Privacy Policy
Last updated: 2026-07-20 — draft pending legal review
Who's who
logcohort is a session replay service. Three parties matter on this page:
- Customers — people or companies with a logcohort account who install our snippet on their website.
- Visitors — people who browse a website where a customer installed logcohort.
- Us — the logcohort service. Payment processing is handled by our billing partner, [SELLER-COMPANY-TITLE] (see seller details).
For visitor data, the customer is the data controller and logcohort is a processor: we record what the customer's site configuration tells us to record, on the customer's behalf. Customers are responsible for the legal basis (e.g. consent banners) for recording on their own sites.
What the recorder collects from visitors
- Screen activity — DOM changes, clicks, scrolls, and navigation, so the session can be replayed.
- Text typed into inputs is masked in the visitor's browser before transmission. Masked values are transmitted and stored as
****. Masking is on by default; customers can relax it per project for non-sensitive fields. - Console output and errors of the customer's own page.
- Network request metadata — method, URL, status code, duration. Never request or response bodies.
- Identity, only if the customer provides it — a customer's app may attach a user id, email, and name to a session via the identify call. We never collect these on our own.
- Technical basics — page URL, user agent, viewport size, and an anonymous per-tab session id.
Recording only works from origins on the customer's allowlist; a leaked project key cannot record from other sites.
Where data lives and for how long
- Recording metadata and search indexes: our database (EU-hosted server).
- Recording event streams: Cloudflare R2 object storage.
- Retention follows the customer's plan — 7 days (Free), 30 days (Team), 90 days (Scale). Recordings past retention are deleted. Customers can delete recordings or entire projects at any time, which deletes the underlying data.
Account data (customers)
For customer accounts we store: email, name, password hash or social sign-in identifier, organization/project settings, and emails we send you (via Resend, our email provider). Payment card details are collected and processed by the payment provider — we never see or store card numbers.
This website records itself
logcohort.com uses logcohort — visits to this site are recorded under the same rules described above (inputs masked, no bodies). We use these recordings to improve the site.
What we don't do
- No selling or sharing of recordings or personal data with third parties beyond the processors named above.
- No advertising trackers or third-party analytics on this site.
- No cross-site profiles of visitors.
Your rights
Under GDPR/KVKK you can request access, correction, or deletion of your data. Customers: from your dashboard or by email. Visitors: contact the website you visited (the controller) — we act on their instruction — or email us and we'll help route the request. Contact:[CONTACT-EMAIL].