Privacy Policy

Last updated: June 12, 2026

Introduction

Stubborn Mule Software LLC ("we," "our," or "us") operates Vizzly, a visual testing and review platform available at vizzly.dev and related Vizzly domains (the "Service"). This Privacy Policy explains what we collect, why we collect it, how we share it, and the choices you have.

If you use Vizzly on behalf of an organization, that organization controls the projects, screenshots, builds, review decisions, and integration data submitted to the Service. You should only submit content and personal information that you are authorized to share with Vizzly.

Vizzly is built to collect the practical information needed to run the product, support customers, and keep the service reliable. We do not run an advertising network, sell personal information, or ask for sensitive data unless it is needed for the Service.

Information We Collect

Account and Organization Information

We collect information you provide when you create an account, join an organization, manage a team, or configure your profile:

  • Name, email address, password credentials, and email verification status
  • Authentication method, such as password, Google sign-in, or passkey
  • Organization membership, roles, invitations, and team activity
  • Profile details, preferences, avatars, and organization logos you upload
  • Support messages, administrative requests, and communication preferences

Product Content

Vizzly processes the content you and your team submit to run visual reviews:

  • Screenshots, approved baselines, generated diffs, thumbnails, and metadata
  • Project, build, branch, commit, pull request, browser, viewport, and OS metadata
  • Comments, review decisions, statuses, and build activity
  • Screenshot properties and public screenshot mappings
  • Preview-hosting files and static site assets you upload for review
  • API, CLI, SDK, and coding-agent context submitted to or generated by the Service

Integrations and Authentication Data

If you connect integrations or authentication providers, we collect the information needed to make those features work:

  • GitHub repository metadata, commit details, branch and pull request data, check runs, installation data, webhook events, and GitHub profile information
  • Google OAuth profile information, such as your Google account ID, email, name, and profile picture, when you choose Google sign-in or account linking
  • OAuth access, refresh, and identity tokens where needed for authorized features; those tokens are stored in encrypted form
  • Passkey credential metadata, including credential ID, public key, sign-in counter, transports, and a user-provided credential name
  • API token metadata, token hashes, device authorization records, and usage details

Vizzly does not receive your biometric data when you use a passkey. Biometric checks, if any, happen on your device or authenticator.

Billing Information

Paid plans are processed by Stripe. We receive billing metadata such as customer, subscription, invoice, plan, payment status, and usage information, but not your full payment card details.

Support and Chat Information

If you contact us for support or use live chat, we collect the message you send and the context needed to help you. For signed-in users, that may include your name, email, avatar, user ID, organization, role, and the page or route where you asked for help. Anonymous visitors may still send page or route context so support can understand what they were looking at.

Technical and Usage Data

We collect technical data to operate, secure, debug, and improve the Service:

  • IP address, user agent, device, browser, operating system, and viewport details
  • Request logs, API usage, response times, error rates, and storage consumption
  • Security events, authentication attempts, rate-limit events, and audit logs
  • Error, performance, and content security policy reports, including Sentry events
  • Feature usage, navigation events, and operational telemetry

How We Use Your Information

We use the information we collect to:

  • Provide, operate, maintain, and improve Vizzly
  • Authenticate users, manage sessions, support passkeys, and secure accounts
  • Process screenshots, visual diffs, baselines, previews, and review workflows
  • Publish public projects, screenshots, properties, or preview links when enabled
  • Create GitHub checks, comments, status updates, and integration workflows
  • Measure storage, retention, plan limits, and billing usage
  • Send transactional emails, security notices, billing notices, and support messages
  • Detect, investigate, and prevent fraud, abuse, security issues, and service misuse
  • Debug errors, monitor performance, and improve reliability
  • Comply with legal obligations and enforce our Terms of Service

Information Sharing and Disclosure

We do not sell personal information or use it for targeted advertising. We share information only as needed to provide the Service, follow your settings, comply with law, or protect Vizzly and our users.

Service Providers

We use service providers that help us run Vizzly, including:

  • Stripe: subscription billing, invoices, taxes, and payment status
  • GitHub: repository integrations, check runs, pull request workflows, webhook events, and OAuth or GitHub App authorization
  • Google: OAuth sign-in and account linking when you choose it
  • Postmark: transactional email delivery and delivery diagnostics
  • Snoot: live chat and support, including chat messages, page context, and signed-in user or organization context when available
  • Sentry: error reporting, performance monitoring, debugging context, and content security policy reports
  • Cloudflare R2 and compatible storage services: screenshots, diffs, thumbnails, preview assets, generated files, and related access logs

Team and Public Sharing

Organization members may see project data, build history, screenshots, comments, review decisions, and integration activity according to their role. If you enable a public project, public screenshot property, public screenshot, public preview, or shareable link, the selected content may be accessible outside your organization.

Legal and Safety Disclosures

We may disclose information if we believe it is reasonably necessary to comply with law, respond to lawful requests, enforce our Terms, protect rights or safety, detect abuse, investigate security issues, or preserve the integrity of the Service.

Business Transfers

If Vizzly is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy or comparable protections.

Retention

We keep information for as long as needed to provide the Service, honor your settings, meet legal obligations, resolve disputes, maintain security, and enforce agreements. Retention depends on the type of information and your plan.

  • Account, organization, and billing records are generally kept while your account exists.
  • Screenshots, diffs, builds, previews, and related assets follow plan retention, manual deletion, project deletion, account deletion, and operational cleanup rules.
  • Current plan retention periods are generally 30 days for Free, 90 days for Open Source and Starter, 365 days for Team, and custom for Enterprise.
  • Billing and tax records may be retained longer where required by law or accounting obligations.
  • Security logs, audit logs, backups, and error reports may be retained for different operational periods where needed for safety, reliability, or legal compliance.

Cookies and Sessions

We use a small number of essential cookies and similar technologies to keep you signed in, protect your account, route authenticated API requests, and understand whether a browser has an active Vizzly session. Some authentication cookies are HTTP-only and scoped to API routes. Vizzly may also set a non-sensitive session indicator that client-side code can read to update the interface.

We do not use cookies for cross-site advertising. Support chat and infrastructure providers may use their own lightweight storage or request metadata to make their services work.

You can control cookies through your browser settings, but blocking essential cookies may prevent sign-in, passkeys, OAuth flows, or other core Service features from working correctly.

Security

We use technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit, restricted access, token protections, audit logging, and service monitoring. No internet service is completely secure, so we cannot guarantee absolute security.

Where Information Is Processed

Vizzly is operated from the United States. Our service providers may process information in the United States and other countries where they operate. If you need specific enterprise privacy paperwork, custom retention terms, or data processing terms, contact us at privacy@vizzly.dev.

Account and Privacy Requests

You can contact us at privacy@vizzly.dev to ask for help with personal information associated with your account. Depending on your request and the data involved, we can help you:

  • Access account information we have about you
  • Correct inaccurate or incomplete account information
  • Delete account information, subject to legal and operational exceptions
  • Export available account or project information where supported
  • Close your account or disconnect optional integrations

We may need to verify your identity and authority before acting on a request. For organization-controlled data, we may direct you to the organization administrator or process the request in coordination with that organization.

Contact

If you have questions about this Privacy Policy or how Vizzly handles personal information, contact us at:

Stubborn Mule Software LLC

Email: privacy@vizzly.dev