← Back

Privacy Policy

Last updated: October 2026

What we collect

When you create a DemoVista account, we store your email address and the content you upload — screenshots, videos, notes, hotspots, and branding — to build and host your demos. If you invite teammates, we store their membership in your team. If you subscribe to a paid plan, billing is handled entirely by our payment processor (LemonSqueezy); we never see or store your card details, only your subscription status.

The DemoVista Recorder browser extension

The Recorder extension only activates while you have explicitly started a recording session from the DemoVista editor. While active, each click captures a screenshot of the current tab, the position of the element you clicked, and the names and positions of the buttons and links visible on that screen (so viewers can jump between the parts of your demo), and uploads them directly to the demo you're recording into. It does not read other page text, keystrokes or form data, and it collects nothing when a recording session isn't running.

The demo agent

When you start the demo agent, our cloud browser opens the web address you give it, clicks through the site to follow the flow you described, and saves a screenshot of each step to your demo. To decide each next step, the agent sends a screenshot of the current page, the text of its buttons, links and form fields, and your demo description to our AI provider (Anthropic). The agent only visits the site you asked for. If a link leads to another website, it goes back.

Test logins you type into the agent form are held in memory for that run only. They are never stored and never sent to the AI provider. The agent types them into the site's login form itself, and the email address is hidden from the recorded steps. On demo sites, payment fields only ever receive Stripe's public test card numbers.

People who view your demos

When someone opens a demo you shared, we record how they move through it so you can see what interested them: which steps they opened, which tabs or menus they jumped to, how long each screen was in front of them, and where they clicked on something the demo doesn't show (the name of that button or link). Each visit gets a random ID kept in the viewer's browser tab, and the demo shows viewers a short note that it records this. We don't store their IP address or device details. If your demo asks for an email, or the viewer opened a personal link you made for them (with a name you chose), that email or name is linked to their visit. You, as the demo's owner, decide to collect this and are responsible for telling your viewers about it where required.

We tell you about new visits with a notification in the app and, when email is set up, an email when a known viewer opens a demo. When a visit ends (the viewer closes the demo, or 30 minutes pass without activity) we email you a PDF report of that visit, with a copy to DemoVista's own support mailbox so we can look into problems you report. Once that email has gone out, we delete the visit's details from our database; the email copies are what remains. Personal links work only for the 1 to 7 days you choose when making them.

For agent-built demos we also keep, privately, the names and positions of the buttons and links visible on each recorded screen. That's what lets viewers jump between parts of the demo, and it's never shown to anyone as is.

Claude connector, API keys and saved test accounts

You can connect Claude (claude.ai, Claude Desktop or Claude Code) to DemoVista so it can create demos and run the agent for you. We only receive the details of each request Claude sends to DemoVista, such as the web address, the demo description and the steps to follow. We don't receive your Claude conversations.

Connection tokens and personal API keys are stored only as one-way hashes. Connection tokens expire after an hour and are renewed for up to 30 days. Logins you save for your own products are encrypted (AES-256-GCM), tied to the one website you saved them for, and only ever typed into that site. Claude only sees a saved account's name, its site and a shortened login name, never its password.

Automatic diagnosis and fixes

When a run doesn't finish every step, we automatically review what happened, using the same AI provider, to explain why and what to change. If the problem was on our side, we may re-run the same flow on the same website to test a fix. That test runs on an internal demo and costs you no coins. A fix is a short, site-specific instruction for the agent. It contains no personal data and only applies to that website.

How we use and store data

Your data is used solely to provide the DemoVista service to you and the teammates you invite. We don't sell your data or share it with third parties beyond the processors that run the service: Google Cloud / Firebase (accounts, database and file storage), Vercel (hosting and running the app), Anthropic (AI decisions for the demo agent and run diagnosis), Resend (sending notification and visit report emails) and LemonSqueezy (billing). Our AI provider doesn't use this data to train its models.

Data retention

Demos, their steps and screenshots are kept until you delete them. Agent run records (the checklist, the steps the agent took and the page text it saw) are deleted within a day after you delete their demo, and in any case after 90 days. Viewer visits and the recorded screen controls are deleted within a day after you delete their demo; a visit is also deleted as soon as its report has been emailed (and otherwise after 12 months), and visit notifications after 90 days. Copies of visit reports in our support mailbox are kept for up to 12 months. Personal links are deleted with their demo, or a week after they expire. If a Free account isn't used for 12 months, its demos are archived: their share links stop showing them, nothing is deleted, and signing in again restores them. Server logs are kept for a short time only.

Your controls

You can delete any demo, or an entire team, at any time from within the app — this permanently removes the associated content. You can also disconnect Claude, revoke API keys and delete saved test accounts at any time on the API keys page. On the Account page you can download all the data we hold about your account as a file, and delete your account: that permanently removes your account, your personal demos (with their steps, leads, analytics and files), agent runs, API keys, saved test accounts and coins, and removes you from your teams. Demos you made in a team stay with that team. We keep only what we must or need to prevent abuse: payment records (order number and account ID, for accounting), and a one-way hash of your email address so free trial demos aren't handed out again to the same address — neither can be turned back into your email or your data.

Contact

Questions about this policy or your data? Email demovista@outlook.com.