Privacy Policy

Last updated: September 10, 2026

Section 1

Data controller

The controller for the processing described in this policy is Sevenda, operated by Dario Calì, registered office Viale della Grande Muraglia 95, 00144 Rome, VAT no. 18605811001.

Privacy contact: hello@sevenda.dev.

Section 2

What the Extension records — and when

Recording starts only when you press "Start Recording" in the Sevenda DevTools panel and stops when you press Stop. Outside of an active recording, the Extension does not monitor, intercept, or store any browsing activity: the network-monitoring component is injected into the page only at the moment you start a recording, and only into the tab you are recording.

During an active recording, the Extension captures, in the recorded tab only:

  • Navigation events — the URLs of pages you visit during the recording.
  • Interaction events — clicks and form submissions: the element's tag, id, visible text (truncated to 100 characters), and position in the page. Form field values (what you type) are never captured.
  • Network events — URL, HTTP method, status code and duration of fetch/XHR calls made by the page, plus a preview of request and response bodies truncated to 500 characters. Before capture, fields commonly containing credentials (passwords, tokens, API keys, card numbers, CVV, OTP codes and similar) are replaced with "[REDACTED]".
  • JavaScript errors — error message, file, line and stack trace.
  • Page structure events — opening/closing of modals and dialogs (element selector only, no content).
  • Analytics events (Insights Mode) — Google Tag Manager dataLayer pushes and decoded GA4 hits emitted by the page, including consent-state signals. Where the Extension's PII-leak detector identifies personal data inside the page's own analytics traffic (a feature that helps you audit tracking compliance), the detected value is stored masked (e.g. ma***@example.com), never in clear text.
Section 3

Categories of data we process

  • Account data — email address, name if you provide one, authentication credentials (stored as a hash) or the identifier of the sign-in provider you use, workspace membership and role, plan, interface language.
  • Recorded browsing sessions — the events listed in Section 2, together with the diagrams, reports and tag plans generated from them. These stay on your device unless you explicitly share them to a workspace (Section 5).
  • Billing data — company name, billing address, country, VAT ID, plan and seat count, invoices. Card data is entered directly into Stripe's payment form: Sevenda never receives or stores full card numbers, expiry or CVV. We store only the plan, the invoice metadata and the identifiers Stripe returns.
  • Google account data (Tag Manager integration) — only if you connect it: the Google account identifier and email returned by OAuth, the list of Tag Manager accounts, containers and workspaces you can access, and the container items read or created on your instruction. See Section 6.
  • Technical logs — IP address, user agent and request timestamps for sevenda.dev and for our backend, used for security and abuse prevention.
Section 4

Where your data is stored

Recorded sessions, events, and generated diagrams are stored locally on your device in the browser's IndexedDB by default. They are transmitted to our backend only when you share them to a workspace (Section 5).

Local data is automatically deleted by a built-in retention policy: sessions are removed daily once they exceed your plan's retention period — or a conservative 30-day default if you are signed out or no plan information is available — and in any case beyond the 100 most recent sessions. You can delete any session manually at any time, and removing the Extension deletes all locally stored data. Sessions synced to a workspace follow the plan-based retention described in Section 8.

Your settings (interface language, capture filters, and your Anthropic API key if you provide one) are stored in Chrome's extension storage. If you have Chrome sync enabled, Chrome synchronizes this storage — including the API key — across your own signed-in browsers via your Google account, under Google's encryption and Google's own privacy policy. If you prefer not to sync it, you can disable extension sync in Chrome settings.

Backend data (accounts, shared sessions, billing metadata, integration tokens) is stored in our Supabase-hosted PostgreSQL database in the European Union, protected by row-level security.

Section 5

When data leaves your device

Data leaves your device only through actions you explicitly take:

  • AI generation (Anthropic). When you press "Generate", the recorded event sequence of the selected session (as described in section 2, with redactions applied) is sent to the Anthropic Claude API to produce your diagram or report. This uses your own Anthropic API key — the Extension ships without one, and Sevenda Lab never sees your key or your prompts. Anthropic processes this data as your API provider under the Anthropic Commercial Terms; per Anthropic's API data policy, API inputs are not used to train models.
  • Team workspaces (Supabase, optional). If you sign in to a Team workspace with your email, sessions you explicitly choose to share are uploaded to our Supabase-hosted backend (EU-hosted PostgreSQL with row-level security), where they are visible only to members of your workspace. We store: your email address, workspace membership, the shared session data, and comments. You can delete shared sessions and your account at any time; deletion is permanent.
  • Google Tag Manager (optional). If you connect your Google account, the tag plan items you choose to apply are sent to the Google Tag Manager API and created as drafts in the workspace you select. See Section 6.
  • Payments (Stripe). When you subscribe, your billing details and card data are submitted directly to Stripe from the checkout page.
  • Jira export (optional). If you configure your Jira credentials in Settings, exports go directly from your browser to your own Jira instance. Credentials are stored locally and never pass through Sevenda Lab.

Outside of these actions the Extension makes no other network requests. It loads no remote code, no remote fonts, no analytics scripts, and displays no ads.

Section 6

Google Tag Manager integration

Sevenda's Insights module includes an active Google Tag Manager integration. It is optional and always initiated by you: nothing is read from or written to your Google account until you connect it through Google OAuth, and you can disconnect at any time.

When you connect, Sevenda requests the following OAuth scopes and uses them strictly as described:

  • https://www.googleapis.com/auth/tagmanager.readonly — to list your Tag Manager accounts, containers and workspaces so you can choose where to work, and to read the existing tags, triggers and variables of the selected workspace in order to compare them with the tag plan Sevenda generated and show you what is missing or duplicated.
  • https://www.googleapis.com/auth/tagmanager.edit.containers — to create tags, triggers and variables as DRAFT items inside the single workspace you select, from the tag plan you have reviewed and approved in the interface.

Sevenda never publishes a container version and never deletes containers, workspaces, tags, triggers or variables. Everything written by Sevenda stays as an unpublished draft in your workspace: reviewing and publishing it to your live site remains a manual action that you perform in the Google Tag Manager interface.

Data obtained through Google APIs is used only to provide these user-facing features to you. It is not used for advertising, not sold or transferred to third parties, not used for profiling, and not used to train or improve any AI or machine-learning model.

Sevenda's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

OAuth access and refresh tokens are stored encrypted in our EU-hosted backend and are used only to call the Tag Manager API on your behalf. You can revoke access at any time from the Sevenda interface or from your Google Account permissions page; on revocation or disconnection the stored tokens are deleted.

Section 7

Purposes and legal bases (GDPR)

  • Providing the Extension and the backend (accounts, authentication, workspace sharing, diagram and report generation) — performance of a contract, Art. 6(1)(b) GDPR.
  • Google Tag Manager integration (reading your containers, creating draft items on your instruction) — performance of a contract, Art. 6(1)(b) GDPR; the access to your Google account is additionally authorised by the OAuth consent you grant to Google.
  • Billing, subscription management and invoicing, including Italian electronic invoicing through SDI where applicable — performance of a contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) GDPR.
  • Security, fraud and abuse prevention, service logs — legitimate interest in keeping the service available and secure, Art. 6(1)(f) GDPR.
  • Service communications (transactional email about your account, plan or incidents) — performance of a contract, Art. 6(1)(b) GDPR.
  • Product and marketing email, where sent — consent, Art. 6(1)(a) GDPR, withdrawable at any time via the unsubscribe link.

For recordings that never leave your device, you are the sole controller of that data: we have no access to it.

Section 8

How long we keep data

  • Session recordings stored in your browser — retained according to your plan (see below), with a cap of the 100 most recent sessions; deletable by you at any time. If you are signed out or no plan information is available, a conservative 30-day default applies.
  • Sessions synced to a workspace — according to your plan: 7 days (Free), 90 days (Analyst / Auditor / Suite Solo), 365 days (Studio / Agency / Suite Team), unlimited (Enterprise, until you delete them). Before expiry you can export your data as XML or SVG.
  • Account data — for as long as the account exists, and deleted within 30 days of account deletion. Encrypted backups are purged within 30 days.
  • Invoices and accounting records — 10 years, as required by Italian tax and civil law (Art. 2220 Codice Civile).
  • Google OAuth tokens — until you disconnect the integration or revoke access, then deleted.
  • Technical logs (access and error logs) — retained for up to 30 days, then deleted or anonymised.
Section 9

Third parties and processors

We use a small number of providers, each bound by a data processing agreement under Art. 28 GDPR where they act as our processors:

  • Supabase — database, authentication and storage for accounts and shared sessions (EU region). Processor.
  • Vercel — hosting and CDN for sevenda.dev. Processor.
  • Stripe — payment processing, subscriptions and invoicing. Stripe acts as an independent controller for payment and anti-fraud data under its own privacy policy.
  • Google — Google OAuth and the Tag Manager API, only if you connect the integration (Section 6). Google acts as an independent controller for your Google account under its own privacy policy.
  • Anthropic — AI generation, called with your own API key: Anthropic is your provider for that processing, not ours, and we never see your key or your prompts.

We do not use advertising networks, data brokers, or third-party analytics on the site or in the Extension.

Section 10

Transfers outside the EU

Our primary storage is in the European Union. Some of the providers listed in Section 9 are established in, or may process data from, the United States. Where such a transfer occurs it is covered by the European Commission's Standard Contractual Clauses and, where the provider is certified, by the EU–US Data Privacy Framework, together with supplementary technical measures (encryption in transit and at rest).

You can request a copy of the safeguards applied by writing to hello@sevenda.dev.

Section 11

Your rights (GDPR)

Under Articles 15–22 GDPR you have the right to access your data, to rectify it, to erase it, to restrict or object to its processing, to data portability, and to withdraw consent at any time where processing is based on consent (without affecting processing carried out before withdrawal).

To exercise these rights, contact hello@sevenda.dev — we respond within 30 days. You also have the right to lodge a complaint with your supervisory authority (in Italy: Garante per la Protezione dei Dati Personali).

A note on recording third-party data: if you record sessions on systems containing other people's personal data (e.g. a CRM), you are responsible for ensuring you are authorized to do so under your organization's policies and applicable law. In that case you act as controller and Sevenda Lab, for anything you sync to a workspace, acts as your processor.

Section 12

Cookies

sevenda.dev uses only strictly necessary cookies and local storage: your authenticated session, your interface language preference, and the anti-fraud cookies set by Stripe on the checkout page. These do not require prior consent under Art. 122 of the Italian Privacy Code.

We set no advertising, profiling or third-party analytics cookies. The Chrome Extension sets no cookies at all. If this ever changes, we will introduce a consent banner before any non-essential cookie is used.

Section 13

What we do NOT do

  • We do not collect telemetry, usage analytics, or crash reports from the Extension.
  • We do not sell, rent, or transfer your data to third parties.
  • We do not use your data for advertising, profiling, or creditworthiness.
  • We do not use data obtained from Google APIs to train AI or machine-learning models.
  • We do not capture keystrokes or form input values.
  • We do not record anything while a recording is not active.
Section 14

Children

Sevenda is a professional tool and is not directed at children under 16. We do not knowingly process children's data.

Section 15

Changes

We will update this policy as the product evolves. Material changes — such as a new integration, a new processor, or a change in retention — will be announced on sevenda.dev and reflected in the effective date above. Your continued use of Sevenda after a change takes effect means you accept the updated policy.

Section 16

Contact