Privacy
What the widget collects
This is a working draft, published so it can be read and corrected. It has not been reviewed by a lawyer. If something here matters to you commercially, ask before relying on it.
Two kinds of people
A customer is someone with a tinybugreport account. An end user is someone using a customer's site who files a message through the widget. The two are treated differently because only one of them chose to be here.
What is collected from an end user
When somebody files a message, the widget sends what they typed and what the page can tell it: the page address, the host, the browser user agent, the viewport size, and any console errors already logged. A name and email address are included only if the customer's site passed them in, or the person typed them. Screenshots and files are attached only when the person chooses them, up to 5 files of 5MB each.
The widget does not track people across pages or sites, sets no advertising identifiers, and sends nothing at all until somebody presses send. It stores one anonymous id in the browser so a person can see replies to their own messages.
Who the data belongs to
Messages filed through a customer's site belong to that customer. We store and process them so the product works, and we do not sell them, use them to train anything, or share them with anyone who is not needed to run the service.
Who else touches it
Amazon Web Services stores it, in the United States. Stripe handles payment and never receives message content. Email is sent through Amazon SES. If a customer connects Slack or Jira, message content goes to those services at their instruction.
How long it is kept
Messages are kept until the customer deletes them or closes their account. Sign in links expire in minutes and sessions in days. Attachments a person selected but never sent are deleted within a day.
Asking for a copy or a deletion
End users should ask the site they filed the message on, because it is that customer's data. Customers can ask us directly and we will action it.