Privacy Policy
ClipInbox is built for user-triggered bug reports with browser context, not always-on session replay.
Scope
This policy describes the current ClipInbox website, app, widget, support, billing, and operational systems. It should be read together with the product privacy model.
| Last updated | July 16, 2026 |
| Controller contact | hello@clipinbox.dev |
| Security contact | security@clipinbox.dev |
| Regulated data | ClipInbox is not yet offered for health, financial, government, child-directed, or other regulated workloads that require a signed DPA, BAA, SCC package, or formal compliance program. We have not finalized a DPA yet. |
Data We Process
ClipInbox only needs enough data to provide accounts, billing, support, and developer-ready bug reports.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email address, workspace membership, role, login and verification state. | Authentication, access control, support, and account recovery. |
| Billing data | Plan, subscription status, provider customer and subscription IDs, webhook delivery state. | Checkout, access decisions, support, refunds, and billing lifecycle handling. |
| Report data | Reporter note, page path, browser/device facts, console signals, failed request metadata, request IDs, screenshot or clip if approved. | Give the customer enough context to reproduce and fix a reported bug. |
| Operational data | Request logs, metrics, traces, health checks, backup status, alert delivery, security logs. | Operate, secure, troubleshoot, and recover the service. |
| Support data | Emails and context you send to support or security contacts. | Respond to questions, incidents, abuse reports, and account recovery requests. |
| Website analytics | Cookieless pageview and performance data from the marketing site and app. | Understand whether the site works and which pages are useful. |
Report Capture Boundary
ClipInbox defaults are intentionally bounded. Customers can configure capture policies per project environment, but the product starts from a narrow report packet rather than a replay timeline.
| Inputs and secrets | No input values, cookies, auth headers, CSRF tokens, or browser storage values by default. |
| Bodies | No request bodies or response bodies by default. |
| Page snapshots | No full DOM snapshots and no always-on background behavior outside the report session. |
| Review | The reporter reviews the report before submitting it. |
Retention And Deletion
Report retention is plan and environment based. Operational records are kept only as long as useful for service operation, security, billing, or legal obligations.
| Reports | Reports and approved media expire according to the project or environment retention setting. |
| Backups | SQLite and analytics backups may retain data after primary deletion until backup rotation removes older backup objects. |
| Billing records | Subscription and webhook records may be retained for accounting, payment support, fraud prevention, and auditability. |
| Deletion/export requests | Workspace owners or verified requesters can contact hello@clipinbox.dev. Self-service export and deletion are not yet product features. |
Subprocessors And Infrastructure
ClipInbox is operated on EU-oriented infrastructure where practical for the current early-stage deployment.
| Compute and storage | Servers, object storage, backups, DNS, and CDN used to run the service. |
| Transactional email for login codes, verification, invites, alerts, and support. | |
| Payments | Hosted checkout, subscriptions, invoices, taxes, and payment methods are handled by the billing provider. |
| Analytics and monitoring | Cookieless analytics, request metrics, traces, uptime probes, and alerting used to operate the service. |
Your Choices
Contact us if you need access, correction, deletion, export, or account recovery. We will verify requester authority before changing workspace data.
| Privacy and support | hello@clipinbox.dev |
| Security and abuse | security@clipinbox.dev |
| Product privacy model | /privacy/ |