Privacy Policy
Last updated 17 August 2026.
This policy explains what demobolt does with personal data. demobolt is operated by an independent sole trader; our full legal and registration details are available on request from hello@demobolt.io, which is also the address for every question and request below.
Three different groups of people
demobolt handles data about three groups, and our role is different for each. Getting this distinction right matters, because it decides who you should be asking.
- Account holders — you and the people you invite into your workspace. We decide what we collect about you and why, so for this group we are the controller, and this policy is our promise to you.
- People who appear inside a capture — the names, email addresses and records that happen to be on screen when a customer records their own product. We never chose that data, and we only hold it because a customer put it there. For this group we are a processor acting on that customer’s instructions, and the customer is the controller. Our Data Processing Agreement governs it.
- People who watch a published demo — see below. As things stand we collect nothing about them at all.
If you saw your own information inside somebody’s published demo, we are not the ones who put it there and we cannot lawfully remove it on our own initiative. Write to us anyway at hello@demobolt.io: we will pass the request to the customer who published it, and if the content breaks our Acceptable Use Policy we will take it down.
What we collect about account holders
- Account details — your name, email address, password (stored only as a cryptographic hash), your organisation and the people in it. We need these to give you an account at all, so the legal basis is performance of our contract with you.
- Content you create — your demos, folders, uploads and settings. Also contract.
- Billing records — described in detail below. Contract, plus our legal obligation to keep books, plus our legitimate interest in understanding our own business.
- Technical records — server logs, IP address, browser and device information, and error reports, kept so the Service works and stays secure. Our legitimate interest in running and protecting the product.
- Product analytics — how the app is used, only if you allow it in the cookie settings. Your consent, which you can withdraw at any time.
- Support conversations — what you write to us in chat or by email. Contract and legitimate interest.
We do not buy personal data from anyone, we do not enrich what you give us from outside sources, and we make no automated decisions that produce legal or similarly significant effects on you.
What is inside a capture
A capture is a copy of a page as it appeared on your screen. It may therefore contain personal data belonging to your own customers or staff — names, email addresses, account numbers, support tickets.
We do not choose, review or monitor that content, and we cannot see it on your behalf. What ends up in a capture, whether it is lawful for it to be there, and whether it is edited or blurred before publishing, is entirely the decision of the customer who made it. The Service provides editing, replacement and blurring tools for exactly this, and using them is the customer’s responsibility. The terms of that arrangement are in the Data Processing Agreement.
The browser extension
demobolt captures with a Chrome extension you install and start yourself. It only wakes up while a capture is running — it does nothing on any site until you press Start, and it never watches your browsing in the background.
A demo is a pixel-perfect clone of the HTML and CSS of your product, not a pile of static screenshots. That’s what makes it feel like the real thing when someone clicks their way through it.
As you record, we do a bit of magic in the background: we store every image, style and font that shows up in your recording, and serve them from a lightning-fast CDN. That’s what lets us replay your product exactly as it looked at that moment — even if your app changes next week, your demo keeps working. This also means your demos load fast, and that images and files which would normally need someone to be logged in to see are viewable by the people you share your demo with.
One exception: some fonts are licensed in a way that doesn’t allow anyone else to keep a copy. We don’t copy those. Your demo loads them from the same place your own site does, so they still look right.
The extension does not read your cookies, your saved passwords, your browsing history, or any other tab. Your live app is never connected to the demo — viewers play with a copy, never with your real product or its live data.
While you are working, the capture sits in your browser’s own extension storage, and clears once it has uploaded.
You keep full ownership of your demo content. We only process it to run the service. And a demo shared by link or embed can be seen by anyone who has that link.
If the extension ever crashes it sends us an error report so we can fix it. That report carries the error and the extension version — not the page you captured.
People who watch a published demo
Today, demobolt collects no personal data about demo viewers. There is no lead capture form, no viewer analytics, no visitor profiling and no advertising. We do not know a viewer’s name, email address or identity, we do not build a profile of them, and we do not share anything about them with anyone.
If we ever add features that do collect viewer data — lead capture forms and demo analytics are on our roadmap — we will update this policy before they ship, and the choice to switch them on will belong to the customer publishing the demo, not to us.
Billing and payments
Payments are handled by Polar, who are the seller of record. They take the payment, issue your invoice and hold your card details. We never see or store your card number. You can view and download every invoice and receipt from Polar's customer portal, which we link to from your billing page.
We do keep a record of the account itself: your plan, whether you pay monthly or yearly, the dates your subscription started and renews, the amounts paid and refunded, and whether a payment failed. We keep this to run your subscription, to keep our own books straight, and to understand which customers get the most out of demobolt so we know where to spend our time. That last purpose rests on our legitimate interest in running the business.
It never changes what you are charged, what you can access, or the support you get. Nothing about it is automated and nothing is shared with an outside analytics tool. If you would rather we did not include your account in that analysis, tell us and we will stop — you do not have to give a reason.
We do not copy your card's brand or last four digits, your billing address or your tax number into our systems. When we need to show you those, we read them from Polar at that moment.
Who else handles data
We use a small number of companies for hosting, storage, payments, email, analytics and support. Each one is bound by a written contract that permits it to use the data only to provide its service to us. The current list, what each one does, and where each one sits, is published at demobolt.io/subprocessors.
We also disclose personal data where the law requires it, to professional advisers under confidentiality, and to a buyer if the business is ever sold — in which case we would tell you first. We do not sell personal data, and we do not share it for cross-context behavioural advertising. We never have.
Where your data is, and international transfers
demobolt runs on infrastructure in the United States, so data you give us is stored and processed there. If you are in the EU, the UK or Switzerland, that is an international transfer and it needs a legal basis. We use:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with the UK Addendum and the Swiss adaptations where those apply, as our primary safeguard, which our Data Processing Agreement sets out in full;
- the EU-US Data Privacy Framework where the provider receiving the data is certified under it. Which of our providers are certified is marked on the sub-processor list.
demobolt itself is not certified under the Data Privacy Framework, so we do not rely on it for the transfer to us — the Standard Contractual Clauses cover that. You can ask us for a copy of the clauses at any time.
Cookies and similar technologies
We ask before storing anything on your device that isn’t needed to run the service. Your choice is remembered in a single cookie that covers both demobolt.io and app.demobolt.io, so we only ask once.
Strictly necessary
Remembers your cookie choice and keeps you signed in. These are what make the basics work, so they stay on.
- Sign-in session — Keeps you signed in, so you don't log in every time.
- Cookie choice — Remembers what you picked here, so we don't ask again.
- Dashboard basics — Small things like which setup steps you've finished and when you last re-sent an invite.
Analytics
Records the pages you open and the things you click, so we can see which parts get used and improve them. With this off we still count the visit, without keeping anything on your device.
- PostHog — Keeps a small id so your visits count as one person, not several.
You can change or withdraw your choice at any time:
Live chat
The chat button is there for everyone, and it is not part of the choice above, because it stores nothing until you use it. We run Crisp’s Total Privacy mode, which holds off starting a chat session until you actually open the chat window.
If you do open it, Crisp sets crisp-client/* cookies that last 6 months. They exist only to keep your conversation going as you move between pages and come back later — they are not used for advertising. Crisp is a French company, and your chat messages are stored in the European Union — the Netherlands and Germany, with encrypted backups in Ireland. Crisp also runs relay servers outside the EU which hold no messages, only connection details such as IP address, time, browser and the page you were on.
Demos you publish
A published demo is served from its own domain and the demobolt player adds no cookies, no local storage and no analytics of its own. The choice you make above does not apply to it.
A demo does still contain the page you captured. When you publish, we strip out the advertising and analytics trackers we recognise — measured on real captures, these otherwise set third-party cookies on whoever views the demo and leak their IP address to companies that have nothing to do with you. That removal is a best effort against a list of known trackers, not a guarantee. A capture can still reference fonts, images or embeds from other companies, and a viewer’s browser may load them and those companies may set their own cookies — exactly as they would on the original site. The demo runs on your website, so that content is yours to account for — review what a capture pulls in before you publish it.
Error monitoring
We use Sentry to be told when something breaks. It reports errors only — no session recording, no cookies, no local storage — so there is nothing to switch on or off here. It is covered by our legitimate interest in keeping the product working, and is listed on the sub-processor list.
How long we keep things
- Account and subscription details — while your account is open, then deleted or stripped of anything identifying 12 months after you close it.
- Your demos and captures — while your account is open. If a trial ends without a subscription, we delete them 7 days after access is locked, and they cannot be brought back. If a subscription lapses, demos will be offline 7 days after access is locked but keep everything, so subscribing again puts them back up. We warn you before either happens.
- Payment records — 5 years from your last payment, so we can settle any dispute over what was paid and keep our accounts in order.
- Failed payment records — 24 months, then deleted.
- Error reports — deleted automatically by Sentry no later than 90 days after we receive them. We cannot extend that period even if we wanted to.
- Server logs — rotated in the ordinary course and kept only for as long as we need them to run and secure the Service.
- Support conversations — kept until we delete them. Our chat provider does not remove them automatically, so ask us and we will delete yours.
- Anonymous totals — figures like average revenue or how long customers stay, with nothing linking them to a person, are kept indefinitely.
Copies inside routine backups are overwritten in the ordinary course rather than picked out one by one, and stay protected until they are.
Keeping data safe
Data is encrypted in transit and at rest, access is limited to the people who need it, and each customer’s data is separated at the database level. No service can promise perfect security, and we do not. If a breach affects your personal data we will tell you and the relevant regulator as the law requires.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to send it to another provider, object to us using it, or ask us to restrict how we use it. Just write to hello@demobolt.io. We answer within 30 days, we do not charge, and we will never treat you differently for asking.
Where we rely on consent you can withdraw it at any time, and where we rely on legitimate interests you can object and we will stop unless we have compelling grounds not to. For invoices and receipts, Polar holds the authoritative copy, so we will point you to their portal for those.
If you ask us to delete everything, we may keep the payment records above for the period stated, because we may need them to defend a dispute about money. We will tell you exactly what we kept and when it goes. Everything else goes right away.
If your data is inside a customer’s demo rather than in your own account, we are the processor and not the controller, so we will forward your request to that customer and support them in answering it.
If you are in the EU, UK or Switzerland, you can complain to your national data protection authority. We would rather you came to us first, but it is your right either way.
If you are in a US state with a privacy law — California, Colorado, Connecticut, Virginia and others — the same rights apply, along with the right to appeal a refusal. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not process sensitive personal information, so there is no “Do Not Sell or Share” choice to make.
Children
demobolt is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, tell us and we will delete it.
Changes
We may update this policy. The new version is posted here with a new date at the top, and where a change materially affects you we will tell you by email or in the app before it takes effect.
Contact
Every question, request or complaint about privacy goes to hello@demobolt.io, and a person reads it.