Security and privacy
Data we collect
Exactly what the SDK sends, and what it never touches.
The SDK sends one config request when your page loads. It sends events only after a guide has been shown:
| Field | Example | Why |
|---|---|---|
| Event type | step_completed | Analytics and billing |
| Guide, version, step, anchor | create-first-invoice, 2, pick-client | Analytics and stale-anchor detection |
| Clip source | hosted | Hosted video metering |
| User key | SHA-256 of your user id, or a random device id | Counting guided users |
| Session id | Random, per tab | Counting clip loads once per session |
| Platform and SDK version | web, 1.0.0 | Support |
What the SDK never collects
- Form contents, keystrokes or screen recordings
- Page content beyond the
data-guideanchors and step selectors it looks for (capture links aside, below) - The traits you pass to
identify(they stay on the device, for targeting) - Cookies: progress is kept in local storage on the device
Capture links
A Generate with AI capture link is the one exception: while someone on your team captures (after they press Start capturing), the SDK sends what each page shows: its path, title and headings, and the text and labels of buttons, links and fields, with a selector for each. It never sends what anyone typed, elements inside data-private, or web screenshots, and it masks emails, phone numbers, long numbers and tokens before sending. Your end users never see a capture link unless someone gives them one.
Where it goes
Analytics events are stored in Cloudflare Analytics Engine and kept for 90 days. Billing meters keep only hashed user keys, per month. Dashboard accounts, guides and clips are stored in Cloudflare D1 and R2. See the privacy policy.