Consent & privacy
Govern how this workspace collects, masks, retains and erases personal data. Policies enforce server-side; changes here update the rules applied at capture and ingest.
Consent policy
Categories presented in the consent banner and how consent is requested. Strictly-necessary tracking is always on.
Data retention
How long each data stream is kept before automatic deletion. Streams with a legal floor cannot be set below their minimum.
Retention depth & auto-anonymize
The resolved per-stream matrix behind the windows above — legal floor, plan ceiling and which windows the server clamped — plus the recurring anonymize schedule for the streams that carry raw touchpoints. Every change previews its blast-radius, then confirms; the same operations are available to AI agents through the audited execute fabric.
PII masking
Choose how much of a recorded session is hidden, and add element-level rules for specific fields. Raw values are dropped before storage.
Masking profile
strictPrivate by default: sensitive content is redacted in the browser before it leaves the device. PII scrubbing is confirmed server-side.
What gets masked
8 of 8 categories redacted- Cards and credentialsLocked
Card numbers, CVV, passwords and tokens.
Redacted - Email addresses
Emails typed or rendered in the DOM.
Redacted - Phone numbers
Phone numbers in fields and body text.
Redacted - Input fields
Values typed into forms, textareas and selects.
Redacted - Page text
Text content rendered in the page body.
Redacted - Images
Photos and graphics loaded by the page.
Redacted - Audio and video
Media elements embedded in the session.
Redacted - User avatars
Profile images tied to the account.
Redacted
Data subject requests
Handle access and erasure requests under GDPR. Each request is tracked to its 30-day legal deadline.
Recent requests
DSAR requests & SLA
Outstanding access, erasure and portability requests with their 30-day legal SLA clock (up to 45 days).
Data portability export
Package a resolved subject's data into a portable artifact (JSON, CSV, or zipped CSV) under the right to data portability (GDPR art. 20). The export runs as an audited, AI-operable job; review the manifest, then download the signed artifact.
AI-operable data governance
The same consent banner, per-stream retention and data-subject controls — operable by you here, and by AI agents through the audited execute fabric. Every change previews its blast-radius, then confirms.
Consent banner
Per-region cookie/consent banner. Analytics, replay and ad categories are denied by default — no pre-ticked tracking.
Per-stream retention
Set how long a single data stream is kept, independently of the others (replay can be shorter than analytics).
Data-subject requests
Export a subject's data bundle (access request) or erase it (right to be forgotten). Erasure runs as a tracked, irreversible job.