Privacy Policy

Last Updated: 9/4/2026

Nveal LLC ("Nveal", "we", "us", or "our") respects your privacy and is committed to protecting it through our compliance with this policy. This Privacy Policy describes the types of information we may collect or that you may provide when you visit our website (nveal.com) or use our session recording Software-as-a-Service (the "Service"), and our practices for collecting, using, maintaining, protecting, and disclosing that information.

1. Introduction & Two Types of Data

Because Nveal is a service that our customers install on their own websites, it is crucial to distinguish between two distinct types of data we process:

  • Customer Data: Information about the individuals or businesses that create an account directly with Nveal to use our Service. For this data, Nveal acts as a Data Controller.
  • End-User Data: Information collected from visitors navigating the websites of our customers who have installed the Nveal SDK. For this data, Nveal acts strictly as a Data Processor (or Service Provider), acting only on the instructions of our customers.

2. Customer Data (Your Information)

What We Collect

When you sign up for an Nveal account, we collect the following personal information:

  • Name
  • Email address
  • Phone number
  • Organization or Business Name
  • IP Address (for security and logging)
  • Account credentials (passwords are securely hashed; we cannot read them)

Payment Information

We use a third-party payment processor, DodoPayments, to handle all billing and subscription transactions. Nveal does not directly collect, process, or store your raw credit card numbers. Your payment details are provided directly to DodoPayments, whose use of your personal information is governed by their privacy policy.

How We Use Customer Data

We use this information to:

  • Provide, maintain, and improve our Service.
  • Process your subscription payments.
  • Communicate with you regarding your account, updates, and support inquiries.
  • Ensure the security of our platform.

Data Retention for Customer Data

If you cancel your subscription, we retain your Customer Data for a period of 365 days for accounting and re-activation purposes, after which it is permanently erased. However, if you explicitly request to delete your account, your Customer Data is immediately and permanently erased from our systems.

3. End-User Data (Your Visitors' Information)

What the Nveal SDK Collects

Our customers use the Nveal SDK to understand how users interact with their websites. Depending on how a customer configures the SDK, it may collect:

  • DOM mutations (structural changes to the webpage)
  • Mouse movements, clicks, and scrolling activity
  • Network requests (URLs and status codes)
  • Console errors and logs
  • Device information (User Agent, viewport dimensions)
  • IP addresses (used for session routing and general analytics)

Privacy Controls & Masking

Nveal is built with privacy-first defaults. By default, the SDK is configured to:

  • Mask all input fields (passwords, text inputs), replacing keystrokes with asterisks before data leaves the browser.
  • Automatically block recognized Personally Identifiable Information (PII) fields (e.g., credit card numbers, SSNs).

Our customers have the ability and responsibility to configure the SDK to ignore or block specific HTML elements containing sensitive information unique to their applications.

How We Use End-User Data

We process End-User Data solely to provide the session replay and analytics Service to the specific customer who collected it. We do not sell, rent, or cross-reference End-User Data across different customers.

Data Retention & Deletion for End-User Data

End-User Data (session recordings) is retained for 7, 14, or 30 days, strictly depending on the customer's subscription plan. Once this retention period expires, the data is permanently and automatically hard-deleted from our AWS S3 and PostgreSQL storage. We do not maintain historical backups of expired session data; once deleted, it cannot be recovered.

4. Subprocessors and Third-Party Tools

We do not use any third-party marketing, tracking, or analytics tools (such as Google Analytics or Meta pixels) on our dashboard or landing page.

To provide our core infrastructure, we share data with the following trusted subprocessors:

  • Amazon Web Services (AWS): Cloud hosting and secure data storage (S3).
  • PostgreSQL & Redis: Database and caching infrastructure.
  • Resend: Transactional email delivery.
  • DodoPayments: Payment and subscription processing.

5. Customer Responsibilities

If you are a customer using the Nveal Service on your website, you are legally responsible for the data you collect. You must maintain your own Privacy Policy that clearly discloses to your end-users that you utilize session replay technology (like Nveal) to collect data regarding their interactions with your site. You must obtain any necessary consents required by applicable laws (such as GDPR or CCPA) prior to activating the Nveal SDK.

6. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Nveal LLC
1322 Middlecrest Dr NW
Concord, NC 28027
Email: [email protected]