it must be before it is relied on by anyone. Every [HIGHLIGHTED VALUE] below is a blank the operator must still fill in.
1. Two very different kinds of data
This service handles two categories of personal data and our role differs between them. Confusing the two is the most common mistake in policies like this one, so we separate them explicitly:
- Account data — we are the controller
- The data about you as our customer: your name and email, your organisation, your plan and billing records, your usage of the platform, your support messages.
- Captured site content — we are your processor
- The screenshots, console output and page metadata we capture from the websites you configure. If those pages display personal data, you decide that, not us. You are the controller and we process it on your instructions under our Data Processing Agreement.
2. Who the controller is, and how to reach us
For account data, the controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (registration [COMPANY REGISTRATION NUMBER], VAT [VAT NUMBER]).
Privacy contact: [PRIVACY EMAIL]. Security reports: [SECURITY EMAIL]. We have not appointed a data protection officer; the privacy address reaches the people who can actually act on your request.
3. What we collect about you
- Account — email address, display name, hashed password, the organisation you belong to and your role in it, email-verification status.
- Billing — plan, subscription status, invoice records, billing name, address and VAT number, and the identifiers our payment processor gives us. We never receive or store your card number.
- Usage — which jobs ran, how many screenshots and AI analyses were consumed, API requests and rate-limit counters. This is what enforces your plan limits and produces your usage page.
- Audit and security logs — significant actions taken in your organisation (who invited whom, who changed a subscription, who created an API key), with timestamps and the IP address the action came from.
- Email logs — a record that a transactional message was attempted and whether it succeeded, so that a lost verification email can be diagnosed.
- Support correspondence — what you send us and what we reply.
- Server logs — standard web-server request logs including IP address and user agent.
We do not run advertising or third-party analytics on this website, and we do not build profiles or sell data to anyone. Ever.
4. What we capture from your websites
On your instruction, and only for the sites and URLs you configure, we capture:
- rendered screenshot images of the pages, at the viewport widths you choose;
- the URLs, page titles and timing metadata of those pages;
- browser console messages and failed network requests observed during the load;
- generated difference images comparing one render with another.
A screenshot of a live page can contain personal data — a staff directory, a testimonial, a name in a logged-in header. You control which pages we fetch and with which credentials, so you control that exposure. If you must not capture a page, do not add it; if a page must be captured logged-out, do not give the environment credentials.
Credentials you give us for an environment (HTTP authentication, proxy credentials) are stored to make the fetch possible. They are write-only in the interface, are never returned in plaintext by the API, and are not written to logs.
5. Why we are allowed to process it
- Performance of a contract — running the account, executing the runs you queue, billing you.
- Legal obligation — keeping invoices and tax records.
- Legitimate interests — securing the platform, preventing abuse, enforcing plan limits, diagnosing failures, and sending service messages about your own account. We have weighed these against your interests and limited the data accordingly.
- Consent — only where we ask for it explicitly, for example a product-news email you opt into. You can withdraw it at any time without affecting the Service.
6. How long we keep it
Captured runs and screenshots. We will not claim a deletion schedule we do not run. There is no automated retention deletion in the platform today — not on a timer, not when you read an old run. Your runs, screenshots and diff images stay until you delete them: a single run, a site, or the whole organisation. The retention period attached to your plan is a minimum commitment — the window we undertake to keep your data available for — and not a promise that it is destroyed at the end of it:
| Plan | Minimum retention commitment |
|---|---|
| Free | 7 days |
| Starter | 30 days |
| Studio | 3 months |
| Agency | 6 months |
| Scale | 6 months |
If you need captured content destroyed on a fixed schedule, delete it yourself or ask us at [PRIVACY EMAIL] and we will do it.
Other categories:
- Account data — kept for as long as the organisation exists. Cancelling a subscription does not delete it: the organisation moves to the free plan and keeps its data. It is removed when you ask for removal — either by running the self-serve deletion in your account, which executes after a 7-day grace period you can cancel within, or by writing to us.
- Trial data — nothing is deleted when a trial ends; the organisation drops to the free plan and its history stays.
- Invoices and tax records — [STATUTORY RETENTION PERIOD], because we are legally required to keep them.
- Audit log — this one is pruned, daily. Records are kept for at least 30 days, and beyond that for the shorter of your plan's retention period and 365 days. In practice today: 30 days on Free and Starter, 90 days on Studio, 365 days on Agency and Scale.
- Email delivery log — the envelope of each transactional message (template, recipient, subject, result). Not pruned on a schedule today; deleted with the organisation.
- Usage events — the per-event ledger and the daily aggregates built from it. Neither is pruned on a schedule today; both are deleted with the organisation.
- Server logs — [SERVER LOG RETENTION].
- Backups — [BACKUP FREQUENCY AND RETENTION]. Data deleted from the live system disappears from backups as they age out.
Erasure on request always overrides the above: see your rights.
7. Sub-processors
These are every third party that can touch customer data, what they do, and where they are. We will notify organisation owners by email at least 30 days before adding or replacing one, and you may object.
| Sub-processor | Purpose | Data it can see | Location |
|---|---|---|---|
| Stripe | Payments, subscriptions, invoicing | Billing name, email, address, VAT number, payment method (held by Stripe, not by us) | Ireland / United States |
| Anthropic (Claude) | AI analysis of visual diffs — only when your organisation leaves AI analysis enabled. Any admin of your organisation can switch AI off entirely under Configs → AI, on any plan; while it is off nothing at all is sent here | The baseline image, the current image, the diff image and the page URL for the diff being analysed | United States |
| [HOSTING PROVIDER AND REGION] | Hosting of the application, database and screenshot storage | All customer data at rest | [HOSTING REGION] |
| [EMAIL DELIVERY PROVIDER AND REGION] | Delivery of transactional email (verification, invitations, alerts, receipts) | Recipient email address and message content | [MAIL PROVIDER REGION] |
| Google (Google Fonts) | Serving the web fonts used by these public pages. It sets no cookie, but your browser requests the font files directly, so Google receives your IP address and user agent on every page view | IP address and user agent of website visitors. No account data and no captured site content | United States |
There is no analytics provider, no advertising network, no session-recording tool and no error-tracking provider in this list, because we do not use any. Google Fonts is listed for completeness and honesty: it is a third-party request your browser makes on our behalf, not a processor of your account data. We intend to self-host these fonts and remove the entry.
8. International transfers
The application and your stored screenshots live with the hosting provider named above, in the region named above. Where a sub-processor is outside the European Economic Area — Anthropic is in the United States, Stripe processes some data there, and Google receives visitors' IP addresses in the United States when this website's fonts load — the transfer is made under the European Commission's Standard Contractual Clauses together with the supplementary measures described in this policy.
Two of these deserve to be stated plainly rather than buried. The font transfer affects every visitor to these public pages, before any account exists, and the only way to avoid it today is to block the request in your browser; we intend to remove it by self-hosting the fonts. The AI transfer is the only one that involves your captured page content: it happens only when an analysis is run, carries only that result's baseline, current and diff images plus the page URL, and never happens at all on a plan without AI analysis. You can also switch it off entirely. Any administrator of your organisation can disable AI analysis for the whole organisation under Configs → AI in the app, on every plan including the free one. While it is off we refuse every analysis on the server — manual, automatic after a comparison, queued, or from a run started through the API — before any content leaves us, whatever your plan includes. Each change to the switch is written to the audit log, on every plan; reading the audit log inside the application is itself a plan capability available from the Agency plan upwards, so on a lower plan the entry is recorded but is not visible to you on screen. This is the same control the Data Processing Agreement commits us to.
9. Security
We would rather describe controls we actually operate than publish a badge. We hold no third-party security certification today, and we will not imply that we do. What is true:
- Transport encryption. All access to the application and the API is over TLS.
- Tenant isolation. Every site, run, screenshot and API key belongs to exactly one organisation, and every read and write is checked against the requesting user's organisation on the server. Hiding a control in the interface is never how a limit is enforced here.
- Screenshot access. Stored images are not publicly listed and are not served from guessable public URLs. They are served only to signed-in members of the owning organisation — there is no public share link feature, so there is no way to expose a run outside your organisation at all.
- Credentials. Passwords are stored only as salted hashes. API keys are stored as hashes and shown exactly once, at creation. Environment HTTP-auth and proxy credentials are write-only in the interface, are never returned in plaintext by the API, and are never written to logs.
- Payment data. We never see or store card details; card entry happens on Stripe's systems.
- Staff access. Only the people who operate the platform can reach production data, only when operating it or answering a support request you raised, and significant actions are recorded in the audit log.
- Backups. [BACKUP FREQUENCY AND RETENTION].
- Testing. No third-party penetration test has been performed to date. We will say so plainly rather than imply otherwise.
Reporting a vulnerability. Write to [SECURITY EMAIL]. We will acknowledge, keep you updated, and will not pursue you for a good-faith report that does not exfiltrate other customers' data or degrade the service.
If a personal-data breach affects you, we will notify the relevant supervisory authority and affected customers as required, without undue delay.
10. Your rights, and how to exercise them yourself
You have the right to access, correct, erase, restrict, port and object to the processing of your personal data, and to complain to a supervisory authority ([SUPERVISORY AUTHORITY], or the authority where you live).
Two of these you can exercise immediately, without asking us, from your account page:
- Export — download your organisation's account data, sites, URLs and run metadata in a machine-readable format.
- Delete — delete your organisation and everything in it, after a short safety window during which you can cancel the request.
For anything else, write to [PRIVACY EMAIL]. We answer within one month and we do not charge for it.
If the request concerns personal data inside a captured screenshot, that data belongs to the customer whose site it is. Send the request to them; if it reaches us first we will forward it and assist them, as our Data Processing Agreement requires.
11. Cookies
This website sets no analytics or advertising cookies at all. The full, short list of what is set and why is in the Cookie Notice.
12. Children
The Service is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16.
13. Changes to this policy
We will update this page when the product changes. For a change that materially affects how we process your personal data — including adding a sub-processor — we notify organisation owners by email at least 30 days beforehand.
Questions: [PRIVACY EMAIL].