Widget privacy

The evidence shape is fixed before a website enables it.

A website owner can enable or disable a category. No setting can add a field or enable a cookie, form, or local-storage value.

Screenshot

  • The visitor starts the capture through a visible action.
  • The visitor sees a preview before inclusion.
  • The visitor gives explicit inclusion approval.
  • The visitor can remove the image before submission.
  • Only PNG, JPEG, and WebP pass type and size checks.

Console errors and warnings

  • At most fifty bounded items.
  • Error or warning level only.
  • A safe message, optional source path and location, and time.
  • Client and server text redaction.

Failed or slow request metadata

  • At most fifty bounded items.
  • HTTP method and path without query values.
  • Optional status, duration, and time.
  • No origin, credential, header, fragment, query value, request body, or response body.

Metadata-only browser state

  • Cookie name, presence state, and size.
  • Form-field name, presence state, and size.
  • Local-storage name, presence state, and size.
  • No cookie, form, or local-storage value.

Values are never available.

This rule applies to Free and Pro. A website setting cannot change it.

Read the evidence guide

Submission controls

The widget shows the enabled categories before submission. Screenshot consent must match the presence of a screenshot exactly. The receipt says only, “We received your report.”

Origin control

The public widget key identifies one website but grants no account access. The server also requires the exact verified website origin for configuration and report submission.

Form reset

After the visitor selects Done, the widget clears the report text, screenshot, approval state, attempt identifier, and evidence review state.