Privacy Policy

Last updated: February 2026

1. Introduction

PipeKit ("we", "our", "us") is committed to protecting the privacy of our users ("you") and the end users of your applications. This Privacy Policy explains how we collect, use, store, and protect data when you use the PipeKit service and SDK.

2. Data We Collect

Account Data

When you register for PipeKit, we collect your email address, name, and company name (optional).

Session Data (from your app users)

When you integrate the PipeKit SDK, the following data may be captured from your app's users:

  • Screen recordings (video of the app UI, not the device camera)
  • Console logs generated by your application
  • Network requests (URLs, status codes, timing — not request/response bodies by default)
  • Device information (model, OS version, app version)
  • Touch/interaction events
  • User identifiers you explicitly set via the SDK

Usage Data

We track session counts and storage usage per account for billing and service management.

3. How We Use Data

  • To provide, maintain, and improve the PipeKit service
  • To display session recordings and logs in your dashboard
  • To manage your account and subscription
  • To communicate with you about your account or the service
  • To enforce our Terms of Service

We do not sell, share, or use your session data or your end users' data for advertising, analytics, or any purpose other than providing the Service to you.

4. Data Storage and Security

Session recordings are stored in encrypted object storage (S3-compatible). All data in transit is encrypted via TLS/HTTPS. API keys are hashed before storage and cannot be retrieved in plaintext. We implement industry-standard security practices to protect your data.

5. Data Retention

Session recordings and associated metadata are automatically deleted after 30 days. Account data is retained for as long as your account is active. When you delete your account, all associated data (sessions, API keys, billing info) is permanently deleted within 30 days.

6. Privacy Masking

The PipeKit SDK provides built-in privacy features to protect sensitive information:

  • Automatic masking of password fields and secure text entries
  • Ability to mark any UI element as sensitive (will be blacked out in recordings)
  • Network request body filtering
  • Console log filtering to exclude sensitive data
  • Option to disable recording entirely for specific screens

It is your responsibility to properly configure masking for sensitive data in your application. See our Privacy & Masking documentation.

7. Your Responsibilities

As a PipeKit user, you are responsible for:

  • Informing your app's users that session recording is active
  • Obtaining appropriate consent before recording user sessions
  • Complying with GDPR, CCPA, and any applicable data protection laws
  • Configuring the SDK to mask sensitive data (passwords, credit cards, personal info)
  • Not recording minors without parental consent where required by law

8. GDPR Compliance

For users subject to GDPR:

  • Data Controller: You (the developer) are the data controller for your end users' session data
  • Data Processor: PipeKit acts as a data processor on your behalf
  • Right to Access: You can export all session data from your dashboard
  • Right to Deletion: You can delete sessions and your account at any time
  • Data Portability: Session data is available in standard JSON format

9. Third-Party Services

We may use third-party services for:

  • Payment processing (Stripe / PayTabs) — we do not store your credit card details
  • Email delivery — transactional emails only, no marketing without consent

10. Cookies

We use essential cookies only for authentication (session tokens). We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through the Service. Continued use after changes constitutes acceptance.

12. Contact Us

For privacy-related questions or data requests, contact us at [email protected]