UXSense

UXSense Privacy Policy

Last updated: August 1, 2026 · Under final legal review — the substance below reflects how the service actually operates.

This policy explains how Hashbrown Interactive Inc., doing business as UXSense ("UXSense", "we"), handles personal data. UXSense plays two distinct roles, and your rights differ by role:

  1. Controller — for data about our own customers and site visitors (accounts, billing, support, our websites).
  2. Processor — for end-user session data that our customers collect from their applications using the UXSense recorder or connected replay tools. For that data, our customer is the controller; if you are an end user of a customer's application, direct requests to that company. Our processing is governed by our agreement with them (including a Data Processing Addendum where applicable).

1. Data we process as a processor (session data)

When a customer deploys the UXSense recorder (or connects PostHog or Sentry), we process, on the customer's behalf:

By design, the UXSense recorder does not capture the values typed into form fields. Customers are responsible for masking any additional sensitive on-screen content and for providing notices and obtaining consents from their end users.

Session recordings are retained for a period set by the customer's plan (e.g. 30 days on free tiers, 90 days on paid tiers) and then deleted. Derived aggregates and reports may be retained longer; they describe behavior patterns rather than identified individuals.

2. Data we collect as a controller

3. How we use data

To provide, secure, and improve the Service; to compute billing (e.g. counting the distinct pull-request authors whose PRs received checks); to send transactional email (reports ready, billing notices, seat prompts); to respond to support; and to comply with law. We do not sell personal data, and we do not use customer session data to train generalized machine-learning models. Analytical processing of session data (for example, LLM-assisted report narration) operates under our instructions with providers bound by data-processing terms, and outputs are gated so that numeric claims come from computed metrics, not model generation.

4. Subprocessors and service providers

We use the following providers to operate the Service:

ProviderPurposeData touched
SupabaseDatabase, authentication, file storageAll service data incl. session recordings
RenderApplication and worker hostingAll service data in transit/processing
AnthropicLLM analysis for report narration and PR-scope extractionSession-derived excerpts, PR titles/descriptions
StripePayments and subscription managementBilling data (card data held by Stripe)
Postmark (ActiveCampaign)Transactional emailNames, emails, report/billing summaries
GitHubSource-control integration (UXSense GitHub App)Repository metadata, check results
PostHogProduct analytics on our own app and websiteUsage events and page views from our properties (never customer session recordings)

Customer-connected tools (PostHog, Sentry, Vercel, Render deploy hooks, Slack) act on the customer's own accounts and are not our subprocessors. Note that PostHog appears in both roles: connecting your PostHog account as a replay source uses your account under your terms, which is separate from our own use of PostHog to analyze our product. This table is the current subprocessor list; we provide notice of additions as required by our data processing terms.

5. International transfers

Data is hosted in United States data centers operated by our hosting subprocessors (Supabase, Render). Where personal data is transferred across borders, we rely on appropriate safeguards (e.g. Standard Contractual Clauses with subprocessors, where applicable).

6. Security

We use industry-standard measures: encryption in transit, encrypted storage, role-based access controls with row-level security, scoped API keys (stored hashed), webhook signature verification, and least-privilege service credentials. No system is perfectly secure; we will notify affected customers of a personal-data breach without undue delay as required by law and the DPA.

7. Retention

8. Your rights

If you are our customer or a visitor (controller data): depending on your jurisdiction you may have rights to access, correct, delete, port, or object to processing of your personal data — contact hello@uxsense.ai. If you are an end user of a customer's application, contact that company; we will assist them in fulfilling verified requests (access, deletion) as their processor.

9. Cookies

Our own properties use strictly necessary cookies for authentication, and product-analytics identifiers (PostHog) on our app and marketing site. The UXSense recorder sets no cross-site tracking cookies in customer applications.

10. Children

The Service is not directed to children under 16, and customers may not knowingly use it to record applications directed primarily at children where prohibited.

11. Changes and contact

We will post changes here with an updated effective date and notify customers of material changes. Contact: hello@uxsense.ai · Hashbrown Interactive Inc., 8404 Aberdeen Road, Coldstream, BC V1B 2J6, Canada.