Privacy Policy
Effective Date: January 11, 2026
1. Scope and Roles
This Privacy Policy explains how Samelogic, Inc. ("Samelogic," "we," "us," or "our") collects, uses, and discloses information when you visit our website, use our web application, Chrome extension, APIs, embedded clients (including microsurveys), and related services (collectively, the "Services").
When we process Customer Content on behalf of a Customer, we act as a service provider or processor. The Customer is responsible for providing End User notices and managing End User rights requests. For account, billing, and marketing site data, Samelogic acts as a controller.
2. Information We Collect
Account and Profile Information
We collect information you provide when creating or managing an account, such as name, email address, username, company, role, and profile details.
Authentication Data
If you sign in using OAuth providers (such as Google or GitHub) or email authentication, we receive identifiers and related authentication data from those providers.
Billing and Transaction Information
Payments are processed by Stripe. We receive billing contact details, subscription status, and Stripe customer identifiers, but payment card details are handled directly by Stripe.
Customer Content
The Services capture and store Customer Content, including:
- Element captures such as selectors, raw HTML, attributes, computed styles, dimensions, metadata, and stability scores.
- Screenshots and preview images associated with captures.
- Notes, tags, bug reports, comments, and element shares.
- Step replay recordings (rrweb events), start URL, viewport, user agent, and playback annotations. Input values are masked by default in step replays, but visible page content and metadata may still be captured.
- Console logs or technical context when enabled.
- Survey responses, response metadata, and event data for microsurveys, including optional identity fields provided by the Customer.
- Web scraping outputs or other data submitted via APIs and integrations.
Usage and Device Data
We collect usage data such as IP address, browser type, device identifiers, operating system, pages viewed, and interactions with the Services. We also collect log data for security, debugging, and performance.
Communications and Support
We collect information when you contact us, including support requests and chat transcripts (for example, through Crisp).
Integration Data
If you connect third-party services, we store integration settings and credentials (such as OAuth tokens or workspace identifiers) needed to enable those integrations.
Cookies and Local Storage
We use cookies and similar technologies for authentication, session management, analytics, and to remember preferences. The Chrome extension may store limited data locally (for example, session state or unsent step replays) to operate properly.
3. How We Use Information
- Provide, operate, and secure the Services, including element capture, stability scoring, replay playback, analytics, and collaboration features.
- Authenticate users, manage accounts, and enforce usage limits.
- Process Customer Content in accordance with Customer instructions and applicable law.
- Improve and develop the Services, including performance and reliability.
- Send administrative messages, service updates, and marketing communications (you can opt out of marketing emails).
- Detect, prevent, and respond to security incidents, abuse, and fraud.
- Comply with legal obligations and enforce our Terms.
4. How We Share Information
- Service providers that help us operate the Services (for example, hosting, analytics, customer support, error monitoring, and storage providers such as Supabase, Vercel Analytics, Heap, Sentry, Google Tag Manager, and Crisp).
- Payment processing through Stripe.
- OAuth and authentication providers when you choose to sign in through them.
- Your organization or collaborators, consistent with your sharing and access settings.
- Legal and regulatory authorities when required by law or to protect rights and safety.
- In connection with a business transaction such as a merger, acquisition, or asset sale.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
5. Data Retention
We retain information for as long as necessary to provide the Services, meet legal obligations, and resolve disputes. Customers can request deletion of Customer Content through their account settings or by contacting us. Local extension data may persist for a limited period unless deleted by the user.
6. Security
We use reasonable technical and organizational measures to protect information against unauthorized access, disclosure, alteration, and destruction. No security program is perfect, so we cannot guarantee absolute security.
7. International Transfers
We may process and store information in the United States and other countries where our service providers operate. When required, we use appropriate safeguards for cross-border transfers.
8. Your Rights and Choices
You may request access, correction, deletion, or export of your account information by contacting us. For Customer Content processed on behalf of a Customer, End Users should direct privacy requests to the relevant Customer. You can opt out of marketing emails using the unsubscribe link in those messages.
9. Children's Privacy
The Services are not intended for children under 13, and we do not knowingly collect personal information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services or by other appropriate means.
11. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at hi@samelogic.com.