Privacy
As of 27 September 2026
This is a translation for convenience. The German version is legally binding.
Controller
Pascal Andreas Beck, Luisenstrasse 25, 8005 Zurich, Switzerland. Email: hello@cirlo.dev
What data we process
Account data (email, organization name), your end users' feedback reports (including their email address if they provide one), access to the GitHub repositories you share, and, once a paid plan is active, billing data via Stripe.
Technical data from the widget
When an end user sends a bug report, the widget also sends a repro package: the last clicks (a description of the element, only the field name for form fields), visited paths without query string, JavaScript errors and failed requests (method, URL without query string, status code, duration). Not captured: keystrokes, field contents, request and response bodies, headers, cookies, screenshots or video recordings. Strings that look like secrets are removed before storage. The app operator can turn capture off per project.
If an uncaught JavaScript error occurs in the app, the widget reports it even without a bug report: error message, file and page (without query strings) and the browser user agent. Requests that end in a server error (status 500 or higher) are reported the same way: method, URL without query string and status code, never request or response bodies. No personal details are sent. The same setting turns this off, as does the attribute data-errors="off" on the widget.
When a visitor leaves the app, the widget sends one anonymous summary: which pages were opened (path only, without query strings, identifiers in the address replaced by a placeholder), whether anything was tapped on the last page, and whether the device has a touchscreen. Only daily counters per page are stored. There are no cookies, no identifier, no stored IP address and no link to a person. Purpose: Cirlo marks a bug as fixed only after the app was used without it, and spots pages where many visitors give up. The same setting turns this off, as does the attribute data-visits="off" on the widget.
Data from Sentry
If you connect Sentry, Cirlo processes the error data Sentry sends: error type and message, the location in the code, the affected path without query string, severity, and the number of events and affected users. Sentry user profiles, IP addresses and session recordings are not processed. The Sentry access you provide is stored encrypted and used server-side only.
Data from Slack and Discord
If you connect a Slack or Discord channel, Cirlo processes the messages that arrive there as reports: in Slack every message in the selected channel, in Discord only what someone sends to Cirlo with /bug or via right-click. Stored are the text, the display name and the person's ID in that service, plus channel and thread so the reply arrives in the same place. Cirlo gets no email addresses from there. The connection credentials are stored encrypted and used server-side only.
Processing on your behalf
For your end users' reports we act as a processor on your behalf. You remain responsible for the legal basis and for informing your users. We sign a data processing agreement on request.
What for
To classify and group reports and narrow down the cause. Cirlo does not download or run your source code. With a connected repository, Cirlo reads the root file list and a few manifest files to detect the stack and test command, and files tasks as issues.
Usage of Cirlo itself
We measure how Cirlo is used to improve the product: projects created, connected sources, completed analyses, fixed messages sent, plan changes. This runs on our server only. There is no analytics script in the browser, no cookies and no cross-device tracking. Only the organization ID, the event type and technical figures are sent, never report contents and never data about reporters or your end users. Provider: PostHog (EU region).
Processors and location
We use these processors to run Cirlo:
- Supabase: database and sign-in, stored in the EU.
- Vercel: hosting, compute region Frankfurt.
- Resend: sending and receiving email, including messages to reporters.
- Inngest: queue for background jobs, contains report contents.
- Anthropic: AI analysis of reports. Anthropic does not use this data to train models.
- Stripe: payments, once a paid plan is active.
- PostHog: usage measurement, EU region (see above).
Vercel, Resend, Inngest, Anthropic and Stripe are US companies, so data may be processed there. Transfers rely on the Swiss-US and EU-US Data Privacy Framework or on the EU Commission's standard contractual clauses recognized by the Swiss data protection commissioner.
How long
Reports, issues and replies are kept until you delete them, the project or your account. Deletion takes effect immediately and covers all related data. Backups at our processors are overwritten according to their retention periods.
Your rights
You delete individual reports, issues and your whole account yourself in Cirlo. For access or an export of your data, write to hello@cirlo.dev.