ReproSlate

Privacy Policy

LEGAL REVIEW PENDING. ReproSlate is operated by Shift Warden LLC. This describes implemented product behavior. Document version: 2026-09-11. [ATTORNEY: roles (controller vs processor), lawful basis, international transfers, retention schedules, and DSR process.] This page does not claim ReproSlate LLC, a DBA, or a trademark registration.

Screenshots can contain emails, customer data, source code, internal URLs, or tokens. Upload only what you are allowed to share with an AI provider. ReproSlate does not claim that processing is fully local, that your screenshot never leaves your device, or that the AI provider has zero data retention.

ReproSlate storage

ReproSlate does not intentionally keep a screenshot archive, OCR/text extracted from images, generated ticket bodies, user context, or filenames. Screenshot bytes are held in server memory for the request, re-encoded, sent to the AI provider for that generation, then discarded.

Signed cookies identify an anonymous visitor (bugshot_aid), a rate-limit helper (bugshot_rl), and an operator admin session. They do not contain screenshot data.

AI processing

During generation, resized screenshot data and your optional context sentence are sent to the configured AI provider (this build: OpenAI when BUGSHOT_PROVIDER=openai). The browser does not call the vendor directly. Provider accounts may retain API traffic for abuse monitoring. Zero Data Retention is not claimed unless the operator has independently verified it on the provider account.

Payments and legal acceptance records

Stripe processes checkout, receipts, and (when used) customer email. ReproSlate stores Stripe customer ids, session ids, event ids, and entitlement balances needed to grant credits. Card data is handled by Stripe, not ReproSlate. Payment email is not used for marketing. Checkout clickwrap records store Terms version, Privacy version, Refund Policy version, timestamp, selected pack or subscription, and Stripe checkout/customer/session references. Those records do not include screenshots, OCR, or generated ticket bodies.

Support

If you submit a support case, ReproSlate stores your description, expected result, what happened, optional email, category, status, and privacy-safe diagnostics (app version, provider/model, image count, size/latency buckets, outcome, failure category, anonymous identity id, example id, credit source, browser family). Screenshots and tickets are not attached. Support email is used for that case and status notices only, not marketing.

Analytics

Coarse event names and numbers only (visit, paste/upload, example used, generation attempt/success/failure, edits, copy/export, allowance exhausted, checkout, credit source, support opened/submitted, refund requested, repeat use). No screenshots, OCR, ticket bodies, or user context in analytics.

Marketing email

ReproSlate does not operate a marketing list in this version. Support and Stripe receipt addresses are not repurposed for marketing. Any future marketing list would require a separate explicit opt-in.

Secrets vs PII

Token-like values are redacted from generated tickets when they match known patterns. Detection is imperfect. Email addresses and phone numbers are not automatically removed because they are often the bug. Prefer synthetic data.

Retention

Identity, credits, generation metadata, Stripe identifiers, legal acceptance records, support cases, and admin audit records are kept to operate billing, abuse controls, and support. See docs/DATA_INVENTORY.md. [ATTORNEY: maximum periods and deletion SLA.]

Contact

Use Support for privacy questions, payment records, or identity deletion requests. Recommended mailbox: support@reproslate.com (configure DNS and Resend before treating mail as live).