Skip to content

Privacy Policy

Effective Date: September 15, 2026

1. Scope and Roles

This Privacy Policy explains how Samelogic, Inc. ("Samelogic," "we," "us," or "our") collects, uses, and discloses information when you visit our website, use our web application, Chrome extension, APIs, embedded clients (including microsurveys), and related services (collectively, the "Services").

When we process Customer Content on behalf of a Customer, we act as a service provider or processor. The Customer is responsible for providing End User notices and managing End User rights requests. For account, billing, and marketing site data, Samelogic acts as a controller.

2. Information We Collect

Account and Profile Information

We collect information you provide when creating or managing an account, such as name, email address, username, company, role, and profile details.

Authentication Data

If you sign in using OAuth providers (such as Google or GitHub) or email authentication, we receive identifiers and related authentication data from those providers.

Billing and Transaction Information

Payments are processed by Stripe. We receive billing contact details, subscription status, and Stripe customer identifiers, but payment card details are handled directly by Stripe.

Customer Content

The Services capture and store Customer Content, including:

  • Element captures such as selectors, raw HTML, attributes, computed styles, dimensions, metadata, and stability scores.
  • Screenshots and preview images associated with captures.
  • Notes, tags, bug reports, comments, and element shares.
  • Step replay recordings (rrweb events), start URL, viewport, user agent, and playback annotations. Input values are masked by default in step replays, but visible page content and metadata may still be captured.
  • Console logs or technical context when enabled.
  • Survey responses, response metadata, and event data for microsurveys, including optional identity fields provided by the Customer.
  • Web scraping outputs or other data submitted via APIs and integrations.

Usage and Device Data

We collect usage data such as IP address, browser type, device identifiers, operating system, pages viewed, and interactions with the Services. We also collect log data for security, debugging, and performance.

Communications and Support

We collect information when you contact us, including support requests and chat transcripts (for example, through Crisp).

Integration Data

If you connect third-party services, we store integration settings and credentials (such as OAuth tokens or workspace identifiers) needed to enable those integrations.

Cookies and Local Storage

We use strictly necessary cookies for authentication, security, and saved preferences. You can choose usage measurement, recordings of public-page visits, and advertising separately. Basic visit counts are always on, and support chat is available independently of these choices. The Chrome extension may store limited data locally (for example, session state or unsent step replays) to operate properly.

CookieSet byPurposeCategoryLifetime
sl_cookie_consentSamelogicRemembers your saved privacy choicesNecessary12 months
next-auth.* / __Secure-*SamelogicSign-in session and CSRF protectionNecessarySession to 24 hours
mantine-color-schemeSamelogicRemembers your light or dark preferenceNecessary30 days
sl_marketing_attributionSamelogicRecords which campaign brought you hereMarketing30 days
_ga, _gidGoogleUsage analytics through Google Tag ManagerAnalyticsUp to 2 years
_clck, _clskMicrosoft ClarityAgreed recordings of visits to selected public pagesPublic-page visit recordingsUp to 1 year
_hp2_id.*, _hp2_ses.*HeapProduct analyticsAnalyticsUp to 13 months
crisp-client/*CrispSupport chat continuityFunctional6 months

Open Privacy preferences at the bottom of any page to change your settings. Reject optional turns off usage measurement, public-page recordings, and advertising. These three tools wait for your permission, and earlier refusals stay off. A supported browser request not to track you keeps these optional tools off by default; you can save different choices for this site. Basic visit counts through Vercel remain on for selected public pages, regardless of these settings or browser tracking preferences. We do not send names, email addresses, or account identifiers with those counts. Support chat also remains available.

Heap and Google Analytics wait for usage permission. Microsoft Clarity waits for separate recording permission and is limited to selected public pages, with page text and form entries hidden. These tools do not load on account, payment, sign-in, invitation, or saved-recording pages. We do not send your account name or email address to Heap. We remove private details from the page addresses used for basic counts and keep unreviewed pages out. Chat opens in a separate embedded window only when you request it. We do not automatically pass the current page address or your account details to Crisp. Crisp receives connection information and anything you choose to share in the conversation.

If you allow usage measurement, Samelogic may keep limited records of opening a shared recording, playing it, or inspecting its timeline. They contain the action, date, and internal recording and viewer references, without recording contents, comment text, or customer website addresses. These optional histories stay inside Samelogic. Signed-in histories can be connected to your account; they are not anonymous. A random reference stored for the browser tab helps avoid counting the same action twice. Turning research recordings off does not disable bug recordings you deliberately create with Samelogic.

3. How We Use Information

  • Provide, operate, and secure the Services, including element capture, stability scoring, replay playback, analytics, and collaboration features.
  • Authenticate users, manage accounts, and enforce usage limits.
  • Process Customer Content in accordance with Customer instructions and applicable law.
  • Improve and develop the Services, including performance and reliability.
  • Send administrative messages, service updates, and marketing communications (you can opt out of marketing emails).
  • Detect, prevent, and respond to security incidents, abuse, and fraud.
  • Comply with legal obligations and enforce our Terms.

4. How We Share Information

  • Service providers that help us operate the Services (for example, hosting, analytics, customer support, error monitoring, and storage providers such as Supabase, Vercel Analytics, Heap, Sentry, Google Tag Manager, and Crisp).
  • Payment processing through Stripe.
  • OAuth and authentication providers when you choose to sign in through them.
  • Your organization or collaborators, consistent with your sharing and access settings.
  • Legal and regulatory authorities when required by law or to protect rights and safety.
  • In connection with a business transaction such as a merger, acquisition, or asset sale.

We do not sell personal information. If you allow Advertising, approved advertising providers may receive limited visit information to measure or personalize ads. Advertising stays off when you refuse it. Clarity's advertising sharing stays off regardless of your advertising choice.

5. Data Retention

We retain information for as long as necessary to provide the Services, meet legal obligations, and resolve disputes. Customers can request deletion of Customer Content through their account settings or by contacting us. Local extension data may persist for a limited period unless deleted by the user.

Optional usage histories kept by Samelogic are limited to 90 days in our reports, with older entries scheduled for daily removal. In Privacy preferences, you can remove usage history linked to your signed-in account or the current browser tab. This does not delete your bug recordings, required service or payment records, or copies held by other companies. Contact hi@samelogic.com for help with those requests. Turning measurement off stops future collection; it does not itself erase earlier history held by other companies.

6. Security

We use reasonable technical and organizational measures to protect information against unauthorized access, disclosure, alteration, and destruction. No security program is perfect, so we cannot guarantee absolute security.

7. International Transfers

We may process and store information in the United States and other countries where our service providers operate. When required, we use appropriate safeguards for cross-border transfers.

8. Your Rights and Choices

You may request access, correction, deletion, or export of your account information by contacting us. For Customer Content processed on behalf of a Customer, End Users should direct privacy requests to the relevant Customer. You can opt out of marketing emails using the unsubscribe link in those messages.

9. Children's Privacy

The Services are not intended for children under 13, and we do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services or by other appropriate means.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at hi@samelogic.com.