UXSense Privacy Policy
Last updated: August 1, 2026 · Under final legal review — the substance below reflects how the service actually operates.
This policy explains how Hashbrown Interactive Inc., doing business as UXSense ("UXSense", "we"), handles personal data. UXSense plays two distinct roles, and your rights differ by role:
- Controller — for data about our own customers and site visitors (accounts, billing, support, our websites).
- Processor — for end-user session data that our customers collect from their applications using the UXSense recorder or connected replay tools. For that data, our customer is the controller; if you are an end user of a customer's application, direct requests to that company. Our processing is governed by our agreement with them (including a Data Processing Addendum where applicable).
1. Data we process as a processor (session data)
When a customer deploys the UXSense recorder (or connects PostHog or Sentry), we process, on the customer's behalf:
- Session replay events: DOM structure and mutations, clicks, scrolls, navigation, viewport information, and page URLs from the customer's application.
- Technical metadata: user agent, timestamps, and a per-session identifier generated by the recorder (not a persistent cross-site identifier).
- Derived behavioral data: interaction weights, goal-completion paths, and similar aggregates computed from sessions (the "Behavioral Load Map"), plus analytical reports.
By design, the UXSense recorder does not capture the values typed into form fields. Customers are responsible for masking any additional sensitive on-screen content and for providing notices and obtaining consents from their end users.
Session recordings are retained for a period set by the customer's plan (e.g. 30 days on free tiers, 90 days on paid tiers) and then deleted. Derived aggregates and reports may be retained longer; they describe behavior patterns rather than identified individuals.
2. Data we collect as a controller
- Account data: name, email, password hash, organization and workspace names, role.
- Billing data: plan, subscription state, and invoices. Payment card details are collected and stored by Stripe, not by us; we store a customer identifier and card metadata (brand, last four digits).
- Integration data: tokens and configuration for services you connect (GitHub App installation ids, PostHog/Sentry credentials you provide, Slack webhook URLs), used solely to operate those integrations.
- Repository metadata (Drift): pull-request titles/descriptions, branch names, commit SHAs, author usernames, and build manifests (component names — not source code bodies).
- Usage and log data: product analytics on our own properties, server logs, and diagnostic records.
- Communications: support requests and emails.
3. How we use data
To provide, secure, and improve the Service; to compute billing (e.g. counting the distinct pull-request authors whose PRs received checks); to send transactional email (reports ready, billing notices, seat prompts); to respond to support; and to comply with law. We do not sell personal data, and we do not use customer session data to train generalized machine-learning models. Analytical processing of session data (for example, LLM-assisted report narration) operates under our instructions with providers bound by data-processing terms, and outputs are gated so that numeric claims come from computed metrics, not model generation.
4. Subprocessors and service providers
We use the following providers to operate the Service:
| Provider | Purpose | Data touched |
|---|---|---|
| Supabase | Database, authentication, file storage | All service data incl. session recordings |
| Render | Application and worker hosting | All service data in transit/processing |
| Anthropic | LLM analysis for report narration and PR-scope extraction | Session-derived excerpts, PR titles/descriptions |
| Stripe | Payments and subscription management | Billing data (card data held by Stripe) |
| Postmark (ActiveCampaign) | Transactional email | Names, emails, report/billing summaries |
| GitHub | Source-control integration (UXSense GitHub App) | Repository metadata, check results |
| PostHog | Product analytics on our own app and website | Usage events and page views from our properties (never customer session recordings) |
Customer-connected tools (PostHog, Sentry, Vercel, Render deploy hooks, Slack) act on the customer's own accounts and are not our subprocessors. Note that PostHog appears in both roles: connecting your PostHog account as a replay source uses your account under your terms, which is separate from our own use of PostHog to analyze our product. This table is the current subprocessor list; we provide notice of additions as required by our data processing terms.
5. International transfers
Data is hosted in United States data centers operated by our hosting subprocessors (Supabase, Render). Where personal data is transferred across borders, we rely on appropriate safeguards (e.g. Standard Contractual Clauses with subprocessors, where applicable).
6. Security
We use industry-standard measures: encryption in transit, encrypted storage, role-based access controls with row-level security, scoped API keys (stored hashed), webhook signature verification, and least-privilege service credentials. No system is perfectly secure; we will notify affected customers of a personal-data breach without undue delay as required by law and the DPA.
7. Retention
- Session recordings: per-plan windows (see §1), enforced by automated deletion jobs covering both database records and stored replay files.
- Account and billing records: for the life of the account and as required for tax/legal purposes thereafter.
- Backups: rotate on a fixed schedule; deleted data leaves backups within 35 days.
8. Your rights
If you are our customer or a visitor (controller data): depending on your jurisdiction you may have rights to access, correct, delete, port, or object to processing of your personal data — contact hello@uxsense.ai. If you are an end user of a customer's application, contact that company; we will assist them in fulfilling verified requests (access, deletion) as their processor.
9. Cookies
Our own properties use strictly necessary cookies for authentication, and product-analytics identifiers (PostHog) on our app and marketing site. The UXSense recorder sets no cross-site tracking cookies in customer applications.
10. Children
The Service is not directed to children under 16, and customers may not knowingly use it to record applications directed primarily at children where prohibited.
11. Changes and contact
We will post changes here with an updated effective date and notify customers of material changes. Contact: hello@uxsense.ai · Hashbrown Interactive Inc., 8404 Aberdeen Road, Coldstream, BC V1B 2J6, Canada.