Privacy

This page describes how Hoot Lens, a Parallel Platforms product, handles information on the public pages of hootlens.com.

Session recording on this website

We use Hoot Lens, our own product, to see how visitors use the public pages of hootlens.com: the home page, the developer FAQ, the example workspace and this page. We use what we learn to improve those pages and the sign-up flow. Signed-in workspaces, shared replay and heatmap links, invitation pages and install links are never recorded.

  • What is recorded: Page text is recorded with email addresses, phone numbers, card-like numbers and long digit runs removed. Form inputs are masked.
  • Where visits come from: the name of the referring site, campaign tags and the name of an ad network from the landing address (never the ad click ID), the name of an in-app browser such as Facebook, and the country and region (state or province) of the visitor. Location is looked up from the connection and the address is not stored.
  • Consent: Visitors are recorded on load, except in European Economic Area, United Kingdom, Switzerland, Washington State, Nevada, Connecticut, where recording starts only after the visitor agrees. Global Privacy Control and Do Not Track stop recording.
  • Never recorded: password fields, payment card fields, one-time-code fields, anything the site marks private, text after # in page addresses, the values typed into form fields.
  • Page addresses: query strings are removed.
  • Share of visits: 100%.
  • Retention: recordings are deleted after 30 days.

In the United States, recording is on by default for most visitors. Visitors in the European Economic Area, the United Kingdom, Switzerland, Washington, Nevada and Connecticut, and visitors whose location we cannot tell, are asked first, and nothing is recorded until they agree.

You can turn recording off or on at any time with the Session recording control in the footer of each page. Global Privacy Control and Do Not Track are honored automatically.

To show where visits come from, we record the name of the site that referred a visit, campaign tags in the landing address, the name of an ad network when an ad click ID is in the address (never the ID itself), the name of an in-app browser such as Facebook, and the visitor's country and region. Country and region are looked up from the connection when the visit starts and then discarded: the IP address, the city and coordinates are never stored. Visitors who send Global Privacy Control or Do Not Track are not recorded or located.

IP geolocation by DB-IP.

Recordings are stored with Google Cloud. Aggregated counts and statistics, never recordings, may be sent to OpenAI to write explanations of what the data shows.