LogClip

Legal

Privacy Policy

What we collect about you when you use LogClip, why, and what you can do about it. Separately: what happens to the data our customers capture with LogClip, which is theirs and not ours.

Version 1.0 · Effective 27 August 2026

1. Two different roles

LogClip handles two kinds of personal data, under two different sets of obligations. Almost every question about this policy resolves once you know which one you are asking about.

Your account with usData you capture with LogClip
Whose dataYou — the person who signs in to the console.Your end users, recorded by the SDK you installed on your own site.
Our roleController. We decide what to collect and why.Processor. You decide what is recorded, with what masking, and for how long. We only act on your instructions.
Governed byThis policy.The Data Processing Agreement, not this policy.

If you are an end user of a site that uses LogClip

We are not the right people to ask. We hold that recording on behalf of the company whose site you visited, and we are not permitted to hand it over, change it or delete it on your say-so — that company decides, and it is the one that has to verify who you are. Section 10 explains how to reach them and what we will do.

2. What we collect

Everything in this section is about your account with us, not about your end users.

DataDetail
AccountYour email address, the name and phone number you optionally add to your profile, your role in the workspace (owner, admin, member or viewer), and when the account was created. We store a scrypt hash of your password, never the password.
WorkspaceThe workspace name, the sites you configure, and the settings you choose — masking rules, retention, consent gating, notification recipients.
API keysPublishable pk_ keys are stored as issued. Secret sk_ keys are stored only as a SHA-256 hash, which is why we cannot show one to you again after it is created.
BillingSubscription and invoice records. Card details are handled by Stripe and never reach our systems.
SupportWhatever you send us by email when you get in touch.
Demo requestsIf you fill in the form on this site: your name, email, and the company, role, site count and message you choose to add. We also keep the IP address, browser and referring page of the submission, to tell real enquiries from bots. It is stored so the request cannot be lost, and emailed to the people who answer it.
Server logsOrdinary operational logs from our own infrastructure, including IP addresses, kept for troubleshooting and abuse prevention.

We do not run analytics on you

There is no third-party analytics, advertising or tracking script on our marketing site, and we do not run our own session-replay SDK on it either. We would rather say that plainly than write a cookie banner about it.

3. Why, and on what basis

PurposeLawful basis (GDPR Art. 6)
Providing the service, authenticating you, keeping your workspace separate from everyone else’sPerformance of a contract
Billing, invoicing and collecting paymentPerformance of a contract
Service email — alerts you configured, usage warnings, invitations, security noticesPerformance of a contract
Keeping the service secure: rate limiting, abuse prevention, the staff-access audit logLegitimate interests — running a multi-tenant service safely
Meeting legal and accounting obligationsLegal obligation

We do not sell personal data, we do not share it for advertising, and we do not use it to train machine-learning models.

4. Your browser storage

The console uses your browser’s local storage, not cookies. Nothing there is used for analytics or advertising, and none of it is readable by another site.

  • A session token, so you stay signed in. Clearing it signs you out.
  • Interface preferences: your selected site and domain, theme, whether the navigation rail is collapsed, and which notices you have dismissed.

Because these are strictly necessary to provide a service you asked for, or are your own preferences, they do not require consent under ePrivacy rules. You can clear them at any time in your browser.

5. Who we share it with

We use a small number of service providers. Each is bound by contract to process data only on our instructions.

ProviderWhat it handles
DigitalOceanHosting, database and object storage — all of the above passes through it.
CloudflareCDN and DNS in front of our script host. Sees request metadata only.
StripeSubscription billing. Handles your payment details directly; we never see a card number.
ResendSends transactional and alert email. Sees your email address, and your name if you have set one.

We also disclose data where we are legally required to. If we receive a request from a public authority for data we hold on your behalf, we will challenge it where there are lawful grounds and disclose the minimum permissible if we must comply.

If the business is ever sold or merged, account data may transfer as part of it. You would be told before that happened, and this policy would continue to apply until replaced.

6. Where it is processed

Personal data is processed in the United States. We do not currently operate an EU region.

Where data protected by the GDPR is transferred to us, we rely on the European Commission’s Standard Contractual Clauses. The detail is in the DPA.

7. How long we keep it

DataRetention
Account and workspaceFor as long as the account is open.
After you close your accountDeleted within 30 days, unless we are required to keep something longer.
Billing and invoice recordsKept as long as tax and accounting law requires, which is longer than the account itself.
Staff-access audit logAppend-only and retained, because a security record you can quietly delete is not a security record.
Captured telemetrySet by you, from 14 days on the free plan. Enforced automatically, not by manual cleanup.

8. How it is protected

  • TLS on every public endpoint, and on database connections, verified at TLS 1.3.
  • AES-256 encryption at rest, requested explicitly on every object rather than relying on a provider default.
  • Passwords stored as scrypt hashes; secret API keys stored only as SHA-256 hashes.
  • Every record carries a tenant identifier and the API derives the tenant from your credential, so a query cannot reach another workspace.
  • Role-based access with per-site grants, so access can be narrowed to a single site.
  • Staff access to customer data is recorded in an append-only log enforced by the database itself, at the one point every administrative route passes through.

What we do not have yet

No SOC 2 or ISO 27001 certification. No multi-factor authentication on console accounts. No EU processing region. These are real gaps and we would rather you learn them here than discover them during a security review.

9. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, and withdraw consent where we rely on it. You can also complain to your local supervisory authority.

Most of this you can do yourself in the console. For anything else, email [email protected]. We will respond within one month. We do not charge for this and we will not ask you to justify the request.

10. End users of our customers

If you visited a website that uses LogClip, your session may have been recorded by the company running that site. They chose to record it, they chose what was masked, and they decide how long it is kept. We hold it for them.

Contact that company. If you contact us instead, we will not answer substantively and we will not act on the request — not to be unhelpful, but because we cannot verify who you are and we are not permitted to change or hand over their data on the instruction of someone we cannot identify. We will tell you that, and we will tell them you got in touch.

What is true regardless of how any given customer configures it:

  • Input values are masked in the page before any data is sent. The values never reach us.
  • Password fields are masked even if masking is switched off everywhere else.
  • Authorization and Cookie headers are removed, with no setting that re-enables them.
  • URL query strings are redacted before storage.
  • Global Privacy Control and Do Not Track stop recording before any of the site’s own configuration is considered — with those set, nothing is recorded and no request is made at all.
  • For visitors in the EEA, recording is gated on consent by default, determined by device time zone.

11. Changes and contact

If we change this policy materially we will tell account holders by email before it takes effect, rather than changing the date and hoping nobody notices. The version and effective date at the top always reflect the current text.

Controller: Siddi Tek LLC, 41551 Bostonian Place, Aldie, VA 20105, United States.

Privacy enquiries: [email protected]. Security reports: [email protected]. EU representative: [EU REPRESENTATIVE, IF APPOINTED].