What Bleap collects.
Bleap is operated by Varun as an independent product. This notice describes the evaluation service and its website tracker. Contact varun@bigleap.app for privacy, access, correction, or deletion requests.
Your Bleap account
We store your name, email, password hash, verification status, and session records to provide account access. Authentication session records can include IP address and user-agent details for account security. We use a session cookie to keep you signed in.
Analytics on an installed website
When the website permits collection, the tracker sends a random session identifier, sanitized page path, event category, coarse target category, timing, device category, and aggregate interaction features. It can also receive conversion names and optional values configured by the website owner.
Pointer coordinates are processed in the browser to compute aggregate features. Bleap does not send or store raw pointer trails, screen recordings, entered text, page text, or full URLs with query strings. Path redaction is a best-effort safeguard. Site owners must avoid placing personal information in paths or configured event names.
A short-lived identifier in session storage links a visit within a browser tab. We do not create a cross-site advertising identifier. Global Privacy Control and Do Not Track disable collection. Without an explicit collection grant, the script waits.
Why we use the data
Website owners use the dashboard to understand observed sessions, interactions, outcomes, and experimental automation and AI estimates. We use account and operational data to provide the service, address support requests, limit abuse, and investigate errors. Behavioral estimates do not establish anyone’s identity. See the methodology.
Service providers and access
The application and database run on Google Cloud in the United States. Emailit sends account verification, password reset, and operational messages. These providers receive the information needed to deliver their service. Website analytics are visible to the relevant workspace and to the operator when needed for support and operations. We do not sell visitor data or use it for advertising targeting.
Web requests necessarily expose connection metadata to hosting infrastructure. Operational and provider logs may retain request metadata under the applicable service settings. Passwords, authentication tokens, and raw analytics payloads are excluded from application logs.
Retention and deletion
Site owners choose 7, 14, or 30 days of session-detail retention. Deleting a site removes its live sessions and events and revokes its tracker key. Deleting your account removes your owned workspace and sites. Backups are retained separately for recovery and age out under the configured backup policy; deleting live data does not instantly rewrite backups.
Account data remains while your account is open. We retain email delivery metadata for up to 30 days. Commercial inquiries are retained to respond and follow up; ask us to remove them when no longer needed. Infrastructure and email-provider retention may differ.
Site-owner responsibilities and visitor choices
Only install Bleap on websites you manage and are authorized to measure. Explain the collection in your own notice, obtain consent when needed, honor visitor choices, and avoid sensitive or children’s data. Visitors can contact the website owner about its analytics or use supported browser privacy controls. The owner decides where and why the tracker is installed.
Changes
We will update this notice when the service’s data practices change. Material changes will be communicated through the service or account email when appropriate.