Privacy Policy
Effective date: July 15, 2026
1. Who we are
DemoVine is a product of PressureForge, registered in Poland.
This Privacy Policy describes how we collect, use, and protect personal data when you use DemoVine, including the Chrome browser extension, web app at app.demovine.com, demo viewer at view.demovine.com, landing page at demovine.com, and our API at api.demovine.com.
For privacy questions or requests, contact us at support@demovine.com.
2. Summary
- We collect account information and the content you deliberately record when using DemoVine.
- Recordings are captured only when you start a recording session.
- Form input values are masked in DOM snapshots, but screenshots and screen recordings may show whatever is visible on screen.
- We use cookieless analytics (Umami) and do not run advertising or ad tracking.
- We do not sell your personal data.
- Your data is hosted in the United States, with safeguards for users in the EU and UK.
- To exercise your privacy rights, email support@demovine.com.
3. Data we collect from account holders
If you create a DemoVine account, we collect and store:
- Identifiers: your email address and name.
- Credentials: a hashed password if you sign up with email and password, or an OAuth token if you sign in with Google. We never see or store your Google password.
- Preferences and settings: profile preferences, onboarding state, and in-extension settings such as viewport and autocapture options.
- Plan and usage data: your plan (for example, free or Beta Pro), and usage counters such as the number of demos, scenes, and storage used.
- Support communications: messages you send us when you contact support.
4. Content you record
When you record a demo, we collect the content you choose to capture. This happens only when you start a recording session — we do not record your browsing outside of that.
For each scene in a demo, we may collect:
- A DOM snapshot of the recorded page (one snapshot per scene, not continuous recording). Form input values are masked in these snapshots.
- PNG screenshots of the visible browser tab, including manual captures, thumbnails, and patches for iframes or canvas elements.
- Screen recordings (WebM or MP4) if you choose to record your screen through your browser's screen-share picker.
- Click and hotspot metadata: coordinates, CSS selectors, element text (up to 50 characters), and action type.
- The URL, viewport size, and scroll position of recorded pages.
- Cross-origin stylesheets fetched and inlined so scenes render accurately.
Important: input masking applies to DOM snapshots only. Screenshots and screen recordings show whatever is visually on screen, including typed text if it is visible.
You are responsible for ensuring you have the right to record the content you capture and that your recordings do not expose other people's personal data without a lawful basis. For content contained inside your recordings, you act as the data controller and DemoVine acts as a processor storing it on your behalf.
5. The browser extension specifically
The DemoVine Chrome extension collects:
- User activity: which elements you click during a recording session (click coordinates, CSS selector, and element text) to generate interactive hotspots.
- Website content: a serialised DOM snapshot of the recorded page (with form inputs masked) and a PNG screenshot of the tab viewport.
The extension does not collect:
- Your browsing history outside an active recording session.
- Cookies, localStorage, or sessionStorage from recorded pages.
- Keystrokes (form inputs are masked in DOM snapshots).
The extension stores authentication tokens, a cached user profile, recording state, and preferences locally in your browser via chrome.storage.local. All extension code is bundled at build time — no remote code is fetched or executed at runtime.
6. Demo viewers
People who open a shared demo link on view.demovine.com do not need a DemoVine account.
When someone views a demo, we may process:
- Standard server logs (IP address, browser user agent, and timestamp) for security and operations.
- Password verification data if the demo is password-protected (the password check happens on our servers).
- Anonymous, cookieless page analytics via Umami.
We do not use ad tracking or cross-site profiling for demo viewers.
7. How we use data
We use personal data to:
- Provide, operate, and maintain DemoVine.
- Authenticate you and manage your account.
- Enforce plan limits and usage quotas.
- Send transactional email (for example, password resets and account notices).
- Respond to support requests.
- Monitor errors, security incidents, and abuse.
- Improve the product using aggregate, anonymous analytics.
We do not use your data for advertising, sell your data to third parties, or train AI models on your content.
8. Legal bases (GDPR)
If you are in the European Economic Area or the UK, we process personal data on the following legal bases:
- Contract performance: to provide the DemoVine service you signed up for.
- Legitimate interests: to secure the service, prevent abuse, and understand aggregate product usage — balanced against your rights.
- Consent: where required, for example optional marketing communications if we offer them in the future.
- Legal obligations: where we must retain or disclose data to comply with applicable law.
9. Service providers (subprocessors)
We use trusted service providers to operate DemoVine. They process data only on our instructions and for the purposes described in this policy:
- Railway — backend API hosting and database storage (United States).
- Vercel — frontend hosting for the web app, demo viewer, and landing page (United States).
- Resend — delivery of transactional email (for example, password resets).
- Stripe — payment processing if you subscribe to a paid plan such as Beta Pro. We do not store your full card number. See Stripe's Privacy Policy.
- Umami — cookieless, aggregate website analytics.
- Sentry — error and performance monitoring.
10. International transfers
Your data is hosted in the United States. If you are located in the EEA or UK, your data is transferred outside your region to provide the service.
We rely on appropriate safeguards for these transfers, including Standard Contractual Clauses approved by the European Commission, and where applicable, the EU–US Data Privacy Framework for providers certified under that framework.
11. Retention and deletion
- Account data is kept while your account is active.
- Recordings and demos are kept until you delete them or delete your account.
- When you delete your account, we remove your content within 30 days, except for minimal records we are required to keep by law (for example, billing records).
- Backup copies are removed on a rolling schedule and are not restored except where required for disaster recovery.
12. Your rights
If you are in the EEA, UK, or another jurisdiction with similar privacy rights, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email support@demovine.com. We will respond within the time required by applicable law.
You also have the right to lodge a complaint with a supervisory authority. If you are in Poland, you may contact the President of the Personal Data Protection Office (UODO). If you are in another EU country, you may contact your local data protection authority.
13. Cookies and analytics
DemoVine uses cookies and browser local storage only for strictly necessary purposes, such as keeping you signed in and maintaining session state.
We use Umami for analytics. Umami is cookieless and does not build personal profiles — it collects only aggregate statistics about page visits.
We do not use advertising cookies or third-party ad trackers. Based on our current setup, a cookie consent banner is not required for analytics.
14. Security
We take reasonable measures to protect your data, including:
- TLS encryption for data in transit.
- Encryption at rest where supported by our infrastructure provider.
- Access controls limiting who can access production systems.
- Masked form inputs in DOM snapshots by default.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
15. Children
DemoVine is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at support@demovine.com and we will delete it.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the revised policy at demovine.com/privacy and update the effective date at the top of this page. For material changes, we will notify you by email or through an in-app notice.
17. Contact
For privacy questions, requests, or complaints:
Email: support@demovine.com