Skip to content

Security and privacy

Data we collect

Exactly what the SDK sends, and what it never touches.

The SDK sends one config request when your page loads. It sends events only after a guide has been shown:

FieldExampleWhy
Event typestep_completedAnalytics and billing
Guide, version, step, anchorcreate-first-invoice, 2, pick-clientAnalytics and stale-anchor detection
Clip sourcehostedHosted video metering
User keySHA-256 of your user id, or a random device idCounting guided users
Session idRandom, per tabCounting clip loads once per session
Platform and SDK versionweb, 1.0.0Support

What the SDK never collects

  • Form contents, keystrokes or screen recordings
  • Page content beyond the data-guide anchors and step selectors it looks for (capture links aside, below)
  • The traits you pass to identify (they stay on the device, for targeting)
  • Cookies: progress is kept in local storage on the device

A Generate with AI capture link is the one exception: while someone on your team captures (after they press Start capturing), the SDK sends what each page shows: its path, title and headings, and the text and labels of buttons, links and fields, with a selector for each. It never sends what anyone typed, elements inside data-private, or web screenshots, and it masks emails, phone numbers, long numbers and tokens before sending. Your end users never see a capture link unless someone gives them one.

Where it goes

Analytics events are stored in Cloudflare Analytics Engine and kept for 90 days. Billing meters keep only hashed user keys, per month. Dashboard accounts, guides and clips are stored in Cloudflare D1 and R2. See the privacy policy.

Search the docs and guides.

PlayStep is coming soon

We're opening PlayStep to teams one at a time. Leave your name and email and we'll set up a demo.

We use your email only to arrange the demo. See the privacy policy.