Legal & Compliance
Privacy Policy
Last updated: July 5, 2026
At Workflow Replay (“we,” “our,” or “us”), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our Chrome Extension (the “Extension”), our Next.js web application (the “Web App”), and our related services (collectively, the “Services”).
Please read this policy carefully. By installing the Extension or accessing our Web App, you consent to the collection and use of information as described herein.
1. Information We Collect
Workflow Replay records your web browsing interactions to automatically generate visual, step-by-step documentation and replayable guides. Depending on how you interact with our Services, we may collect the following categories of information:
A. Recording & Interaction Data (Extension)
When you actively initiate a recording session, the Extension captures the following data from the target web browser tab:
- User Action Events: Clicks, keyboard input, scrolls, drag-and-drops, form submissions, and page navigation events.
- Document Object Model (DOM) States: The structure, layout, and text content of the page (captured via DOM capture tools like rrweb) necessary to recreate the page layout for replay.
- Screenshots: Full-page or viewport screenshots captured during interactions to provide visual context for each step.
- Metadata: Webpage URLs, tab page titles, and timestamps of captured events.
B. Account & Authentication Data
If you sign up or log in to sync your workflows across devices or collaborate with team workspaces:
- Google Sign-In Account Information: We collect your name, email address, and profile photo URL via Google OAuth to create and manage your account.
- Authentication Tokens: Securely stored credentials to maintain your logged-in session.
C. Workspace & SOP Configurations
Custom descriptions, titles, step orders, and branding/watermarks you add to your workflows, as well as team names, roles, member directories, and permissions for collaboration.
D. Billing Data
If you subscribe to our Pro or Pro Limited plans, billing transactions are processed directly by our payment processor, Stripe. We do not collect or store your complete credit card numbers or banking credentials.
2. How We Store Your Data
We store your data using a hybrid structure designed to maximize performance and privacy:
- Local On-Device Storage (IndexedDB): All captured workflow events, screenshots, and temporary states are saved locally on your device in your browser's IndexedDB. We request
unlimitedStoragepermissions to prevent the browser from automatically deleting these visual assets. - Extension Configuration Storage: Small preference settings and login tokens are stored locally via
chrome.storage.local. - Cloud Hosting (Firestore & Storage): If you choose to sign in and sync your workflows, your data (including event streams, screenshots, and metadata) is securely transmitted and stored in our database (Google Cloud Firebase Firestore) and file storage (Google Cloud Storage).
3. How We Use Your Information
We use the data we collect solely to provide and improve the core functionalities of the Services, including:
- Generating interactive, step-by-step visual guides from your recorded paths.
- Powering the Replay-to-Refresh engine to re-run your steps on a webpage and capture updated screenshots when layouts change.
- Enabling read-only workflow sharing links (
/s/[shareId]) for help centers, customer support, or documentation. - Managing user permissions and workspace membership inside collaborative teams.
- Preventing service abuse, troubleshooting software bugs, and responding to support queries.
4. User Controls & Privacy Protection
We build privacy-preserving features directly into our application:
- In-App Redaction (Manual Blur): The Web App includes a redaction tool allowing you to permanently blur out passwords, personal identifying information (PII), or private financial figures on screenshots before they are shared or synced.
- Local-Only Mode: You are not required to sign in or sync workflows. You can use the Extension to record, edit, and export workflows entirely locally (e.g., as offline HTML or PDF exports), meaning no data leaves your machine.
- Data Deletion: You can delete individual workflows or workspace items at any time. Deleting a synced workflow removes it permanently from our Cloud Storage and Firestore databases.
- Account Deletion: You may delete your account from your workspace dashboard, which wipes your user profile, synced sessions, and team memberships.
5. Data Sharing & Third Parties
We respect your data and never sell, rent, or trade your personal information or captured workflows to third-party advertisers or data brokers.
We only share data with the following essential services to maintain functionality:
- Google Cloud Platform / Firebase: To securely authenticate users (Google OAuth) and host the application database and assets.
- Stripe: To process subscriptions and billing transactions securely.
- Legal Compliance: We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
6. Children's Privacy
Our Services are not directed to children under the age of 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately to have it deleted.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will notify you of any material changes by posting the new policy on this page, updating the “Last Updated” date at the top, and, if you have an active account, sending a notification via the dashboard or email.