Legal

Privacy
Policy

TL;DR — We store your feedback data to show it in your dashboard. We don't track you, we don't sell your data, we don't share it with anyone. Everything is hosted in the EU.

01

What We Collect

Account data

Your email address, used for authentication via magic link and to communicate important service updates.

Project data

Project names, domain allowlists, widget configuration, and API keys you create within the Service.

Feedback data

Screenshots, browser console logs, network error logs, user journey breadcrumbs, and any annotations or comments — submitted by your website visitors through the Sendshot widget.

02

What We Don't Collect

No tracking

We do not use analytics tools, tracking pixels, or any form of behavioral tracking on our website or within the Service.

No cookies beyond auth

The only cookie we set is a session cookie required for authentication. No advertising or third-party cookies.

No data selling

We do not sell, rent, or trade your data to anyone. Period.

03

How We Use Your Data

Your data is used exclusively to provide the Service to you: displaying feedback in your dashboard, powering share links, and sending transactional emails (magic links, account notifications). That's it.

04

Data Storage & Security

Hosted in Europe

All data is stored on servers located in the European Union (Hetzner, Germany). Screenshots are stored in S3-compatible object storage. Database records are stored in PostgreSQL.

Encryption

All data is encrypted in transit (TLS). API keys are hashed before storage. We follow security best practices for a service of this nature.

05

Third-Party Services

We use Resend for sending transactional emails (magic links). Resend processes your email address solely for email delivery. We have no other third-party data processors.

06

Data Retention

We retain your data for as long as your account is active. When you delete your account, all associated data (projects, feedback, screenshots, API keys) is permanently deleted within 30 days.

07

Your Rights (GDPR)

Access & portability

You can request a copy of all data we hold about you.

Rectification

You can update your account information at any time.

Erasure

You can delete your account and all associated data.

Objection

You can object to processing of your data. Contact us and we will address your concern.

08

Children

Sendshot is not intended for use by anyone under the age of 16. We do not knowingly collect data from children.

09

Changes

We may update this policy from time to time. Material changes will be communicated via email. Continued use after changes constitutes acceptance.

10

Contact

Questions or requests about your data? Reach us at privacy@sendshot.dev.