Acceptable Use Policy
Last Updated: 8/27/2026
This Acceptable Use Policy ("AUP") outlines the prohibited uses of the Nveal Service (the "Service"). By using the Service, you (the "Customer") agree to comply with this AUP. Nveal LLC ("Nveal") reserves the right to suspend or terminate your account if you violate these rules.
1. Prohibited Data Collection
Session replay technology is powerful, and with that power comes the responsibility to protect user privacy. You must not use the Nveal SDK to intentionally or negligently record, transmit, or store Highly Sensitive Information.
"Highly Sensitive Information" includes, but is not limited to:
- Payment Card Information (PCI): Full credit or debit card numbers, CVV codes, or expiration dates.
- Protected Health Information (PHI): Medical records, health status, or any data regulated by HIPAA or similar health privacy laws.
- Government Identifiers: Social Security Numbers (SSNs), passport numbers, driver's license numbers, or similar state/national IDs.
- Authentication Credentials: Passwords, security questions/answers, or biometric data.
- Special Categories of Data: Data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sexual orientation (as defined under GDPR Art. 9).
2. SDK Masking Obligations
Nveal provides built-in masking capabilities (such as maskAllInputs and maskPII) to help prevent the collection of sensitive data. However, as the developer integrating the SDK into your specific application, it is your responsibility to ensure these controls are properly configured and effective.
- You must utilize the
blockSelectororignoreSelectorconfigurations to explicitly hide any custom UI elements that contain Highly Sensitive Information before the data leaves the user's browser. - You must not disable default masking features on inputs that accept sensitive information.
3. Prohibited Activities
You agree not to use the Service to:
- Violate any applicable local, state, national, or international law, including data protection regulations (e.g., GDPR, CCPA).
- Record users on web properties you do not own or do not have explicit authorization to monitor.
- Surreptitiously track individuals across websites or devices in a manner that constitutes spyware or malware.
- Interfere with or disrupt the integrity or performance of the Service.
- Attempt to gain unauthorized access to the Service or its related systems or networks.
4. Enforcement and Remediation
If we become aware that you have recorded Highly Sensitive Information in violation of this AUP, we reserve the right to immediately and permanently delete the offending session data without notice. Repeated or severe violations will result in immediate account termination.
5. Contact Us
If you have questions about this AUP or need guidance on configuring the SDK to mask specific elements, please contact us at [email protected].