---
title: Privacy Policy | ReplayPilot
description: What ReplayPilot collects, why, and how long we keep it, in plain language.
canonical: https://replaypilot.com/policies/privacy
---

# Privacy Policy | ReplayPilot

PRIVACY

# Privacy Policy

Last updated August 12, 2026

The privacy of your data, and it is your data, not ours, is a big deal to us. This page lays out what we collect and why, how it's handled, and your rights over it. We promise we never sell it: never have, never will.

## The short version

- We record what happens in your users' sessions on your site, because that's the product.
- We mask passwords and card numbers automatically, before we ever store a session.
- We don't sell your data or your users' data. We don't run ads.
- We keep sessions for as long as your plan says, then delete them.
- You can export or delete your account and its data any time from Settings, no email required.

## Who we are

This policy is for ReplayPilot, the session-replay product you're using or evaluating. For data protection law, we're the controller of your own account data, and a processor of the session data you collect from your users through our snippet. You decide what to record, and we handle it on your instructions. This policy doesn't cover how your own product handles your end users' data, since that's between you and them.

Privacy questions and data rights requests go to a dedicated inbox: [privacy@replaypilot.com](mailto:privacy@replaypilot.com).

## What we collect and why

Our guiding principle is to collect only what we need. Here's what that means in practice.

Identity and access. When you sign up, we ask for your name and email address, so you can use and personalize your account and so we can send you essential account updates.

Billing information. If you're on a paid plan, your card details go straight to Paddle, our merchant of record, and they don't hit our servers. We keep a record of the transaction, including the last 4 digits of the card, for invoicing and billing support.

Session data. When your site loads our snippet, we record clicks, page changes, form field names (not values), console errors, and network requests, for each visitor session. We mask passwords and card numbers before we store any of it.

Ingest logs. We log the IP address of requests to our ingest endpoint, to rate-limit abuse. We don't attach it to a session recording.

Advertising and cookies. We don't run ads, and we don't use analytics or advertising cookies. See our [Cookie Policy](/policies/cookies) for the one cookie we do set.

Our own site. We also run our own product on replaypilot.com, to see what's confusing about it. We don't record you here until you accept the notice at the bottom of the page: same masking rules as above, same product, no third party involved.

## Why we're allowed to process it

We process your account data to perform our contract with you: you can't use a product you're not signed in to. We process session data on your instructions, as your processor, because that's the service you asked us to run. We process ingest IP addresses under our legitimate interest in keeping the service available and free of abuse. Some local laws require your users' consent before you record a session; getting that consent is your responsibility, not ours. See the Terms of Service.

## How we use it

We use session recordings to show you what happened in your product, flag sessions with errors, and write an AI summary you can search in plain English.

If you turn on webhook or email alerts, we send you a short message when a session ends with an error, using the address or URL you gave us.

## When we access or disclose your information

No one at ReplayPilot looks at your session recordings except for limited purposes with your explicit permission, for example to help with a support request you've raised. An automated process rarely errors out partway through and needs a human to step in. When that happens, we look at the minimum data necessary to fix it, and we aim for a root-cause fix so it doesn't recur.

We rely on a small set of infrastructure providers to run the service. They act as our processors on our instructions, not as independent users of your data. That's Cloudflare (Workers, D1, and R2) for hosting session data, and Cloudflare Workers AI for session summaries and search. That AI runs on our own infrastructure, not a third-party vendor. It's also Cloudflare Email for alert delivery, and Paddle for billing.

As a company, our policy is to not respond to government requests for data unless compelled by legal process, or in limited emergency circumstances. Where we're required to disclose data, we'll notify affected account holders first, unless we're legally prohibited from doing so.

We'll also disclose data if the law requires it, or to protect the rights, safety, or property of ReplayPilot or our users.

If ReplayPilot is ever acquired by or merged with another company, we'll notify you before any of your personal information transfers or becomes subject to a different privacy policy.

## Where it's processed

ReplayPilot runs on Cloudflare's global network, so your data may be processed in countries other than your own, including the United States. Our processors handle it only on our instructions, under the same processor relationship described above, wherever their infrastructure happens to run it. See our [Data Processing Addendum](/policies/dpa) for how EU/UK data transfers are safeguarded.

## How long we keep it

Retention depends on your plan: 30 days on Free, 90 days on Starter and Growth, 180 days on Scale, and unlimited on Enterprise. See [pricing](/pricing) for current details. Expired data on self-serve plans is deleted automatically by a daily job, so you don't need to ask.

Dashboard retrieval follows the same window as storage retention. Every plan also has a log volume allowance. Once an account hits its allowance, we keep recording sessions as normal but stop writing new log lines until older ones age out of the retention window.

Want it gone sooner? Delete it yourself: a single session from its playback page, a whole project from Settings, or your entire account from the Danger zone in Settings. All three take effect immediately, no email required.

## How we protect it

We encrypt data in transit and mask passwords and card numbers before we ever store a session. Add your own masking selectors for anything else sensitive to your product. No system is perfectly secure, and we can't guarantee data stays safe from every exposure. This is the actual, current shape of our defenses, described rather than summarized as a badge.

## Your data protection rights

Whoever's covered, whether you as our customer or your end users whose sessions we process on your behalf, has the same set of rights over their personal data:
- Access: ask what personal data we hold about you.
- Correction: fix inaccurate account data.
- Deletion: delete an individual session, a project, or a whole account, any time, self-serve.
- Portability: export your account's data as JSON from Settings, any time.
- Objection: object to or ask us to restrict how we process your data.

We won't charge you differently, offer you fewer features, or give you worse support because you've exercised any of these rights.

If you're in the EU or UK, you also have the right to lodge a complaint with your local data protection authority. If you're a California resident, you have the right to know what we collect and to delete it under the CCPA. We don't sell or share personal information for cross-context advertising either, so there's no "opt out of sale" to exercise.

To use any of these rights, for your own account or on behalf of your end users, email [privacy@replaypilot.com](mailto:privacy@replaypilot.com) from your account's registered address and we'll respond within 30 days. If someone else is asking on your behalf, like a lawyer, we'll need something showing they're authorized to act for you before we act on the request.

## Your choices

- Add your own CSS selectors in Settings to mask anything else on top of the automatic masking.
- Delete an individual session, a project, or your whole account any time, self-serve.
- Export your account's data as JSON any time, from Settings.
- Revoke a shared session link any time from Settings.

## Children's privacy

ReplayPilot isn't intended for children under 16, and we don't knowingly collect their personal information.

## Changes and questions

If we change this policy in a way that matters, we'll update the date at the top and email account holders. Have questions, comments, or concerns about this policy, your data, or your rights? Email [privacy@replaypilot.com](mailto:privacy@replaypilot.com) and we'll be happy to answer them.

We adapted parts of this policy from the 37signals Privacy Policy, used under CC BY 4.0.

## Questions?

Email us and a real person will answer.[hello@replaypilot.com →](mailto:hello@replaypilot.com)