Draft for legal review. This text is a starting point written for PlayStep's launch and has not yet been reviewed by a lawyer.
Privacy policy
Last updated 10 October 2026
This policy explains how Company legal name ("PlayStep") handles personal data.
Dashboard users (our customers)
| Data | Why | Kept |
|---|---|---|
| Name and email | Your account and sign-in (we email you a one-time code; there are no passwords) | While your account exists |
| Workspace, member roles, invitations | Running your workspace | While the workspace exists |
| Billing details | Handled by Paddle, our reseller; we receive your plan and status, not your card | As Paddle requires |
| Product usage logs | Security and support | 30 days |
Demo requests
Before launch, "Request a demo" on playstep.app asks for your name and email. We use them only to arrange a demo and to tell you when PlayStep opens, and we store them with Brevo, our email provider, along with which page you asked from. We keep them until you ask us to delete them, or until a year after launch if you do not become a customer. Write to privacy@playstep.app to have them removed.
End users of our customers' apps
When a customer's app shows a PlayStep guide, the SDK sends the events described in data we collect: event types, guide and step ids, a hashed user key or random device id, a session id, the platform and SDK version. It does not collect form contents, page content, keystrokes or screen recordings, and sets no cookies. For this data, our customer is the controller and PlayStep is the processor; we use it only to provide guides, analytics and billing to that customer.
Analytics events are kept for 90 days. Billing meters keep hashed user keys for the billing month and its invoicing.
Generate with AI
When a customer's team member opens a capture link (or asks PlayStep to read public pages), we receive what those screens show: page paths, titles, headings, and the labels of buttons, links and fields. We never receive what anyone typed into a field, elements marked private, or web screenshots; Flutter apps send small screenshots only when the customer turns them on. Emails, phone numbers, long numbers and tokens in labels are masked before they are stored.
To write tour suggestions, we send these screens to Google (the Gemini API) as our subprocessor, on a paid plan under which Google does not use the data to train its models. Captured screens, screenshots and suggestions are deleted after 30 days.
Where data is stored
On Cloudflare's network (Workers, D1, R2, Queues, Analytics Engine and Browser Run). Email is sent through Cloudflare. Payments are processed by Paddle. Generate with AI uses Google's Gemini API. Demo requests are kept in Brevo.
Your rights
You can access, correct, export or delete your account data from the dashboard or by writing to privacy@playstep.app. End users should contact the app they use; customers can delete an end user's data with our server API.
Changes
We will post changes here and email account owners about material changes. Contact: privacy@playstep.app.