Privacy

Collect the context a report needs, not private browser values.

IssueProbe uses fixed browser evidence fields, explicit screenshot approval, exact website origins, and plan-based screenshot retention.

Account and website data

IssueProbe stores the account email for authentication. It stores website names, exact origins, repository locations, public deploy keys, evidence category settings, report records, review decisions, and account activity.

Email is not a channel for visitor reports or visitor replies.

Visitor reports

A report contains the visitor's problem or suggestion, the page facts supplied by the widget, and the evidence categories that the website owner enabled. Customer text is untrusted and appears as escaped text in owner views.

Browser evidence

A visitor-approved screenshot can contain visible page data. The visitor sees a preview and can remove it before submission. Console and request evidence use bounded metadata and text redaction.

Cookie, form, and local-storage values are never collected. Each browser-state item contains only a name, a presence state, and a size. Read the exact widget privacy rules.

Repository access

Each website uses one separate SSH deploy key. The owner adds the public key with read-only access. IssueProbe does not ask for a Git password, personal access key, general SSH key, or private deploy key.

Retention

Free keeps screenshot artifacts for seven days. Pro keeps screenshot artifacts for thirty days. IssueProbe removes expired screenshot bytes automatically and retries a failed removal. Report and review records remain part of the owner account record.

Human and agent access

A human owner can create and revoke API credentials. An agent needs owner authorization, narrow scopes, and an expiry. Each agent action appears in customer-safe account activity.

Billing

Stripe-hosted pages collect payment details for Pro. IssueProbe does not receive card data. A Free account needs no card and no Stripe customer.

Questions and account requests

Use the authenticated account surfaces for account actions. The first release does not use email for visitor report intake or replies.