Demo Pine is operated by RyanTech LLC, a South Carolina limited liability company doing business as "Demo Pine" and "DemoPine" ("Demo Pine", "we", "us", "our").
This policy explains what personal data we handle, why, who we share it with, how long we keep it, and what rights you have. It covers:
- our marketing website at demopine.com;
- our application at app.demopine.com;
- the storage and delivery of captured media, described in Section 4.5;
- the Demo Pine Capture Chrome extension; and
- published demos viewed at
app.demopine.com/s/<code>links.
It does not cover third-party websites we link to, or the products our customers build and operate using Demo Pine.
We review and update this policy at least once every twelve months.
If you are reading this because of a demo someone sent you, skip to Section 3 — the company that made that demo, not Demo Pine, decides what happens to your information.
1. Two very different roles: controller and processor
Demo Pine handles personal data in two distinct capacities. Which one applies changes who you should talk to about your data.
1.1 We are a controller for the data we need to run our business: your account, your workspace, your billing, our security and diagnostic logs, and visits to our marketing site. Sections 2, 7, 11, 12 and 13 of this policy describe that data, and you can exercise your rights directly with us.
1.2 We are a processor (a "service provider" under US state law) for the content our customers put into Demo Pine and the data their demos collect. That includes:
- screenshots, screen recordings, audio, and copies of web pages our customers capture;
- the text, callouts, and calls-to-action they write into a demo;
- analytics about people who view their demos;
- names, email addresses, and company names submitted through a demo's lead-capture form;
- employee records pushed to us by a customer's identity provider or directory (SSO and SCIM).
For all of that, our customer decides what is collected, why, and for how long. We act on their instructions under our agreement with them. We do not use that data for our own purposes, we do not sell it, and we do not use it to train AI models.
1.3 What this means for you. If you are a demo viewer, a lead, or an employee of a Demo Pine customer, and you want your data corrected or deleted, the fastest route is to contact the company whose demo you saw or whose workspace you belong to. If you contact us instead, we will pass your request to that customer and help them respond — see Section 13.6.
1.4 Personal workspaces. When you sign up, we automatically create a personal workspace named after you (for example, "Alex Chen's workspace"). Our roles do not change with the size of a workspace. We are the controller of your account, authentication, billing, and security data (Section 1.1), and we are the processor of the content you capture and the data your demos collect (Section 1.2), whether you are the only member or one of many. Where you are the sole member, you are the customer and the controller of that content, and you exercise controller rights and obligations directly. Once you invite others or join a company workspace, the workspace — not you individually — is the customer.
2. Data we collect as a controller
2.1 Account holders
| What | Why | Legal basis (GDPR Art. 6) | Source |
|---|---|---|---|
| Name, email address, whether the email is marked verified | To create and operate your account, identify you across a workspace, and contact you about the service | Performance of a contract, Art. 6(1)(b) | You, or your employer's identity provider |
| Password, stored only as a salted scrypt hash | To authenticate you. We never store or can recover your plaintext password | Contract, Art. 6(1)(b) | You |
| Profile image URL | Shown in the app header and member list. If you sign in with Google, this is the photo URL from your Google profile | Contract, Art. 6(1)(b) | You or Google |
| Google OAuth access, refresh, and ID tokens, and granted scopes — only if you choose to sign in with Google | To let you sign in without a separate password | Contract, Art. 6(1)(b) | |
| IP address and browser user-agent string, recorded for each sign-in session | Session security and detecting unauthorised access | Legitimate interests, Art. 6(1)(f) — keeping accounts secure | Your browser and network |
| Password-reset and sign-in verification records (your email address and a one-time token) | To let you reset a password or complete a federated sign-in | Contract, Art. 6(1)(b) | You |
| Workspace membership and role (viewer, editor, admin) | Access control | Contract, Art. 6(1)(b) | You or your workspace admin |
We do store IP addresses for signed-in sessions. Some parts of Demo Pine deliberately avoid IP collection — in particular demo-viewer analytics, described in Section 3 — but that is a statement about our analytics records, not about your account and not about our infrastructure providers' request logs. Please do not read a general "we never collect IP addresses" promise into this policy, because it would not be true.
Google sign-in. Demo Pine's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the scopes needed to sign you in and to display your name and profile image. We do not read your Gmail, Drive, Calendar, or Contacts.
2.2 Content you create
Demos, steps, overlays, callouts, calls-to-action, brand kits, and uploaded media are yours. We store them so we can show them back to you and to the people you share them with. We do not review, moderate, or validate the contents of a demo, and we do not inspect the free-form text or JSON you save. See Section 4 for the significant caveats about captured screens.
If you use the brand scanner, our servers fetch a web address you supply — or one derived from the domain of your email address — and read its HTML, stylesheets, scripts, and logo files to extract colours and logo candidates, which we then store on your brand kit. Our server's IP address will appear in that site's logs. You must only scan sites you are entitled to have us fetch.
- Legal basis: performance of a contract, Art. 6(1)(b), for storing and serving your content; legitimate interests, Art. 6(1)(f), for the brand scanner, which exists to configure your workspace's appearance. You can decline to use the brand scanner and enter colours and logos manually.
2.3 Workspace members and people you invite
If you invite someone to a workspace, we store their email address, the role you assigned, who invited them, and the invitation's timestamps — and we email them an invitation link on your instruction. That person may have no Demo Pine account and may never create one.
- Legal basis: our legitimate interests and those of the inviting customer in operating a collaborative product, Art. 6(1)(f). Our terms require the inviting customer to have a genuine business relationship with the person they invite.
- The invitation email identifies the person and the workspace that invited you, and contains an acceptance link that expires after 7 days. We do not add invited addresses to any mailing list, and we send no marketing email. If you would rather not receive invitations from Demo Pine, email [email protected] and we will suppress your address.
- The invitation record itself — including the invited person's email address — is deleted 90 days after the invitation is accepted, revoked, or expires. See Section 11.1.
- Any member of a workspace, including read-only viewers, can see the name, email address, avatar, role, and join date of every other member, and the email addresses on any pending invitations.
If you were invited and want the record of your email address removed, email us at [email protected] and we will delete it.
2.4 Accounts created for you by your employer
If your employer uses single sign-on (SAML) or directory provisioning (SCIM):
- SSO. When you first sign in, we receive your email address and display name from your employer's identity provider inside a signed assertion, and create an account and workspace membership for you. We do not retain the raw assertion or any other attribute it contains.
- SCIM. Your employer's directory can create an account for you before you ever visit Demo Pine. We store your email address, display name, and the directory's external identifier for you. We ignore every other attribute the directory sends.
- What we send back to the directory. When your employer's directory queries us, we return that member's email address, display name (including a first/last split derived from the stored name), active status, and workspace role. Group listings include the email addresses of the members in them.
- Accounts created this way are marked "email verified" because your employer asserted the address. We did not independently verify it.
- Removing you from the directory removes your access to that workspace. It does not delete your Demo Pine account or the demos you authored. Ask us if you want the account itself deleted.
- Your employer is the controller of this data. We act on their instructions.
We also store your employer's SSO configuration: claimed email domains, the identity provider's entity ID and sign-on URL, and its x.509 signing certificates. For SCIM we store only a SHA-256 hash of the access token plus a short prefix so it can be identified in the UI, and the time the token was last used.
2.5 Billing contacts and payment data
Payments are processed by Stripe. Card details are entered directly into Stripe's own payment form or its hosted checkout and never reach Demo Pine's servers. We do not store card numbers.
| What we send to Stripe | What Stripe sends back and we store |
|---|---|
| The email address of the admin who starts checkout, the workspace name, the plan, the seat count, and internal workspace identifiers. Stripe collects the billing address (and, where automatic tax is enabled, uses it for tax calculation) | Invoice numbers, amounts, tax, currency, line-item summaries, billing period, payment status, links to Stripe-hosted invoices and receipts, the card brand and last four digits, and any decline reason text |
We also store a complete copy of each webhook event Stripe sends us, as a billing audit trail. Those event payloads routinely contain the billing contact's name, email address, and billing address. We keep the payload for 18 months (548 days) from receipt, after which it is redacted in place rather than deleted — the row itself is the idempotency key that stops an old webhook redelivery re-applying its effect, so it has to survive even when its contents do not. See Section 11.1.
- Legal basis: performance of a contract, Art. 6(1)(b), and compliance with tax and accounting obligations, Art. 6(1)(c).
- Any member of a workspace, at any role, can view the workspace's invoice history, receipt links, card brand, and last four digits. If that is not appropriate for your team, limit who you add to the workspace.
- Billing receipts, payment-failure notices, and renewal notices are sent by Stripe, not by us. Stripe also acts as an independent controller for its own fraud-prevention and financial-crime obligations — see Section 8.
- Subscription terms, cancellation, and refunds are governed by our Terms of Service. In summary: you can cancel at any time, cancellation stops the next renewal, access continues to the end of the paid period, and fees are non-refundable except where the law requires otherwise or where Section 8 of this policy gives you an exit right over a new subprocessor.
2.6 AI usage records
If you use the built-in AI writing features, we record the feature used, the model, the credits consumed, and the input and output token counts. We do not store the prompt text, the screenshot, or the generated output. See Section 6.
- Legal basis: performance of a contract, Art. 6(1)(b), where AI credits are part of your plan, and legitimate interests, Art. 6(1)(f), in metering a paid feature and preventing abuse.
2.7 Visitors to demopine.com
Our marketing site is a static site published to Cloudflare Pages. The published pages set no cookies of our own, load no third-party scripts, run no analytics, and serve their web fonts from demopine.com itself — no font CDN or advertising network receives your IP address from those pages. Our hosting provider, Cloudflare, processes your IP address and request headers in the ordinary course of serving the page and keeps its own request logs, and may set its own security or bot-management cookies at the network level.
We do not operate a marketing mailing list, and we send no marketing email.
- Legal basis: legitimate interests, Art. 6(1)(f) — delivering and securing our website.
2.8 Support and correspondence
If you email us, we keep your message and our reply so we can help you and keep a record of the issue. Legal basis: legitimate interests, Art. 6(1)(f).
2.9 Demos published without an account
Demo Pine accepts published demos from people who have not signed in. If you build and publish a demo without an account, we store that demo's content — including its captured screenshots, video, audio, and page copies — and serve it at a public share link, exactly as we would for a signed-in customer.
Because there is no account attached to it, there is no signed-in deletion path that reaches it — no dashboard lists it and nobody can log in to unpublish it. Two things now limit that:
- a share link created without an account is scheduled for deletion 180 days after it was created, whether or not anyone asks — but note the job that enforces that schedule currently runs in dry-run and deletes nothing yet (see Section 11.1), so until we enable it, use the email route below; and
- if you created one and want it removed sooner, email [email protected] with the share link and we will delete it.
Demos published without an account always carry the "Made with Demo Pine" badge and cannot use paid appearance settings, because there is no plan behind them to check.
Old links that are converted when opened. Demo Pine used to offer a share link that carried the whole demo inside the URL itself, after the #. That part of a URL is never sent to a server, so we hold no copy of those demos and no record that any particular link exists. That format is retired. The first time anyone opens one of those older links, the demo it contains is sent to us, stored as an ordinary share, and the visitor is redirected to its new address — which means content that previously existed only inside a URL becomes content we hold, at that moment. Converted demos are treated exactly like any other demo published without an account: same badge, same 180-day schedule, same removal-on-request route above. If you would rather it were not stored, do not open the old link — and email [email protected] with it and we will delete the converted copy.
Legal basis: performance of a contract at your request, Art. 6(1)(b).
3. If you viewed a demo or filled in a demo form
This section is for people who have no Demo Pine account and simply opened a demo someone shared with them.
3.1 What happens when you open a share link
Opening a share link does not set a cookie of ours, does not store anything on your device, and does not create any analytics record in Demo Pine's application. If you never press play, our application records nothing about your visit.
As with any website, our CDN and hosting providers process your IP address and request headers in order to serve the page, and keep their own request logs. We do not control the contents or retention of those logs. See Section 8.
The "Made with Demo Pine" badge. Demos published on our free plan, and demos published by someone who was not signed in, show a small "Made with Demo Pine" badge in the corner of the player. It is a link to our marketing site. It sets nothing, reports nothing, and tells us nothing about you unless you click it — and if you do, you simply arrive at demopine.com. Whether the badge appears is decided from the demo owner's current plan each time the demo is loaded, not from anything about you.
3.2 What we record when you play a demo
Once playback starts, we record the following on behalf of the demo's owner:
| Recorded | Detail |
|---|---|
| Event type | One of: view, step viewed, hotspot clicked, demo completed, lead submitted |
| Playback session ID | A random identifier generated in your browser's memory each time the player loads. It is not a cookie, is not saved to your device, is regenerated if you restart the demo, and cannot link you across two demos or two visits |
| Step and hotspot identifiers | Which parts of the demo you reached |
| Share code and demo identifier | Which demo and link |
| Device class | "mobile", "tablet", or "desktop", derived from your browser's user-agent string. The user-agent string itself is discarded |
| Referring host | The hostname only of the page you came from — never the full URL |
| Country | A two-letter country code supplied by our CDN from your IP address |
| Timestamp | When the event occurred |
Demo Pine's analytics records do not include your IP address. We set no analytics cookies and use no cross-site or cross-demo identifiers. Your IP address is used transiently, in memory only, as a key for rate limiting to stop abuse of the endpoint; it is not written to our analytics database. Our infrastructure providers' request logs are a separate matter, described in Section 11.4.
Your browser sends these events in small batches, including one final batch when you close or navigate away from the page.
3.3 Lead-capture forms
Some demos ask for your name, work email, and company — or any subset of those — before playback starts, at a particular step, or at the end of the demo before its closing call-to-action. If you submit that form:
- The information is sent to Demo Pine's servers and stored, and is visible to the company that made the demo.
- We keep only those three fields, each truncated to 320 characters. We discard anything else submitted.
- The demo's owner can read it in their dashboard and export it to a CSV file, on plans that include full analytics and CSV export. Any member of their workspace, at any role, can do so. Once exported, what happens to it is entirely up to them.
- Lead forms can be switched on regardless of the demo owner's plan. On plans that do not include full analytics, submissions are still transmitted to us and stored, but the demo's owner cannot view or export them until they upgrade.
- Lead submissions are stored even if the demo is not published, unlike playback analytics, which are only recorded for demos that are live.
- Submissions are kept for 24 months from the day you submit them, unless deleted sooner by the demo's owner — see Section 11.1.
- We are the processor. The company that made the demo is the controller and is responsible for telling you why they are collecting it and on what legal basis.
You are told this in the player, before you submit. The lead form itself carries the line "What you enter is sent to Demo Pine and stored for the company that created this demo. They decide how it is used," directly above the submit button, with a link to this section. The demo's author sees a matching warning in the editor when they switch the form on: that submissions go to their workspace, that any member of it at any role can read and export them, that they are stored even while the demo is unpublished, and that the author is the controller. If you ever see wording inside a Demo Pine player that contradicts this section, this policy governs — please tell us at [email protected] so we can correct it.
3.4 Share links are public
A share link is a public URL protected only by a random 12-character code. While it is live, anyone who has the link can view the demo — there is no password, no email gate, and no domain restriction. Links can be indexed by search engines if they are posted publicly.
Share links are not permanent. A link stops working the moment the demo's owner unpublishes it, and also the moment they delete the demo — deletion revokes every link minted from that demo in the same database transaction, so there is no window in which the demo is gone but a link still serves it. The same revocation runs automatically if the demo disappears because the account or the workspace behind it was deleted. A revoked or expired link returns "This demo is no longer available." and never becomes live again: we keep the retired code as a marker so it is not handed out again while that marker exists. The markers themselves are removed after 90 days (180 days for a link created without an account) — see Section 11.1. See Section 11.2.
Media inside a published demo is embedded in the published copy itself rather than fetched from our storage bucket, so revoking the link takes the media with it. See Section 4.5.
If you are a Demo Pine customer: treat a live share link as public. If it contains something you would not publish, do not publish it. Revoking a link stops us serving it; it does not retrieve copies anyone already downloaded.
3.5 Exercising your rights as a viewer
Contact the company whose demo you viewed. If you do not know who that is, or they do not respond, email [email protected] with the share link and we will identify the customer and pass the request on. See Section 13.6.
4. Content our customers capture — an important warning
Demo Pine records real screens. That is the product. It also means captured content can contain personal data belonging to people who have never heard of us.
4.1 What a capture actually contains
A single captured step can include any of the following:
- A full screenshot of the browser tab as it appeared at the moment of the click, in JPEG form.
- A video recording of the tab, and — if the customer switched it on — the tab's audio.
- A complete copy of the page's HTML, cloned from the live document with only scripts,
<noscript>blocks, and iframes removed. Everything else is preserved verbatim, including any customer records, names, email addresses, order data, or other content that was rendered on the page. - The URL and title of the page, and the coordinates of the click.
- Structured details of the element clicked, including its visible text, accessible label, form label, placeholder, and — where the element is an input — the value it currently held. Text typed into a form during a recording can therefore be captured as text, separately from the pixels.
- The original filename of any file uploaded, which frequently reveals customer names or internal project labels.
Because the recorder captures the text content of form fields as well as the pixels, treat a recording session the way you would treat session-replay software: do not record while real users are entering their own data, and use test accounts and test data.
4.2 Whose responsibility this is
The customer who makes the recording is the controller of everything in it. Under our terms, customers must have a lawful basis for capturing and processing any personal data that appears on the screens they record, and must not capture data they are not entitled to process. We do not inspect, review, or moderate captured content, and we have no practical way to know what is inside it.
Our terms also prohibit using Demo Pine to capture, store, or publish:
- protected health information under HIPAA, or consumer health data as defined by the Washington My Health My Data Act or Nevada SB 370;
- data subject to the Gramm-Leach-Bliley Act or FERPA;
- biometric identifiers, precise geolocation, government identifiers, or other categories treated as sensitive under GDPR Art. 9 or US state privacy law, unless the customer has a lawful basis and, where required, opt-in consent.
Captures containing that material are a breach of our terms. If you believe a Demo Pine customer has published a demo containing your personal data, contact them first. You can also email [email protected] and we will route your request and, where appropriate under our terms, act.
4.3 The blur tool — what it does and does not do
The editor includes a blur tool. Please understand exactly what it does:
- It draws a blurred region over part of the image during editing and playback.
- It does not alter, redact, or remove the underlying pixels. The original, unblurred screenshot is what we store and what is included in a published share payload and in any exported bundle.
- A determined viewer who retrieves the underlying image file can therefore see what was blurred.
Blur is a presentation tool, not a redaction tool. If a screen contains data that genuinely must not be disclosed, do not capture it — use test or scrubbed data instead. We are working to make blur destructive at capture time; until this policy says otherwise, assume it is not.
4.4 Duplicating and exporting
- Duplicating a demo makes a second physical copy of every screenshot, video, audio file, and HTML clone. The copy is authored by the person who duplicated it and stays in the same workspace, visible to every member of it.
- Any workspace member, at any role, can download a complete export bundle containing the raw bytes of every captured asset in any demo in the workspace.
4.5 Where captured media is stored and who can reach it
All uploaded media — screenshots, video, audio, and HTML page copies — is stored in Cloudflare R2.
Media is no longer served from a public address. Every link the app hands out for a stored file is now a signed URL that expires one hour after it is issued. The signature is checked by the storage service on every request, so a link that has lapsed retrieves nothing. The app re-issues a fresh URL shortly before the old one expires, which is why editing sessions do not break. Stored files are marked private, and the API responses that carry these URLs are marked private, no-store so no browser or intermediary keeps a copy of them.
Published demos do not fetch the storage bucket at all. When a demo is published, its media bytes are embedded directly into the published copy. A viewer at a /s/<code> link therefore never receives a storage URL, and revoking the share link removes their access to the media along with everything else.
Two honest caveats:
- URLs issued before this change, under the old public
media.demopine.comaddress, keep working. Cutting them off requires detaching that public domain from the bucket in Cloudflare, which is an operational step we have to perform, not something the application code can do. Until we have completed it, any media URL that was copied, forwarded, logged, or captured in a browser's network tab while the old scheme was in place remains retrievable. This section will be updated to say the domain has been detached once it has been. In the meantime, assume that anything captured before this change may still be reachable by someone holding an old link. - A signed URL is still a bearer token for its one hour of life. Anyone you hand one to — or anyone reading your screen, your proxy logs, or a HAR file you export — can fetch that one file until it lapses.
Storage keys still contain your account identifier and the demo identifier as path segments. That no longer grants access to anything, because the signature is what is checked, but it does mean the identifiers are visible in a URL while it is live.
The underlying advice has not changed: do not capture screens containing data you would not be prepared to have leave your control. Access controls reduce exposure; they do not undo a capture.
5. The Demo Pine Capture Chrome extension
5.1 Permissions and why we need them
| Permission | What it allows | Why |
|---|---|---|
<all_urls> (host access to every site) | Access to any page you are on | You record your own product, which can be on any domain. We cannot know that domain in advance |
activeTab | Screenshot of the visible tab | Capturing each step |
tabs | The URL and title of tabs | Recording which page each step came from |
scripting | Injecting our capture script into the page you are recording | Detecting clicks, scrolls, and typing, and cloning the page's HTML |
tabCapture | A video (and, if enabled, audio) stream of the tab | Video capture mode |
offscreen | A hidden document that runs the recorder | Chrome requires this for media recording in Manifest V3 |
storage | Local extension storage | Remembering your Demo Pine address and in-progress recording state |
The extension can capture any http, https, or file page. It does not exclude banking sites, webmail, or internal admin tools. You are responsible for what you point it at.
Recording audio may be regulated. Several US states — including California, Illinois, Pennsylvania, Washington, and Massachusetts — and many other countries require the consent of every participant before a conversation is recorded. If you record tab audio while other people are speaking, for example during a video call, you are responsible for obtaining their consent first. Demo Pine does not obtain it for you.
5.2 What the extension stores and where data goes
- The extension itself makes no network requests and sends nothing to any third party. It contains no analytics or telemetry.
- In-progress recording state is held in Chrome's session storage and cleared when the browser closes.
- Your Demo Pine address (default
https://app.demopine.com) is stored in Chrome's sync storage and therefore replicates through your Chrome profile sync. You can change it. - When you stop a recording, the extension automatically opens Demo Pine in a new tab and hands the capture to it. If you are signed in, the app then uploads the screenshots, video, audio, and HTML clones to our storage without a separate confirmation step. Captured data does not stay on your device.
- If you are signed out, the capture is written to a database inside your browser instead — see Section 7.4.
5.3 Chrome Web Store limited-use commitments
As required by Google's Limited Use policy for Chrome extensions, we confirm that we do not sell data collected by the extension, do not transfer it for any purpose unrelated to the extension's single purpose of building product demos, and do not use it for creditworthiness or lending decisions.
6. AI features
6.1 The built-in AI writing assistant
If you use the built-in AI features to name a step or draft a caption, tooltip, or rewrite:
- We send the instruction text and the text you are working on to Anthropic PBC for processing. Where the step you are working on is a screenshot step, that screenshot is sent as well; screenshots larger than 5 MB are not sent, and no image is sent for video, page-capture, or audio steps. A screenshot sent this way may contain personal data captured from a real screen — see Section 4.
- We store only the feature used, the model, the credits consumed, and input and output token counts. We do not store the prompt, the image, or the generated text.
- We do not use customer content to train AI models. Our agreement with Anthropic PBC prohibits Anthropic from using inputs or outputs submitted through its commercial API to train its models, and we will not engage an AI subprocessor that does not make an equivalent commitment. If that ever changes, this policy will be updated before the change takes effect.
6.2 Bring your own API key
You can instead supply your own Anthropic API key.
- Your browser then calls Anthropic directly. The request never touches Demo Pine's servers, and we never see the prompt, the screenshot, or the result.
- Your relationship in that case is with Anthropic under your agreement with them. Our commitments in 6.1 cannot and do not extend to it. Anthropic will see your IP address.
- Your API key is stored in plain text in your browser's local storage. It is never sent to Demo Pine. Anything with access to that browser profile — including other extensions and developer tools — can read it. It is not currently cleared when you sign out or delete your account; clear it yourself from the AI settings panel, and prefer a key that is scoped and rate-limited for this use. We are changing the app to clear it on sign-out.
7. Cookies and browser storage
7.1 Do we show a cookie banner?
No. Every cookie and storage item listed below is either strictly necessary to provide a service you asked for, or a functional setting you set yourself. We use no analytics cookies, no advertising cookies, no tag manager, no session replay, and no cross-site advertising or profiling technology on either domain.
Some third-party requests are nonetheless made in the ordinary course of running the product, and we would rather name them than claim a blanket absence:
- Stripe loads its payment library on the billing page and sets its own fraud-prevention cookies there (Section 7.2).
- Google receives a request from your browser for your profile image on app pages, if you signed in with Google (Section 8).
- Cloudflare, as our CDN, may set network-level security or bot-management cookies.
If we ever introduce analytics, advertising, or any other non-essential technology, this policy will be updated and, where the law requires it, consent will be sought first.
7.2 Cookies
On demopine.com (marketing site): none set by us. Our CDN may set its own network-level security cookies.
On app.demopine.com:
| Name | Purpose | Duration | Flags | Party | Type |
|---|---|---|---|---|---|
__Secure-better-auth.session_token | Keeps you signed in. Holds a signed, opaque session token | 7 days, refreshed while you stay active | HttpOnly, Secure, SameSite=Lax, host-only | First | Strictly necessary |
dp_org | Remembers which workspace you are working in. It only selects — your actual permissions are re-checked on every request | 365 days | HttpOnly, SameSite=Lax, host-only. Not currently marked Secure — see note below | First | Strictly necessary / functional |
__Secure-better-auth.state | Protects the Google sign-in round trip against cross-site request forgery. Only set if you use Google sign-in | 5 minutes | HttpOnly, Secure, SameSite=Lax, signed | First | Strictly necessary |
Note on
dp_org. It is not currently set with theSecureattribute. It contains only a workspace identifier and confers no permissions — your access is re-checked against your membership on every request — but we are adding the flag. All traffic to app.demopine.com is served over HTTPS regardless.
On the billing page only, Stripe's payment library loads from js.stripe.com and sets its own cookies for fraud prevention (Stripe currently documents these as __stripe_mid, about one year, and __stripe_sid, about 30 minutes). Stripe is the controller of those cookies; see Stripe's own cookie policy for the authoritative list. Clicking through to Stripe's hosted billing portal, or to Google's sign-in page, takes you to their domains under their own policies.
We use no CSRF cookie — cross-site request forgery is blocked using request headers instead.
7.3 Local storage
| Key | Where | Purpose | Duration |
|---|---|---|---|
dp-theme | demopine.com | Light or dark theme, set when you click the toggle | Until you clear it |
arcade.aiKey | app.demopine.com | Your own Anthropic API key, in plain text, if you supply one | Until you clear it |
arcade.aiModel | app.demopine.com | Which model to use with your own key | Until you clear it |
demopine.brandTemplate | app.demopine.com | Your brand colours and logo, for signed-out use | Until you clear it |
demopine.migrate.<your account id>.* | app.demopine.com | Records that we already offered to migrate demos stored in this browser. These keys contain your account identifier | Until you clear it |
We use no session storage.
7.4 Browser database (IndexedDB)
The app maintains a database in your browser named demopine, holding local copies of demos and their captured media — screenshots, screen recordings, page HTML, and audio. This is how the editor works when you are not signed in: your captures have nowhere else to live, so they are kept on your own device until you create an account. It is read when we offer to migrate pre-account demos into your account.
It is not cleared when you sign out, and it is not cleared when you delete your account. If you have used Demo Pine signed out, copies of your captures may remain in that browser. To remove them, clear site data for app.demopine.com in your browser settings, or delete each demo individually from within the app. We are changing the app to clear this database on account deletion.
7.5 Extension storage
See Section 5.2.
8. Service providers, subprocessors, and independent controllers
Providers in the first table are bound by a written agreement limiting them to processing personal data on our documented instructions. Providers in the second table determine their own purposes for at least part of what they do and are governed by their own policies — we cannot instruct them, and requests about that processing must go to them.
8.1 Processors acting on our instructions
| Provider | Role | Data it receives | Primary location |
|---|---|---|---|
| Fly.io, Inc. | Application hosting for app.demopine.com | All request data in transit: credentials in transit, demo content, form submissions, SSO assertions, and application logs | United States (Ashburn, Virginia) |
| Neon, Inc. | Managed PostgreSQL database | All account, workspace, membership, invitation, billing, analytics, lead, and demo metadata | United States (AWS US East) |
| Cloudflare, Inc. | Object storage (R2) for all captured media and published-demo payloads, retrieved over expiring signed URLs (Section 4.5); CDN; hosting for demopine.com | Screenshots, video, audio, HTML clones, share payloads; visitor IP addresses and request headers. Uploads go directly from your browser to Cloudflare, so Cloudflare receives your IP address | Storage region: Eastern North America (ENAM); global CDN |
| Anthropic PBC | AI text generation for the built-in writing assistant | Prompt text and, for screenshot steps, the current step's screenshot, at the moment you use an AI feature. Not retained by us | United States |
| Zoho Corporation (ZeptoMail) | Transactional email only | Recipient email address and full message content, including password-reset links and workspace invitations | United States (our default endpoint; an EU endpoint is available) |
8.2 Independent controllers
| Provider | What it does | What it receives |
|---|---|---|
| Stripe, Inc. (and Stripe Payments Europe Ltd for EU customers) | Payments, subscriptions, invoicing, hosted billing portal. Stripe acts as our processor for the transaction records we instruct it to keep, and as an independent controller for fraud prevention, financial-crime compliance, and its own regulatory obligations | Billing contact email, workspace name, billing address, card details entered directly into Stripe, transaction records, and device signals collected by Stripe.js on the billing page. Stripe's own privacy policy governs its controller activities |
| Google LLC | Optional sign-in provider, and the host of your profile image if you signed in with Google | Your sign-in attempt, your IP address, our application identity; and, for avatar requests, your IP address and the referring page on each app page load. Google returns your email address, name, and profile image URL. We do not control and cannot instruct Google's use of that data |
Your own identity provider. If your employer connects SSO or SCIM, that provider is your employer's vendor, not ours. Your employer is responsible for what it sends us.
Email we send. We send exactly two kinds of email: password resets and workspace invitations. Every other message you receive about Demo Pine — receipts, payment failures, renewal notices — comes from Stripe.
Subprocessor changes. The table above is our current subprocessor list. We will give at least 30 days' notice before adding or replacing a subprocessor that processes customer personal data, by email to workspace owners where we hold a working address for them and by updating this page. If you are a customer and you reasonably object to a new subprocessor on data-protection grounds within that period, we will work with you in good faith to find an alternative; if we cannot, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused remainder of the term. This is a deliberate, narrow exception to our otherwise non-refundable fee policy.
9. International data transfers
Demo Pine is operated from the United States, and our infrastructure is hosted in the United States. If you are outside the United States, your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your home country.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on:
- the European Commission's Standard Contractual Clauses;
- the UK International Data Transfer Addendum for UK transfers;
- for Swiss transfers, the Standard Contractual Clauses with the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner, including references to Swiss law, the FDPIC as competent authority, and extension of protection to legal entities; and
- where a provider is certified under the EU-US Data Privacy Framework and its UK Extension and Swiss-US framework, that certification.
We carry out transfer impact assessments for our subprocessors and will share them with customers on request. You can request a copy of the relevant transfer mechanism from [email protected].
Demo Pine has no establishment in the European Union or the United Kingdom, so no single lead supervisory authority applies to us; you may complain to the authority in your country of residence or workplace. Our representative under Article 27 of the GDPR and the UK GDPR is: [[EU_UK_REPRESENTATIVE]].
10. How we share and disclose information
10.1 We do not sell your data
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and comparable US state laws. We have never done so, including in the twelve months before the date of this policy.
We run no advertising, no ad pixels, no marketing analytics, and no data brokerage. We do not use sensitive personal information for any purpose other than performing the service.
10.2 Who does see your data
- Other members of your workspace. Everything in a workspace is scoped to the workspace, not to the individual author. Any member — including a read-only viewer — can see every demo and its captured media, download full export bundles, read the member list with names and email addresses, view the billing history including card brand and last four digits, and (on plans that include full analytics) read and export lead names, email addresses, and companies. Choose workspace members accordingly.
- Anyone with a live published share link, as described in Section 3.4, for as long as that link is live; and anyone holding an unexpired signed media URL, or an old public-domain media URL issued before we made that change, as described in Section 4.5.
- Our subprocessors and the independent controllers listed in Section 8.
- Professional advisers — lawyers, accountants, auditors — under confidentiality obligations.
- A buyer or successor, if RyanTech LLC is involved in a merger, acquisition, financing, or sale of assets. We will notify you before your personal data becomes subject to a materially different privacy policy.
10.3 Government and law-enforcement requests
We require valid legal process before disclosing customer data. We will not disclose customer content in response to a request we believe is unlawful, overbroad, or improperly served, and we will seek to narrow or challenge such requests.
Where we are legally permitted, we will notify the affected customer before disclosing, and give them an opportunity to seek protective relief. If we are prohibited from notifying, we will seek to have that prohibition lifted. If we receive a request directed at data we hold as a processor, we will redirect the requester to our customer wherever legally possible.
As of the last-updated date of this policy, Demo Pine has never received a national-security request, a FISA order, or a national-security letter, and has never disclosed customer content to any government body. We will update this statement if that changes, to the extent we are legally permitted to.
We may also disclose information where necessary to protect our rights, the safety of any person, or to investigate fraud or abuse.
10.4 Copyright complaints
Demo Pine hosts content uploaded by its customers, including screenshots and copies of web pages. If you believe content published through Demo Pine infringes your copyright, send a notice complying with 17 U.S.C. § 512(c)(3) to our designated agent, whose registered details are published at https://demopine.com/dmca, or by email to [email protected] (postal notices to the address in Section 16).
We will respond in accordance with the DMCA, including by removing or disabling access to the material and notifying the customer, who may submit a counter-notification. Under our Terms of Service we will terminate, in appropriate circumstances, the accounts of users who are repeat infringers.
11. How long we keep data, and what deletion actually removes
11.1 Our retention position, stated honestly
Two things govern how long we keep data: the schedule below, which deletes records once their period runs out, and the ordinary rule that content you control is kept until you delete it or close the account.
The schedule. These are the periods we enforce. Each one is measured from the clock named in the third column, not from the day you signed up.
| Data | Kept for | Measured from | Status |
|---|---|---|---|
| Sign-in session records, including the stored IP address and user-agent | 30 days after the session expires | Session expiry (sessions expire after 7 days) | On |
| Password-reset and sign-in verification records | 7 days after the token expires | Token expiry (tokens last 1 hour) | On |
| Workspace invitations, including the invited person's email address | 90 days after the invitation is accepted, revoked, or expires | Whichever of those happened | On |
| Revoked or expired share codes, kept as markers so a retired code is never reissued | 90 days | Revocation or expiry | On |
| Share links created by someone who was not signed in | 180 days | When the link was created | On |
| Published-demo payloads with no surviving share record | 7 days | When the file was last written | On |
| Stored media files with no surviving database row | 7 days | When the file was last written | On |
| Demo analytics events (views, steps, hotspots, completions) | 400 days (13 months) | The event | On |
| Lead-capture submissions | 730 days (24 months) | The submission | On |
| AI usage records | The user identifier is removed at 90 days, leaving an unattributed counter; the record is deleted at 400 days | The AI request | On |
| AI credit counters for a closed billing period | 400 days | End of that period | On |
| Stripe webhook payloads | Redacted in place at 548 days (18 months). The record is not deleted — it is the key that stops an old webhook being replayed | When we received it | On |
| Empty workspaces (no members, no demos, no billing history) | 90 days | Last change to the workspace | Off at launch |
| Invoices and payments | 7 years — basis: tax, accounting, and audit law | Record creation | Off at launch |
Everything not in that table follows the ordinary rule: it lives as long as the account or workspace does. Your demos, their captured media, your brand kits, and your workspace membership are kept until you delete them, until a workspace admin deletes them, or until the account or workspace is deleted — see Sections 11.2 and 11.3. Records we need to resolve a live dispute or enforce our agreements are kept until that need ends.
Two things the schedule is not. The 400-day analytics period is a retention limit and applies on every plan. The 30-day analytics window on the free plan is a separate display limit: the underlying events are still there for the full 400 days, so a free workspace that upgrades sees its history. And the "Off at launch" rows are genuinely off — nothing deletes an empty workspace or a paid invoice today. If you want an empty workspace removed now, ask us.
How it runs, stated plainly. A dedicated background process runs once a day at 03:20 UTC and works through the categories above. Once it is deleting, it works in small batches and writes an audit record of every run; while it is in dry-run it only counts what it would remove and reports that to our application logs, so no audit record is written yet. If any one category is about to touch more than a quarter of its own table, it skips that category and reports it rather than proceeding — a safeguard against a mistaken period or a misconfigured connection. The other categories continue, and the check is not applied to tables with fewer than 1,000 rows.
The sweeper ships in dry-run mode. As of the date of this policy it reports what it would delete and deletes nothing. Enabling it is a configuration change on our side, made deliberately once we have reviewed the dry-run output against real data. Until we make it, the periods above are our published commitment and the deletions behind them are performed on request rather than automatically. We will not remove this note until the sweeper is live.
11.2 What you can delete yourself
| Action | What it removes |
|---|---|
| Delete a demo | The demo, its analytics, its leads, and its media files — and every share link ever published from it, which is revoked in the same transaction and stops working immediately |
| Reset a demo's analytics (admin only) | Every analytics event and every lead for that demo. This is the only way to erase lead data short of deleting the demo — there is no per-record lead deletion |
| Unpublish a demo | Revokes the share link and deletes the published copy. The link stops working immediately |
| Delete your account (Account → Danger zone) | See 11.3 |
Deleting a demo now revokes its share links. You no longer have to unpublish first. Deletion revokes every link minted from that demo in one transaction, including links published anonymously, so there is no committed state in which the demo is gone but a link is still live. The database enforces the same rule for every other route a demo can disappear by, including workspace and account deletion. A revoked link returns "This demo is no longer available." Revocation is checked before anything is served, so a link is dead the instant its record is revoked, even if the stored copy has not yet been cleared away. The retired code is kept as a marker and is never reissued while that marker survives; the markers themselves are cleared on the schedule in Section 11.1. What this does not do is reach copies already downloaded, or old media URLs issued under the public address described in Section 4.5. If you need something taken down and cannot reach the controls, email [email protected] with the link.
11.3 What deleting your account removes — and what survives
Deleting your account removes: your profile, your password and any linked Google account, all your sign-in sessions (with their stored IP addresses and user-agent strings), your workspace memberships, your personal brand presets, and every password-reset and verification record tied to you.
What happens to demos depends on whether anyone else is in the workspace, and it is now decided per workspace.
| The workspace | What happens to its demos, media, share links, analytics, and leads |
|---|---|
| You are the only member — your personal workspace, or a team everyone else has already left | The whole workspace is deleted. That destroys every demo in it, every screenshot, video, audio file, and HTML clone, every analytics event, every lead, its brand kits, and its share links, which are revoked as they go. This is what makes account deletion a real erasure rather than a rename |
| Somebody else is in it | Nothing that belongs to the workspace is destroyed. Your demos, their media, their share links, and the shared brand kit are reassigned to the workspace owner — and if you were the owner, another member is promoted first so the workspace always has one. Deleted with your account: your personal brand preset, any media you uploaded that was never attached to a demo, and any share link of yours that was not attached to a workspace. Your membership is dropped and the seat count is re-synced |
Demos authored inside a shared workspace are no longer destroyed when you delete your account. They belong to the workspace and stay with it. The earlier behaviour, where leaving a team took the team's demos with you, is gone. You should still tell your team you are leaving, because ownership of your work moves to them.
Deletion is refused while a paid plan is running. If a workspace that is solely yours still has a live subscription — active, trialing, past due, or unpaid — we will not delete the account, because nothing in this process cancels the plan at Stripe and you would keep being billed for a workspace that no longer exists. Cancel in Billing first, then delete. You will be told this if it happens.
The following survive account deletion, and you should know about them:
| What survives | Why |
|---|---|
| Invoices, payments (including card brand, last four digits, and decline reasons), subscription history, and the Stripe webhook records — which contain the billing contact's name, email address, and billing address | Required for tax, accounting, audit, and dispute-resolution purposes. Legal obligation, GDPR Art. 6(1)(c) and Art. 17(3)(b). Webhook payloads are redacted at 18 months (Section 11.1); the invoice and payment records are kept for 7 years. Note that a shared workspace keeps its own billing records regardless — they are the workspace's, not yours |
| Invitation records for people you invited, if the workspace itself survives | These belong to the workspace. They are deleted 90 days after the invitation closes (Section 11.1), or immediately if the workspace is deleted with you. Ask us and we will delete them sooner |
| AI usage counters for a workspace that survives | The individual's identifier is removed from AI usage records at 90 days, leaving an unattributed counter for billing purposes; the records are deleted at 400 days |
| Copies of demos duplicated by another workspace member | Those copies belong to the workspace they were made in |
| Share links you created while not signed in, and their stored copies | They were never attached to your account, so account deletion cannot find them. They are scheduled for deletion 180 days after creation, though that job is still in dry-run (Section 11.1); send us the link and we will delete one now |
Data in your own browser — the demopine IndexedDB database, your stored AI key, and local settings | We cannot reach your browser. Clear site data for app.demopine.com |
Where this section says "ask us and we will delete these", we will complete the deletion within 30 days of a verified request and confirm in writing when it is done. Our statutory response deadlines apply to these requests in the same way as any other; the fact that we currently perform some of these deletions by hand does not extend them. If you want a genuinely complete erasure, email [email protected] after deleting your account and we will remove everything above except the billing records we are legally required to keep, and anything that now belongs to a workspace you were sharing with other people — that is their data, and we will not delete it on your instruction.
11.4 Logs
Application error and diagnostic logs are written to our hosting provider's log stream. They can contain email addresses and technical diagnostics. They are not designed to capture credentials: they do not contain passwords (which we never hold in plaintext) or payment card data, and they do not contain Demo Pine analytics records of demo viewers' IP addresses.
Separately, our hosting, storage, and CDN providers maintain their own request logs, which do contain client IP addresses, for every request to demopine.com and app.demopine.com and for every retrieval of a stored media file. We do not control the contents of those logs, and their retention is controlled by those providers. See Section 8.
11.5 Backups
Our database provider maintains automated backups and point-in-time restore history. When data is deleted from the live service it is removed from our production systems immediately, but residual copies may persist in encrypted backups for up to 1 day before they are overwritten in the ordinary rotation. We do not restore deleted personal data from backup except to recover from a system failure, and if we do, we re-apply pending deletions immediately afterwards. Backups are encrypted at rest and are not accessible to our customers or used for ordinary operations.
12. Security
We describe only measures we actually have. We make no claim to any certification.
What we do:
- Passwords are stored only as salted scrypt hashes. We never store, log, or can recover a plaintext password. A minimum length of 12 characters and a strength check are enforced on both the client and the server, and passwords that resemble your name or email are rejected.
- Resetting your password revokes every other active session on your account.
- Session tokens are opaque and cryptographically signed, delivered in HttpOnly, Secure cookies that JavaScript cannot read.
- API tokens and invitation tokens are stored only as SHA-256 hashes; the plaintext is shown once and never again. Token comparison is constant-time.
- SAML assertions must be signed, are checked against a pinned audience, and are tied to email domains the customer has claimed. We do not retain the raw assertion.
- All traffic to demopine.com and app.demopine.com is served over HTTPS, and plain HTTP requests are redirected.
- Card data never touches our servers.
- Access control is enforced server-side on every request; the workspace cookie only selects a workspace and confers no permissions of its own.
- Captured media is access-controlled. Stored files are private and are retrieved only through a signed URL that expires after one hour; there is no public read path in the application, and the responses carrying those URLs are marked
private, no-store. Published demos embed their media rather than pointing at storage, so a demo viewer never receives a storage URL at all. See Section 4.5 for the one outstanding caveat. - Revocation is checked on the read path, not just written on the delete path. A share link is resolved by consulting its record first, so a revoked, expired, or unknown code is dead even if a stored copy of the demo survived a failed cleanup. Deleting a demo revokes its links in the same transaction, and a database trigger applies the same rule to every other route by which a demo can disappear.
- Rate limiting is applied to public endpoints to limit abuse.
- Our database and object storage providers encrypt data at rest as part of their platforms; we rely on their published commitments for that.
What we want you to know we do not do:
- We hold no SOC 2, ISO 27001, HIPAA, or PCI DSS certification or attestation, and we do not claim compliance with those frameworks.
- We do not currently run a formal penetration-testing programme or a bug-bounty programme.
- We have not yet finished retiring the old public media domain. The application no longer issues public media URLs, but URLs handed out under
media.demopine.combefore that change stay readable until we detach the public domain from the storage bucket, which is an operational step we still owe. Until then, anyone holding one of those older URLs can retrieve that file. See Section 4.5. - Our retention sweeper is running in dry-run mode. It reports what it would delete and deletes nothing until we enable it. See Section 11.1.
- We have no automated intrusion-detection system and no general-purpose security audit log. We do retain a billing webhook audit trail (described in Section 2.5) and a last-used timestamp for directory access tokens.
Reporting a vulnerability. Report vulnerabilities to [email protected]. If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, will not pursue civil action or refer the matter to law enforcement, and will work with you to understand and resolve the issue quickly. Please avoid privacy violations, data destruction, and service degradation, do not access or modify data belonging to others, and give us a reasonable time to remediate before public disclosure.
Breach notification. If a personal data breach occurs, we will notify affected customers without undue delay and in any event within 48 hours of becoming aware of it, so that they can meet their own notification deadlines. Where we are the controller, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms. We will comply with applicable US state breach-notification statutes, including notification to state Attorneys General where required. No system is perfectly secure.
13. Your privacy rights
13.1 Rights under the GDPR and UK GDPR
If you are in the EEA, the UK, or Switzerland, you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten"), subject to the exceptions in Section 11.3;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, including on grounds relating to your particular situation;
- data portability — receive data you gave us in a structured, machine-readable format and have it transmitted to another controller where technically feasible;
- withdraw consent at any time, where we rely on consent (we currently rely on consent for very little);
- lodge a complaint with your supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority in your country of residence or workplace. We would appreciate the chance to address your concern first.
Where we rely on legitimate interests, we have carried out a balancing assessment; you can request a summary of it from [email protected], and you can object to that processing at any time.
13.2 US state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota, Tennessee, Indiana, Kentucky, Rhode Island, Washington, or another state with a comprehensive privacy or consumer-health-data law, you may have the right to:
- know what personal information we collect, use, and disclose, and the categories of recipients;
- access a copy of that information, and obtain it in a portable format;
- correct inaccurate information;
- delete your information, subject to legal exceptions;
- opt out of sale, of sharing for cross-context behavioural advertising, and of profiling with legal or similarly significant effects. We do none of these things, so there is nothing to opt out of, and we do not publish a "Do Not Sell or Share My Personal Information" link;
- limit the use of sensitive personal information (see 13.2.2);
- not be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We offer no financial incentives in exchange for personal information.
13.2.1 Categories of personal information we collect
| Statutory category | Examples in Demo Pine | Sources | Business purpose | Disclosed to | Retention |
|---|---|---|---|---|---|
| Identifiers | Name, email address, account and workspace identifiers, session IP address, invited people's email addresses, SCIM external identifiers | You; your employer's identity provider; your browser | Account creation, authentication, access control, security, support | Hosting, database, and email providers (Section 8.1) | Life of the account, except where Section 11.1 sets a shorter period — sign-in session records 30 days past expiry, verification records 7 days past expiry, invitations 90 days after they close. See also the survivor list in 11.3 |
| Commercial information | Plan, seat count, invoices, payments, subscription history, card brand and last four digits, decline reasons | You; Stripe | Billing, tax, accounting, dispute resolution | Stripe; our accountants and auditors | At least the period required by tax and accounting law (generally 7 years); not deleted on account closure |
| Internet or other electronic network activity | Sign-in session records (IP, user-agent), demo playback events, step and hotspot interactions, referring hostname, device class, AI usage counters | Your browser; demo viewers' browsers | Security, product operation, analytics for the demo's owner, metering | Hosting and database providers | Demo analytics events: 400 days. AI usage records: user identifier removed at 90 days, record deleted at 400 days. Sign-in session records: 30 days past expiry. Or until you or a workspace admin delete the demo or account, whichever comes first. See Section 11.1 |
| Geolocation data | A two-letter country code supplied by our CDN. No precise location | Our CDN | Coarse analytics for the demo's owner | Hosting and database providers | Same as the analytics records — 400 days |
| Audio, electronic, visual, or similar information | Screenshots, screen recordings, tab audio, verbatim HTML page copies, captured element text and input values, uploaded filenames | Captured by our customers using the extension | Providing the demo product on the customer's instruction | Cloudflare (storage); Anthropic where a screenshot is sent to an AI feature; anyone with a live share link, or an unexpired signed media URL | Until deleted by the customer; see Sections 4.5 and 11 |
| Professional or employment-related information | Work email, company name, and role submitted through a lead form; workspace role; directory display name | Demo viewers; customers' directories | Providing lead capture and access control on the customer's instruction | Hosting and database providers; the customer who owns the demo | Lead submissions: 730 days, or until deleted by the customer or by analytics reset, whichever comes first. See Section 11.1 |
| Inferences | None. We draw no inferences and build no profiles | — | — | — | — |
13.2.2 Sensitive personal information
We collect account credentials — stored only as hashes — and, if you sign in with Google, OAuth tokens. Both are "sensitive personal information" under California law. Content captured by our customers may also contain sensitive information belonging to third parties; we process that content only as a service provider on our customer's instructions, and our terms prohibit capturing the categories listed in Section 4.2.
We use sensitive personal information only for the purposes permitted by California Civil Code § 1798.121(d) and the corresponding regulations — providing the service you requested, security, and fraud prevention — and never to infer characteristics about you. Because of that, we are not required to and do not offer a "Limit the Use of My Sensitive Personal Information" link.
Consumer health data. We do not knowingly collect consumer health data as defined by the Washington My Health My Data Act or Nevada SB 370. Our terms prohibit customers from capturing or publishing it through Demo Pine, and captures containing it are a breach of those terms. If you believe consumer health data about you has been published through Demo Pine, email [email protected] and we will act.
13.2.3 Do Not Track and Global Privacy Control
Demo Pine does not track you across third-party websites, so we take no action on Do Not Track browser signals — there is no cross-site tracking for them to switch off. Because we do not sell or share personal information, there is currently nothing for a Global Privacy Control signal to opt out of; if that ever changes, we will honour GPC signals.
Third parties whose resources load in our pages — currently Stripe on the billing page, and Google where you have chosen Google sign-in — may receive your IP address and the page you are on. We do not authorise them to build cross-site advertising profiles from it, and we receive nothing from them in return.
13.3 How to exercise your rights
Email [email protected] with the address you want us to act on and what you would like us to do.
- We will confirm receipt within 10 business days and tell you how we will process your request and when you can expect a response.
- We will respond within 30 days for GDPR/UK GDPR requests (extendable by two months for complex requests, with notice) and within 45 days for US state requests (extendable by a further 45 days, with notice).
- We do not charge for responding to a request. We may decline, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, in particular because of their repetitive character, and we will explain our reasons if we do.
- Where you ask for a copy of your data, we provide it in a structured, commonly used, machine-readable format (JSON or CSV).
There is no self-service "download all my data" button in Demo Pine. We handle access and portability requests manually. You can export your own demo content, including all captured media, as a bundle from within the app at any time. Lead and analytics CSV export is available on Pro and higher plans; Free plans can view the last 30 days of headline analytics only. For anything the app cannot export, we handle the request manually.
13.4 Verifying who you are
We will verify your identity before acting, in proportion to the sensitivity of the request. Ordinarily we ask you to send the request from the email address on the account and to confirm details only the account holder would know. Please note that email-address ownership alone is not conclusive — we do not require email verification at signup, and accounts created through an employer's directory are marked verified on the employer's word. For a deletion request we may ask you to authenticate in the app. We will not create an account or collect additional identity documents solely to process a request.
13.5 Authorised agents
You may use an authorised agent. We will ask the agent for written proof of authorisation and, in most cases, will ask you to confirm the authorisation directly.
13.6 If we are only the processor
Where your request concerns data we hold on a customer's behalf — a demo you viewed, a lead form you filled in, captured content in which you appear, or an account your employer created — we will:
- tell you promptly that we act as a processor and identify the customer where we are permitted to;
- forward your request to that customer; and
- assist them in responding, as our agreement with them requires.
We will not delete or alter a customer's data on the instruction of a third party except where the law requires it.
13.7 Appeals
If we decline your request, we will tell you why. You may appeal by replying to our decision with the word "Appeal" and any additional information. We will review and respond within 45 days (or sooner where state law requires). If we deny your appeal, you may complain to your state Attorney General, or — in the EEA or UK — to your supervisory authority.
13.8 Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not profile you for targeted advertising. Our AI writing features generate text at your request; they do not evaluate you, score you, or make decisions about you. If this ever changes we will update this policy and provide the information required by Article 13(2)(f) of the GDPR and the corresponding US state laws before the change takes effect.
14. Children
Demo Pine is a business tool. It is not directed to children, and we do not knowingly collect personal data from anyone under 16 through any channel.
- You must be at least 18 years old, or the age of majority where you live, to create a Demo Pine account, because using Demo Pine means entering a binding contract. If we learn that an account was created by someone under 18, we will close it.
- We set the "not directed to" threshold at 16 rather than 13 deliberately. Article 8 of the GDPR sets the default age of digital consent at 16, and Demo Pine collects an unusually broad range of content — including screen and audio recordings — where the more protective threshold is the right one. It also comfortably exceeds the 13-year floor set by the US Children's Online Privacy Protection Act.
- We do not operate an age-verification gate, and we have no way to know the age of someone who views a shared demo or fills in a lead form. Our customers are responsible for ensuring that the demos and lead-capture forms they publish are not directed to children and do not knowingly collect personal information from children under 13. Under our Terms, using Demo Pine to operate a child-directed service is prohibited.
- If we obtain actual knowledge that a lead-capture form has collected personal information from a child under 13, we will delete that record promptly, retain it no longer than necessary to do so, and notify the customer.
- If you believe a child under 16 has provided personal data to us, email [email protected]. We will delete the account and its data promptly.
15. Changes to this policy
We will update this policy when our practices change. The "Last updated" date at the top always reflects the current version, and this policy is always available at https://demopine.com/privacy.
If a change is material — for example, a new category of data, a new subprocessor that materially changes where your data goes, or any advertising or tracking technology — we will post the revised policy here before it takes effect, and where we are able to reach you by email, or where our agreement with a customer requires advance notice, we will also notify you directly.
We will not apply a materially different use to personal data we already hold without giving you notice and, where the law requires your consent, obtaining it first. Continuing to use Demo Pine after a non-material change indicates you have been notified of it; it does not constitute consent to any processing for which the law requires consent, and it does not modify our Terms of Service, which have their own amendment procedure.
16. How to contact us
RyanTech LLC (d/b/a Demo Pine) Postal address: 2764 Pleasant Road, Suite A #599, Fort Mill, SC 29708, USA
| What you need | Where to write |
|---|---|
| Privacy requests, data protection, DPAs, subprocessor questions | [email protected] |
| Security vulnerability reports | [email protected] |
| Copyright / DMCA notices | [email protected] (see Section 10.4) |
| Complaints about content published through Demo Pine | [email protected] |
| Everything else, including legal notices | [email protected] |
Terms and dispute resolution. If you have an account with Demo Pine, your agreement with us is our Terms of Service, which are governed by South Carolina law and include a binding individual arbitration provision, a jury-trial waiver, and a class-action waiver, with a small-claims carve-out and a 30-day right to opt out of arbitration. Those provisions apply only to people who have accepted the Terms. They do not apply to demo viewers, lead-form submitters, invitees, or anyone else who has not accepted them. Nothing in this privacy policy limits any statutory right you have to complain to a regulator or supervisory authority, or to bring a claim you cannot lawfully be required to arbitrate.
Data processing agreement. We make a Data Processing Addendum, including Standard Contractual Clauses and the UK Addendum, available to customers on request from [email protected].
Demo Pine is a product of RyanTech LLC. Cloudflare, Stripe, Anthropic, Google, Fly.io, Neon, and Zoho are trademarks of their respective owners.