Detected country: US
logo
Open AppStatusSubmit Ticket
GuideAPI References
‌
‌
‌
logo

Powered by

  • Home
  • Security & Compliance
  • Brainfish Privacy and Security Features

Brainfish Privacy and Security Features

6min read

Share

At Brainfish, we prioritise user privacy and data security while providing valuable insights through advanced analytics and AI. Below are the key features of our platform that ensure your data is protected and compliant with privacy laws such as GDPR and CCPA.


1. Real-Time Redaction of Sensitive Information (PII)

To protect user privacy, Brainfish ensures that any sensitive personal information (such as email addresses, phone numbers, and other personally identifiable information, or PII) is automatically redacted in real-time during screen recordings and screenshots. This means that sensitive data is hidden or anonymized during the recording or capturing process, ensuring that no PII is ever stored or shared unintentionally.

  • Example: If a user enters their email or phone number during a session, that information will be hidden or replaced with a placeholder like **** to protect their privacy.

2. Handling Sensitive Data in Screenshots (Redaction & Anonymization)

To further protect user privacy, Brainfish ensures that sensitive information is automatically redacted in real-time during screenshot captures. This means that Personally Identifiable Information (PII) such as email addresses, phone numbers, names, and other identifiable data are hidden or anonymized, ensuring that sensitive data is not exposed in the screenshot.

  • How does obfuscation work? Brainfish uses regular expressions (regex) to detect and redact sensitive information in real-time as it appears in screenshots. Once a sensitive data point is detected, it is automatically replaced with a placeholder or completely hidden from the screenshot. This process ensures that no PII is captured or stored.
    • Examples:
      • Email Address: Regex used: \b[A-Za-z0–9._%+-]+@[A-Za-z0–9.-]+\.[A-Za-z]{2,}\b Original Data: john.doe@example.com Obfuscated: @.com
      • Phone Numbers: Regex used: \b\d{3}[-.\s]??\d{3}[-.\s]??\d{4}\b Original Data: 123–456-7890 Obfuscated: --*
      • Credit Card Numbers: Regex used: \b(?:\d{4}[-.\s]?){3}\d{4}\b Original Data: 1234–5678-1234–9876 Obfuscated: ---
  • What data is excluded?
    • Usernames and user-specific data like account names or any login credentials are also obfuscated in real-time during screenshot captures to ensure they are not visible.
    • Payment Information: Any data entered during a transaction, including credit card numbers or billing addresses, is hidden in the screenshots.
  • What data is included?
    • The content of pages or interactions (such as buttons clicked, scroll depth, etc.) is included as long as no sensitive data like PII is exposed.
    • Any non-sensitive, non-PII information is visible and captured in the screenshot for analysis.

3. Cookieless Tracking for Enhanced Privacy

Brainfish takes a cookieless approach to tracking, which means we do not use cookies to track users. Instead, we rely on server-side tracking to gather valuable data without storing any information on a user’s device.

  • What does this mean for users? Users no longer need to deal with cookie consent popups every time they visit your site, and their privacy is better protected. Plus, it’s harder for ad blockers to interfere with the tracking, so you get more accurate data..

4. Data Retention and Deletion

We respect user privacy by automatically deleting data after a set period. For session recordings, the data is stored for a maximum of 365 days, after which it is permanently deleted.

  • What does this mean for users? You can rest assured that user data is not stored unnecessarily and is deleted according to privacy laws once it's no longer needed.

5. User Control Over Data

At Brainfish, we believe that users should have full control over their data. Therefore, we provide tools for data access and deletion:

  • Data Access Requests: Users can request a copy of all data that has been collected about them.
  • Data Deletion Requests: Users can request to have their data deleted from our system, which will be processed promptly.
  • Do Not Track (DNT): Users can enable the "Do Not Track" (DNT) feature in their browser settings, which will prevent Brainfish from collecting any tracking data during their session. This empowers users to opt out of tracking and ensures their interactions are not recorded if they choose.

6. Data Processing Agreements (DPA) and GDPR Compliance

Brainfish is fully GDPR and CCPA compliant, ensuring that your data processing activities meet strict privacy standards. We also offer the option to enter into a Data Processing Agreement (DPA) with you, clarifying how data is processed and protected.

  • What’s a DPA? It’s a legal agreement that outlines the responsibilities of both parties when handling personal data. This ensures compliance with privacy laws.

7. Anonymizing User Data in Session Recordings

To protect user privacy in session recordings, Brainfish anonymizes user data. This means that instead of recording identifying details like IP addresses or user names, we replace them with anonymous identifiers.

  • Why anonymize? This ensures that even if someone accesses the session recordings, they won’t be able to link the actions back to an individual user.

8. Session Identifiers Instead of Personal Information

Instead of storing personally identifiable information such as emails or names in session data, Brainfish uses session identifiers. These identifiers are random strings of characters, ensuring that no personal data is tied to the session.

  • What does this mean? It reduces the risk of exposing personal data while still allowing you to track and analyse user interactions.

FAQs - Answering Your Questions

  1. What data does Brainfish track? Brainfish tracks user interactions such as page views, click events, session duration, scroll depth, and outbound links (e.g., clicking a link to another website). We also collect technical data such as device type, browser, and screen resolution. This information helps us improve website performance and enhance the user experience, while ensuring privacy and security.
  2. How does Brainfish protect sensitive data in screenshots? Brainfish uses real-time redaction techniques during the screenshot capture process to automatically hide sensitive information such as email addresses, phone numbers, credit card numbers, and other personal data. This ensures that no Personally Identifiable Information (PII) is captured or exposed in the screenshots. For example:
    • Email Addresses: Redacted as **** (e.g., john.doe@example.com becomes ****)
    • Phone Numbers: Redacted as **** (e.g., 123–456-7890 becomes ****)
  3. What is the benefit of cookieless tracking? Cookieless tracking improves user privacy by avoiding the use of cookies for tracking purposes. This means no intrusive consent popups are required. Additionally, this method is less likely to be blocked by ad blockers, ensuring better accuracy in data collection and a seamless user experience.
  4. Does Brainfish use cookies for tracking? No, Brainfish does not use cookies for tracking. Instead, we rely on server-side tracking and local storage to gather analytics, which allows us to collect data without storing anything on the user's device, ensuring privacy is maintained.
  5. Can users request access to the data Brainfish has collected? Yes, users can request access to the data that Brainfish has collected about them. If you wish to see what data has been recorded, you can contact us, and we will provide a way to deliver this information in compliance with privacy laws.
  6. Can users ask for their data to be deleted? Yes, users can request that their data be deleted at any time. Once a data deletion request is made, we ensure that all related data is promptly and securely removed from our systems, in compliance with privacy regulations.
  7. Can users opt-out of being tracked or recorded? Yes, users can opt-out of screen recording at any time and can also request their data to be deleted. We prioritize user control and ensure that you have full autonomy over your data.

Share