This Privacy Policy explains how Grabdemo LLC (“grabdemo,” “we,” “us,” or “our”) handles information in the grabdemo browser extension and related grabdemo service (collectively, the “Service”).
The extension lets you record an interactive demo of a website that you choose. Please do not record a website or content unless you have the authority to do so.
Summary
The extension is inactive for recording until you select a demo type and start a recording. During an active recording, it captures the selected tab’s website content and interaction data to create a demo. It sends the recording to our service when you stop the recording and are signed in. We do not sell recording data or use it for advertising.
Information we handle
Account and authentication information
When you sign in to use the Service, our authentication provider, Clerk, processes account and authentication information, such as your account identifier and session/ authentication token. The extension uses the authenticated session to associate uploads with your account and authorize them. The extension does not collect or store your account password.
Recording content and activity
While a recording is active, the extension handles content from the selected browser tab, including:
- DOM snapshots of the recorded pages, including visible and non-visible text and HTML attributes included in the page, inlined stylesheets, images, and fonts;
- page URLs, page titles, viewport dimensions, and browser user-agent information;
- interaction events in the recorded tab, including clicks, pointer movement/hover information, scrolling, page navigation, and keyboard/input events;
- metadata about interacted-with elements, such as tag name, text, accessibility labels, link targets, CSS selectors, and coordinates; and
- text entered in text-like form fields during the recording.
Website content can contain personal, confidential, financial, health, authentication, or other sensitive information belonging to you or others. You control what you record and should avoid recording real sensitive information.
Sensitive-input protections and their limits
The extension replaces the values of password fields and fields it identifies as payment-card, CVC/CVV, or Social Security number fields with masking characters before the recording is stored or uploaded. Those values are not intentionally included in the recording payload.
This protection is heuristic, not a guarantee: a sensitive value entered into another field, embedded elsewhere on a page, present in page text or attributes, or captured in an image may still be recorded. Do not rely on masking as the sole protection for sensitive information.
If the Service offers a visual blur or redaction feature, it may only hide content in the viewer. Unless the feature expressly says it permanently deletes the underlying data, the original content can remain in the stored recording. Delete the recording to request removal of the underlying captured content.
Local recording buffer
Before a successful upload, the extension stores the active recording session and recording data locally in the browser. Session state is stored using chrome.storage.local; recording events, page snapshots, and steps are stored in the extension’s IndexedDB storage. This buffer persists across page navigations and browser extension service-worker restarts. If an upload fails or you are not signed in when recording stops, the buffer may remain locally for a later retry until it uploads successfully. The extension does not currently provide a control to discard an unuploaded recording; to remove one, remove the extension or clear its browser storage data.
How we collect information
The extension has code that loads on websites so it can begin recording the tab you select, including after a recorded page navigates. It does not begin DOM or interaction capture until you affirmatively start a recording. It does not capture content from other tabs as part of a recording.
How we use information
We use the information described above only to:
- authenticate you and associate recordings with your account;
- create, upload, store, replay, edit, and share the demos you request;
- provide customer support or investigate security, abuse, or technical problems when permitted by law; and
- comply with applicable legal obligations and enforce our agreements.
We do not sell recording data. We do not use or transfer it for personalized, retargeted, or interest-based advertising; creditworthiness or lending decisions; or any purpose unrelated to providing or improving the Service’s user-facing demo-recording features.
No one on our team accesses your recording content except to provide support you request, to investigate security or abuse, or to comply with law.
How and with whom we share information
We share information only as follows:
- Service providers. We use Clerk for authentication, Cloudflare R2 for recording-asset storage, and Render to host and operate the Service. These providers process information on our behalf to provide the Service.
- People you authorize. A demo is private to your account unless you share it. If you create a share link, embed, or otherwise grant access, the recording content is available to the people who can access that link, embed, or authorization. Share links may be accessible to anyone with the link. If enabled: You can protect share links with a password or restrict access to specified viewers.
- Legal, safety, and business transfers. We may disclose information when required by law or reasonably necessary to protect rights, safety, security, and the Service, or in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, as permitted by law.
We do not otherwise share, rent, or sell recording content.
Retention and deletion
We retain recording content while your account keeps the recording, then delete it according to our deletion process. You may delete a demo through the demo’s menu on your dashboard and choose Delete. Deleted recordings and their associated assets are removed from active systems within 30 days, subject to limited backup, security, legal, and dispute-resolution retention. To delete your account and associated data, contact us; we will delete or de-identify it within 60 days, subject to the exceptions below.
The extension does not currently provide a button to discard an unuploaded recording. To remove an unuploaded local recording, remove the extension or clear its browser storage data. A buffer is otherwise cleared automatically once its recording uploads successfully.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. Recording data is transmitted using HTTPS/TLS and is stored using AES-256 encryption at rest provided by our storage and database providers. No method of transmission or storage is completely secure.
Your choices and rights
You can choose not to start a recording, stop a recording, delete demos, and control who receives links to shared demos. Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection. To exercise applicable rights, contact us using the details below. We may need to verify your request.
Children’s privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under the applicable minimum age. If you believe a child provided personal information to us, contact us.
Changes to this policy
We may update this policy from time to time. We will post the updated version and change the “Last updated” date. Where required, we will provide additional notice or obtain consent.
Contact us
Chrome Web Store Limited Use disclosure
grabdemo’s collection, use, and transfer of user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.