This Privacy Policy describes how Scriptx, UAB (“Scriptx”, “we”, “us”), a company incorporated in the Republic of Lithuania, processes personal data in connection with the Everframe website, the Everframe ingest service, the Everframe SDKs, and the admin console (together, the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and applicable Lithuanian law.
1. Two roles: controller and processor
Our role depends on whose data we are handling.
- For account and website data — the details of the people who sign up for and administer an Everframe account, plus visitors to our website — Scriptx is the data controller.
- For bug-report (ingest) data — the reports your end users submit through an SDK you embed in your app — you, our customer, are the data controller and Scriptx acts as a data processor on your behalf. We process that data to validate, serve it for your plan's retention window (14 days to unlimited, then a further 14-day grace period before permanent erasure — see Section 5), and deliver it to the receivers you configure, and according to our Data Processing Agreement — see Section 3 for the additional processing our AI features involve.
2. Data we process as a controller
Account data
When you create and use an Everframe account we process your name, email address, hashed password (or your identity-provider identifier), organisation name, billing details, and the configuration you create (registered apps, SDK keys, webhook subscribers).
Billing data
Payments are handled by our payment processor. We do not store full card numbers; we retain invoices, plan, and billing contact for tax and accounting purposes.
Website & product analytics
We process limited technical data (IP address, browser, pages viewed) to keep the site secure, measure interest, and improve the product. We keep this to a minimum and do not build advertising profiles.
On this marketing website we use Google Analytics 4 to count
visits and see which pages are read. It sets first-party cookies in your
browser (names beginning _ga) and sends the technical data above
to Google, which acts as a sub-processor and may process it outside the EEA
under the safeguards described in section 7. Google Analytics does not run on
the dashboard, the reporter, or anywhere a bug report is handled — it is
limited to the public site. We do not enable Google Signals or advertising
features, and we do not use this data to build advertising profiles. You can
opt out with Google’s
browser add-on
or by blocking cookies for this site.
Support communications
When you contact [email protected] we process the contents of your message and your contact details to respond.
3. Data we process as a processor (bug reports and install counting)
An Everframe report is an “AI-ready envelope.” Depending on how you configure your SDK, it may contain a screenshot, a screen recording, the focused component, console and network logs, device and app metadata, and — only if you choose to attach it — an end-user identifier, email, or display name. You decide what your SDK captures, and you are responsible for providing notice to and obtaining any consent from your end users, and for redacting sensitive fields before submission.
We process this data to provide the Service: validating the payload, storing it for the delivery and retry window, and forwarding it to the webhook receivers you configure. We also run AI features that process report contents, listed below with what triggers each one, what it sends, and whether the AI triage toggle (Project Settings → AI triage) controls it. Turning the AI triage toggle off does not stop the AI assistant or AI agent runs — it controls only AI triage and resolution analysis, as stated against each one below.
- AI triage runs automatically on every report. It sends report contents to a model-gateway sub-processor. Its output is a severity suggestion, duplicate detection, and a summary. The AI triage toggle controls it.
- Resolution analysis runs automatically when a linked ticket enters a resolved column. It sends the ticket's title and description, its triage summary, and up to 20 recent thread messages from every report linked to it — including messages your end user wrote — to the same model-gateway sub-processor. Its output is a short account of how the bug was resolved, stored for your team. The AI triage toggle controls it.
- The AI assistant runs when someone in your organisation uses it on a report. It sends report contents to the same model-gateway sub-processor, and can return attachment contents (including images) into the model's context. The AI triage toggle does not control it.
- An AI agent run runs when someone assigns a linked ticket to the AI agent. It sends the card's title and description to the same model-gateway sub-processor. The AI triage toggle does not control it.
- Search and duplicate matching send short derived text — such as a triage summary, an error signature, a component name, a card's title and description, or a search query someone types — over a separate endpoint and credential from the model-gateway sub-processor above, which may be the same underlying vendor depending on configuration. The full report is never sent this way.
We do not use report contents to train models, and we do not sell or share them.
Install counting
Separately from bug reports, and at most once a day whether or not a report is
ever filed, our SDKs send a random per-install number generated on your end
user’s device. We store a keyed hash of that number — never the number itself —
together with the calendar month it was seen and the exact time it first
appeared that month, so we can count how many distinct installs your app had
that month and show it to you as plan usage. No name, email, IP-derived value,
device fingerprint, or advertising identifier is used or derived from it, and
it is not shared across the apps you register with us. We retain it for up to
about two months — the current calendar month plus the previous one — deleted
by a periodic sweep rather than the instant a month ends. As with bug-report
data, we process it only on your instructions; your developer can turn it off
with the installIdentifier.disabled flag in the React and React
Native SDKs, or the installIdentifierEnabled flag in the iOS and
Android SDKs, in which case this app stops sending new identifiers from that
point on. Turning off that flag does not necessarily zero out the count shown
to you, since it is per
organization rather than per app: installs already recorded earlier that
month stay counted until they age out, and any other app in your org that
still sends an identifier keeps contributing.
4. Why we process data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Service for account holders | Performance of a contract (Art. 6(1)(b)) |
| Processing bug reports on your instructions | Processing on behalf of a controller (Art. 28) under your legal basis |
| Security, fraud prevention, and service improvement | Legitimate interests (Art. 6(1)(f)) |
| Billing, accounting, and tax | Legal obligation (Art. 6(1)(c)) |
| Product updates and marketing email | Consent (Art. 6(1)(a)), withdrawable at any time |
5. Retention
Report artifacts (screenshots, recordings, logs, and the stored envelope) are served for your plan's retention window — 14 days on Free, 90 on Starter, 365 on Pro, and unlimited on Enterprise — so you and your team can access and act on a report for as long as your plan provides, not merely long enough to hand it off. The floor under every window is delivery: retrying and dead-lettering a webhook takes about a week, and even the shortest (Free) window clears that with room to spare. Once your plan's window ends the artifact stops being served, and a further 14 days after that it is permanently erased: both the underlying files and the heavy capture channels (screenshots, recordings, session replay, breadcrumbs, network bodies). The report's own title, description, and lightweight metadata are not affected by erasure. Evidence you attach to a board card is kept for as long as the card exists, regardless of the window above. Erasure removes artifacts from our live systems immediately; encrypted backups roll off on their own schedule. Lightweight event metadata may be retained longer for analytics and abuse prevention. Account, billing, and tax records are kept for as long as your account is active and afterwards as required by Lithuanian law.
Retention is not the only reason an attachment can stop being served. On the Free plan, while the org is over its monthly active install limit, screenshots, video, audio, and session replay are withheld — a separate, reversible condition, not an early erasure: nothing is deleted, and a normal presigned URL returns the moment the org upgrades or drops back under the limit. See data & retention for the full mechanism.
6. Sub-processors
We rely on a small set of vetted infrastructure providers (cloud hosting, object storage, email delivery, payment processing, and AI model inference) to run the Service. Each is bound by a data-processing agreement with appropriate safeguards. A current list of sub-processors is available on request at [email protected].
7. International transfers
We aim to process data within the European Economic Area. Where a sub-processor transfers data outside the EEA, we rely on an adequacy decision or the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures.
8. Security
Bug reports are delivered over TLS and signed with HMAC-SHA256 so receivers can verify authenticity. SDK keys and webhook signing secrets are stored encrypted, and access to production systems is restricted and logged. For more detail see our security practices.
9. Your rights
Subject to the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent. To exercise these rights for data we hold as a controller, contact [email protected]. Where Everframe processes bug-report data on a customer’s behalf, please direct requests to that customer (the controller); we will assist them as required.
You also have the right to lodge a complaint with a supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija).
10. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the product or by email, and the “last updated” date above will change.
12. Contact
Scriptx, UAB · Lithuania
Privacy enquiries: [email protected]
See also our Terms of Service and security practices.
