A note for self-hosted installations
OpenJam is self-hostable. The organization or person operating the OpenJam server you use is the controller of information stored on that deployment. Their hosting, access, backup, and retention practices may differ. Ask your deployment administrator if you need details specific to your instance.
01
Scope
This Privacy Policy applies to the OpenJam web application, API, and official browser extension (together, the “Service”). It applies when you create or use an account, capture or view a bug report (a “jam”), submit a recording through a recording link, comment, collaborate in a workspace, or use a public share link.
It does not govern the privacy practices of a website you choose to capture, your browser vendor, or an independently operated OpenJam deployment beyond how the OpenJam software itself works.
02
Information we handle
The Service may handle the following categories of information:
Account and workspace
Name, email address, password hash, optional profile image, workspace membership, roles, invitations, and session credentials. OpenJam does not store your plain-text password.
Capture content
Screenshots, tab or screen recordings, instant replay data, page content visible in a capture, capture title and description, and the captured page URL.
Diagnostic context
Console messages and errors; request URLs, methods, status, timing, headers, and limited text request or response bodies; clicks, scrolls, navigation, and input interactions; browser, operating system, viewport, language, and timezone.
Collaboration
Comments, replies, reactions, folders, public-link settings, recording-link submissions, and other information you choose to add to a jam.
Service and local data
Request method, path, and status in server logs; theme and selected-workspace preferences in browser storage; and temporary extension recording state and bounded diagnostic buffers.
03
How the browser extension works
The extension needs access to webpages because a bug can occur on any page you choose to debug. It locally maintains bounded diagnostic buffers so recent context is available when you create a report. A screenshot, tab or screen recording, or armed instant replay starts only after an action you take in the extension or capture UI.
Privacy protections built into capture
- Input values are masked in DOM replay data.
- Canvas content is not recorded in DOM replay data.
Authorization,Cookie,Set-Cookie, andX-API-Keyheader values are redacted before diagnostic data is stored or uploaded.- Captured text request and response bodies are limited in size.
- The extension does not block, redirect, or modify website network requests.
- It does not use captured information for advertising, sell it, or build cross-site browsing profiles.
Please review before sharing. Screenshots, recordings, console output, page text, URLs, and request or response bodies can still contain personal, confidential, or sensitive information. Only capture pages you are authorized to record.
Extension permissions
OpenJam uses browser permissions for the active tab, website access, tab capture, offscreen media recording, local/session storage, network observation, and access to the OpenJam session cookie. Cookie access is limited to the session cookie for the configured OpenJam API and is used only to authenticate your requests. OpenJam does not read cookies belonging to unrelated websites.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
04
How the web application works
The web application lets you create and manage an account and workspaces; view, organize, edit, archive, and delete jams; invite members; create recording links; and collaborate through comments and reactions. Public recording links can capture a screen or window only after the submitting user grants the browser's screen-sharing permission.
Authentication uses an OpenJam session cookie. The session normally expires after 30 days and can be ended by logging out. The web application also stores your theme and selected workspace locally in your browser. The current OpenJam code does not include advertising trackers or third-party analytics.
05
How information is used
Information is used only as needed to:
- provide, authenticate, maintain, and secure the Service;
- create, store, display, organize, and share jams at your direction;
- attach diagnostic context to reports and synchronize it with playback;
- support workspace membership, comments, reactions, and invitations;
- troubleshoot failures, enforce technical limits, and prevent abuse; and
- comply with applicable law and protect users, operators, and the Service.
OpenJam does not sell personal information. OpenJam does not use capture content, browsing activity, or authentication information for targeted advertising, credit decisions, or purposes unrelated to the Service's single purpose of creating and collaborating on bug reports.
07
Storage and retention
Account, workspace, jam, asset, and collaboration data is stored on infrastructure configured by the deployment operator. It is generally kept until a user with access deletes the relevant jam or the operator removes the workspace, account, or deployment, subject to backups, legal obligations, and operational needs. Deleting a jam removes its database record and initiates deletion of its stored capture assets; residual backup or orphaned copies may remain until the operator's cleanup cycle completes.
Temporary extension data can be kept in memory, browser session storage, local storage, or extension IndexedDB to maintain bounded diagnostic history and recover an in-progress capture if the extension's background worker stops. Pending capture data is cleared when you submit or delete it through the capture workflow; session-scoped data may also be cleared by the browser.
Exact server-log, backup, and deletion schedules depend on the deployment operator. Data may be processed in any location where that operator or its infrastructure providers operate.
08
Your choices and rights
You control much of the information handled by OpenJam. You can:
- choose whether to start a screenshot, recording, or instant replay;
- review and delete a pending capture instead of submitting it;
- edit or delete jams and comments where the Service gives you permission;
- enable or revoke public share links;
- disable or uninstall the extension and clear its data in your browser;
- log out to end the current session; and
- ask your deployment administrator to provide access to, correct, export, or delete your personal information, subject to applicable law.
OpenJam does not currently provide a self-service account deletion control. Contact the administrator of the OpenJam deployment you use for account-level privacy requests.
09
Security
OpenJam uses safeguards including one-way password hashing, hashed server-side session tokens, restricted workspace access, private-by-default sharing, sensitive-header redaction, and time-limited signed asset URLs. Deployment operators are responsible for configuring transport encryption, credentials, network access, backups, updates, and other infrastructure protections. No system is completely secure, so review capture content carefully and report suspected unauthorized access promptly.
10
Children's privacy
OpenJam is a professional collaboration and debugging tool and is not directed to children under 13. If you believe a child has provided personal information through a deployment, contact that deployment's administrator so the information can be reviewed and deleted where appropriate.
11
Changes to this policy
This policy may be updated when OpenJam's features, data practices, or legal obligations change. The effective date at the top will be revised when that happens. A deployment operator may also maintain additional terms or notices that apply to its installation.
12
Contact
For questions, requests, or complaints about information stored by your OpenJam instance, contact the organization or administrator that provided your account. For the official browser extension, use the support contact shown on its browser-store listing. Include the deployment address and workspace name, but do not send passwords, session tokens, or sensitive capture content in your request.