Privacy

Defrixa measures where visitors get stuck on a web page. This page describes what that involves for the people who visit a site running our tracker, and for the customers who install it.

If you visited a site that uses Defrixa

We record anonymous signals about how the site was used: which pages you viewed and in what order, how long each page was visible to you and how far you scrolled, which buttons came into view, the text on the buttons and links you clicked, which form fields you focused, filled in, changed or left blank, when a form was submitted and when it showed an error, and events the site’s owner chooses to send, such as a completed signup. With each visit we record the page you arrived on and the outside site or campaign that brought you, plus your device type, browser and operating system. Your browser’s full identification string is checked for bots as the request arrives and is not stored.

The site’s owner can also turn on: page speed measurements; error messages produced by the site’s own code, with sensitive web address parameters removed; bursts of repeated clicks in one spot; clicks that got no response, recorded by the type of element clicked and never its text; form submissions sent by the page’s own scripts; When a site enables private page context, bounded control structure, interface labels and explicitly permitted page text, including on signed-in pages, are stored privately for seven days. Entered values, private regions and raw HTML are excluded. Sites may separately enable masked browser-rendered viewport images on explicitly selected hostnames, retained privately for seven days. Images are approximate DOM reconstructions; unapproved text and images are masked. Context is not a recording of every state.; When a site enables page structure, the first visit from a browser to each page sends what that page contains: headings, short text, buttons, links, form fields, images and payment frames, with their positions, and may send it again after a press changes the page. Defrixa’s own browser may also open that site’s public pages and keep their HTML and script. For pages that need a sign-in, a visitor’s browser may send that page’s HTML and script once, without passwords, card details or other secure fields..

Sites testing the new tracker also record the structure, type, position and available state of controls, with bounded interface labels when the site enables label capture, excluding entered field values, and native form activation, submission and validation observations, which do not confirm a successful outcome. Site owners can enable filtered interface labels and structural page context. A site’s owner can also turn on interactions, which record which form fields you focused, filled in, changed or left blank, and what you entered in them, except passwords, card details, identity numbers and other secure fields, which are never read, and what appeared or changed on the page after you pressed something or changed a field, such as a form opening or a message, with its text. Form field names are never stored, entered values are kept only when interactions are on and never for secure fields, address queries and fragments are removed, and marked private regions are excluded. Filtered campaign source, medium and campaign labels are stored separately for attribution.

We never record what you type into a form. For form fields we store the field’s name and type, and whether it was left blank or changed — never its value — and fields that look sensitive (passwords, payment details, anything marked hidden) are skipped entirely, both in the tracker and again on our servers. Web addresses are stored with parameters such as email or token replaced, and without the part after a # — unless it names a page inside the site (for example #/orders), which is kept so those pages can be told apart.

We do not set cookies and we do not store a persistent identifier. A random id is held for the lifetime of the browser tab so a visit can be grouped into one session, and it is erased when the tab closes. It is not linked to you and cannot follow you to another site. If you opt out, that choice is saved in your browser so it lasts.

Your IP address is used to make the request and is not stored against these events.

To opt out: turn on Global Privacy Control or Do Not Track in your browser — we honor both on our servers, on every site, before anything is recorded. You can also opt out in this browser.

If you scan a page on defrixa.com

We keep the address you scanned, your email address if you gave it, and your IP address, so we can limit repeated free scans and stop abuse. Score reports for a domain are shared by everyone who scans that domain.

If you have a Defrixa account

We store your email address, your workspace and its members, the sites and flows you configure, the reports we generate, and your billing status. Payment card details go directly to Stripe and never reach our servers.

From Settings you can download your workspace’s data — its members, billing and email history, and each site’s settings, flows, reports, recommendations, fixes and scores. The download does not include individual visits and events, or the daily totals built from them.

You can also delete the workspace there. Deletion removes its sites with their flows, recommendations, shipped fixes and all visitor data we collected, and the workspace itself. Score reports for a domain are shared by everyone who scans it and are not removed. Deletion is not reversible.

How long we keep it

Visitor events are deleted after 400 days. Records of how far a page was scrolled, most button and link clicks, and which buttons came into view are deleted sooner, after 45 days, once they have been added to the daily totals. A visit or visitor record is deleted once it is older than 400 days and none of its events remain.

For the new tracker, random event identifiers and content fingerprints prevent retried uploads from being counted twice. These deduplication records contain no event payload and are kept until the site is deleted.

Daily totals are kept without a time limit so historical charts survive. They hold page addresses, button and link text, form field names, the outside sites that sent visitors, and counts, but no visitor id. Scan records and score reports are also kept without a time limit. Your workspace and its sites are kept until you delete the workspace.

We keep a record of each email we send (the address, the subject, which kind of email it was, and whether it was delivered, opened, clicked, bounced or marked as spam) for 400 days. An address that bounced or marked our email as spam stays on our do-not-email list until it is cleared.

Who else processes it

We use the following subprocessors. Each receives only what its purpose requires.

SubprocessorPurposeWhat it receives
Amazon Web ServicesHosts the application and its databaseEverything described on this page
AnthropicWrites reports, page rewrites, fix explanations, flow summaries and support chat answersPublic content of scanned pages, a site’s flow step names and conversion rates, and questions asked in the support chat
StripePayments and subscriptionsAccount email, billing details
ResendSends product and account email, including install instructions and fixes a customer asks us to sendRecipient email address, message content
SentryError monitoringError traces (no request bodies, no IP)
BetterStackLog storageServer logs (redacted)
CloudflareBot check on public formsChallenge token
Voyage AIFinds the help pages that answer a support chat questionDefrixa’s public documentation and the question asked

If you install Defrixa on your own site

You are the controller of your visitors’ data and we are your processor. Disclose Defrixa in your own privacy notice, and link visitors to the opt-out page. Because we hold no cross-site identifier, we cannot single out one of your visitors on request. To serve an erasure request, delete the workspace from Settings, or write to us to delete one site’s visitor data.

Contact

Privacy questions and data requests: privacy@defrixa.com.