Privacy Policy
Last updated: 17 August 2026.
This policy describes how Walkstamp works today: the tool has no processing server, and there is an
optional account — described below — for anyone on a paid plan.
Until 14 August 2026 this service was called ClipContext. Only the name changed — the controller, the legal bases and the retention periods below are exactly the same.
Who is responsible
Walkstamp is offered by Produtize Produtos e Serviços Inteligentes Ltda., a company registered in Brazil under CNPJ 48.417.292/0001-99, acting as the controller of the small amount of personal data described in this policy, under Brazilian Law 13,709/2018 (LGPD).
Data subject requests, questions and privacy complaints: privacidade@walkstamp.com. This is also the channel for the data protection officer (LGPD art. 41).
Summary
We do not receive your videos, your audio, your frames, your transcripts or the documents you generate. That has not changed, it holds on every plan, and it is the promise the product rests on — not a setting we can loosen later.
What does exist is this, all detailed below: a page-view count with no cookie and no identifier; an anonymous count of fifteen usage milestones; your e-mail, if you leave it on the pricing page; and, for anyone on a paid plan, an account — holding the sign-in e-mail, the invoices, the support tickets and the list of cases to run, if you use the test-run screen. Using the tool still requires no account: signed out, it records, transcribes and generates documents exactly the same.
How the service works
Walkstamp is a static page. When you choose a video, it is read directly from your device by the browser and stays there. Extracting the images, reading the audio, transcribing it and assembling the PDF all happen entirely on your computer, using its processing power.
The file is never sent to us. There is no temporary copy on our systems, because no system of ours is involved in the processing.
Data we do not collect
- Videos, audio, extracted images, transcripts and generated PDFs
- File name, size, duration or any characteristic of what you process
- Name, phone number or personal identifier — and your e-mail only if you type one, by your choice
- Tracking identifiers, behavioural profiles or advertising data
- Tracking, advertising or measurement cookies — none. The account uses a session cookie, which is what keeps you signed in; it is described in the “Paid account” section, and the tool works without it
What is measured, and why
A tool nobody knows is being used cannot be improved in the right place. So there are two measurements, and both were designed not to know who you are:
- Page views, through Vercel Web Analytics. No cookie and no identifier that persists between visits. It tells us how many people arrived and by which route.
- Fifteen usage milestones, inside the tool: that it was opened, that a video was opened successfully, and that an output file was downloaded. Alongside goes the page language, where the video came from (file, Drive, recording or sample) and the format downloaded. Nothing else. No file name, size, duration, content or session identifier — there is no way to tie two milestones to the same person, or this visit to the next.
If your browser sends Do Not Track or Global Privacy Control, the three milestones are not sent. And the offline version — the single file you download — is built with no measurement address inside it at all: it talks to nobody, and you can check that by searching the file for “supabase”.
The notification list no longer exists
The pricing page once had an optional e-mail field, to tell you when the paid plan existed. The paid plan exists, and the field is gone: there is nothing here any more that collects the address of someone who is only visiting the site. Addresses left while the field existed are kept for up to 24 months after they were left, and are deleted sooner on request, through the contact at the end of this page. They were never cross-referenced with the measurements above, never sold or shared, and are used for nothing else.
The paid-plan account, and the test run
Anyone on a paid plan gets an account. It is the only place where we store data of yours by your choice, and it is where the one feature that writes customer content to a server of ours lives: the test-run screen. That is why it is described here field by field.
The account holds:
- the sign-in e-mail, which is the identity of the account and where the sign-in link goes;
- the invoices and subscription status, coming from Stripe;
- the support tickets you open, with the text you wrote;
- on the Team plan, the seats: each team member's e-mail and what they have issued;
- the document templates and the branding you configure (company name, logo address, label, environment).
And, if you use the test run, it holds the fields of the task list, and nothing else: the case code, the title, the system, the ticket number, the owner's e-mail, the date the case was marked done, who marked it, the name of the generated file, its fingerprint and any note you type.
When you mark a case done, a receipt is stored too: the record of what was run (case, scenario, system, ticket, environment, result, date and format) and the fingerprint of every frame, in order. Those are numbers. It travels inside the return link itself, and it is what lets you take a document months later and check that it is the same one.
What the receipt never contains: images, transcripts or step text. The fingerprint is computed from the screens and does not allow any image to be reconstructed. The spreadsheet you upload to create a run is read, becomes the rows described above, and the file is discarded: we do not store the spreadsheet.
The session attachment — the one exception, and it is yours
When you confirm a case as done there is an optional field: attach the complete
.json of that session. That file has the frame images inside it, along with the
step text and the transcript, if there is one.
Attaching it is the only thing in this product that puts content of yours on a server of ours. Because of that, and without exception:
- it never goes on its own — the field starts closed and you have to pick the file;
- what it means is written next to the field, at the moment of the choice, not only here;
- it lives in private storage with no public address: downloading goes through our server, which checks your session and returns a signed address that expires in two minutes;
- whoever can see the case can see the attachment — on a team run, that is the whole team;
- there is a delete attachment button, and it deletes the file, not just the record pointing at it;
- the limit is 32 MB per case, and only
.jsonfiles are accepted.
Your video and audio still never leave your browser, attachment or no attachment. With no attachment, only the receipt is kept — numbers, no images.
Note what that means in practice: a run is a work list, and a case code or a ticket number can say what your company is testing. Write in those fields what you would write on a task-board card — system names and ticket numbers, fine; someone else's personal data, no.
A run marked “team” is visible to everyone with a seat on the same account; a “mine only” run is visible only to whoever created it. Whoever created a run can delete it at any time, and deleting takes all of its cases — and the files attached to them — with it, immediately and with no copy.
You do not have to ask: the account deletes it itself
Inside the account there is a screen — Your data — that lists, in plain language, everything that exists on our server under your name: how many case scripts, how many cases, how many attached files, how many templates, how many tickets. And it lists, beside it and with the same weight, what does not go when you delete, and why. On the same screen there is a button that deletes everything of yours, right away, without talking to anyone and without waiting for any period to run. It asks you to type your own e-mail first, because there is no undo.
When the subscription ends, the account's content is deleted within 90 days, by a routine that runs every day: runs, cases, receipts, attachments, templates, configuration, seats, issuance history and support tickets. Before that, on request, through the contact at the end of this page.
One thing is not deleted, and it is fair to say which: the invoice. Invoices carry a statutory retention period longer than 90 days, and meeting it is a legal obligation — not our choice nor yours. The customer record survives alongside it, reduced to what describes the sale (plan, seats, term): the name and the tax ID are deleted, and no e-mail, run or file remains.
The account session uses a cookie, and it is necessary: it is what keeps you signed in. It is not used for measurement, is not readable by third-party script, and exists only on the account pages — the tool still works with no cookie at all.
External connections
The page makes a small number of connections to third-party services, and none of them carries your content:
- jsDelivr — the content delivery network that serves the PDF generation and transcription libraries. It only receives the request for the library file.
- Hugging Face — where the transcription model is downloaded from, and only if you trigger automatic transcription. It receives the request for the model, never your audio.
- Supabase — the database that receives the fifteen usage milestones and, if you fill it in, the notification-list e-mail. It never receives video, audio or transcripts.
- Vercel — the page's hosting and the page-view count. Like any web server, it technically logs requests to the site.
These third parties have their own policies and may record technical connection data, such as your IP address, in the same way that happens when you visit any website.
The table below is the one a vendor security review asks for: who else touches the data, what they receive, and under which safeguard.
| Third party | Role | Data it receives | Country | Safeguard |
|---|---|---|---|---|
| Supabase | Database and storage for the session attachment | Notification-list e-mail, usage milestones, and all paid-account content. Never video, audio or transcripts | Brazil (São Paulo region) | Vendor data-processing agreement; data at rest within Brazil |
| Vercel | Site hosting and page-view count | Technical access logs and the page-view count, with no cookie and no identifier | Global network | Vendor standard contractual clauses (LGPD art. 33, II) |
| Stripe | Subscription billing | Name, e-mail and payment details of whoever subscribes. We never receive the card number — it goes straight to Stripe | United States and European Union | Standard contractual clauses; vendor PCI-DSS certification |
| Brevo | Sending the account sign-in link and the e-mail invitation | The recipient e-mail address and the message text | European Union (France) | Standard contractual clauses; country with an adequate level of protection |
| jsDelivr | Delivery of the PDF-generation and transcription libraries | Only the request for the library file | Global network | Receives no account data and no content; connection always encrypted |
| Hugging Face | Where the transcription model is downloaded from, and only if you trigger transcription | Only the request for the model. Never your audio | United States | Receives no account data and no content; connection always encrypted |
| Google not a sub-processor of ours |
Opening a video from your Drive, and the Send to Google Docs button — only if you click it | On opening: nothing beyond the request for the file you choose. On sending to Docs: the generated document, which goes from your browser straight to your Google account | As per your Google account | Minimum permission (drive.file), restricted to the files you select. Sending asks for explicit confirmation |
Screen and microphone recording
When you use the recording feature, the browser asks your permission to capture the screen and, if you tick the option, the microphone. The image and both audio channels are processed on your own computer: frames are extracted and the audio is transcribed right there. The session video is never recorded — not on our side, which does not exist, and not on your disk. Nothing from that capture is transmitted to us.
Webcam in a corner
Also optional, also off by default in every scenario, with no exception: a face is personal data of a different order than a screen, and switching that on ourselves would be deciding for the person being filmed. With it ticked, the browser asks permission for the camera and the image is drawn in a corner of the frames and clips, on your computer — it never leaves it, as nothing else does. If you are going to film someone, ask that person: we have no way to ask for you.
Clip of the marked moments
There is one exception, and it is yours to make: the “keep a clip of the marked moments” option. With it on, and only for the moments you mark while recording, about fifteen seconds of video with sound are kept around each mark. The rest of the session is still discarded. The option starts off in every scenario except the usability research session, where the clip is the deliverable itself — and even there, unticking it is enough.
Those clips live in this tab’s memory: closing the tab erases them. They only
reach your disk if you download the .zip package, and they still pass through no server at
all. There is also a “discard the videos” button that erases them all at once and
writes the discard date into the document — because a participant recording is personal data with an
expiry, and whoever audits a study needs to see when it stopped existing.
Google Drive
If the button to open a video from Google Drive is available and you use it, the browser connects to
Google to authenticate and download the file you pick. The file goes from Google straight to your
browser, without passing through any server of ours. We request the most restricted permission
that exists (drive.file), which grants access only to the files you select in the Google
window — never to the rest of your Drive. Until you click that button, no connection to Google is made.
There is also a Send to Google Docs button. It is the only function in the tool where the generated document leaves your computer: the Word file assembled in the browser is sent to Google, which converts it into a Google Docs document inside your Drive. It goes straight from here to Google, without passing through any server of ours — but from that moment on the content lives at Google, under Google's policies and not ours. That is why the button asks for explicit confirmation before sending, and why it says what it is doing. If the evidence contains sensitive data, download the file instead of sending it.
The email invitation
At the end of a session, the tool offers to send the site address to a colleague. If you use it, the email address of the person receiving it passes through our server — it is the only point where anything leaves your machine. No video, no transcript, no document; what you recorded still never leaves your computer.
What we keep of that is a hash of the address and of the request origin, not the values themselves. It exists only to count how many invitations went out and to stop the feature from becoming a nuisance tool: five per hour per origin, two per day to the same recipient. The records are deleted after seven days. There is no list, no sign-up, and the invitation does not repeat.
Copying the address and sharing on LinkedIn do not pass through us: they happen entirely in your browser.
Storage in your browser
The home page stores one single thing: the language code you picked in the switcher at the top
(pt, en, es, de or fr). It exists so you are not sent back to your system
language on the next visit. It is two letters, it identifies nobody, it is never sent anywhere, and it
disappears when you clear browsing data.
The list of your system terms — the codes and proper names speech recognition gets wrong —
lives in sessionStorage with the rest: it disappears when the tab closes, is never read by
us, and never leaves your device. The correction happens in your browser, over text that was already
here.
It also keeps a handful of screen preferences: the size of the lens, the size of the control strip, the size of the window you point at screens in while recording, which blocks were left open and which document model you used last. These are measurements and layout choices — none of them is content from your work, none leaves this computer, and all of them go when you clear browsing data.
The tool can be opened with fields already filled in from the address — for example
?caso=CT-014&chamado=NAT-1234, in a link the test coordinator sends to the team. One
warning: whatever goes in the address stays in your browser history and in the logs of whoever
serves the page. System names and ticket numbers are fine; personal data is not — type that on screen.
Anyone who activates the Team plan also stores the licence key — the same line they received by email. It is checked inside the browser against a public key that sits in the page file itself: there is no call to a licence server, it works offline, and we never learn that it was used or by whom. The “remove this licence” button erases it immediately. The client logo, when used, is read by the browser and drawn inside the document — it does not leave here either.
The tool stores one more: which combination of library and file format managed to open the transcription model on this computer. It is a configuration — version and file names — not content: it exists so the next visit does not repeat the search, which on some machines costs hundreds of megabytes of downloads. The delete the stored model button, next to the diagnostics, erases that note along with the model.
If you install the tool as an app (the shortcut the browser offers), a service worker keeps a copy of the pages and stylesheets so it opens without a network. It stores only what the browser would download from our address anyway — never video, audio, transcripts or generated documents, because none of those are network requests: they live and die inside the tab. Uninstalling the app, or clearing browsing data, removes that copy.
If you use automatic transcription, the browser caches the downloaded model so it does not have to be downloaded again. That file stays on your device, under your control, and is removed when you clear your browsing data. We have no access to it.
The evidence identification fields the tool offers — test case, system, who ran it, ticket, result — and the per-step notes are never sent anywhere. They appear only in the documents you generate and download yourself.
Two of them, system and executed by, are kept in sessionStorage while the
tab stays open, so you do not retype them for every test case. sessionStorage is cleared by
the browser itself when the tab closes: it does not survive between visits, it is not a cookie, it
is not read by us, and it never leaves your device. There is a “Forget” button next to the
fields that clears it immediately. The remaining fields and the notes are not stored even while the tab
lives — they are gone on reload.
The same sessionStorage holds the summary of the last screen recording: how
many frames were kept and why the others were not. These are counters — no image, no text — and
they exist so the diagnostics survive a page reload after something goes wrong. They vanish when
the tab closes, like everything else.
The screens of a recording in progress
This is the only thing the tool keeps for longer than the tab, and it exists for a concrete reason: a tab can crash. Before, a crash 110 minutes into a two-hour recording erased the two hours — and during a long wait, closing the tab is exactly the decision any reasonable person makes.
So while you record, each captured screen is also written to your browser's private storage (the Origin Private File System). That lives on your computer, in an area only this page can read, and it is not sent anywhere — the F12 test still holds: load a multi-gigabyte video and the bytes sent stay at zero.
Three things worth writing down:
- It erases itself as soon as a document comes out. The moment you generate the PDF, the Word file, the .zip or any other output, the work has left the tool and the copy on disk is deleted.
- It erases itself after seven days, even if no document ever came out.
- You can throw it away at any time. When there is a stored recording, step 1 says so plainly and offers “throw it away” next to “bring it back”. Throwing it away erases it right then — it does not merely stop writing from that point on.
When a recording is stored, step 1 says so plainly — how many screens, from when, how much space — and offers the only two things anyone could want: bring it back, or throw it away.
Cookies
We use no first-party or third-party cookies — not for tracking, not for advertising, not for measurement. The page-view count and the three milestones described above work without cookies and without any identifier that persists between visits, which is precisely why there is no cookie banner on this site: there would be nothing to consent to.
Children
The service is not directed at children under 13, and the notification list should not be filled in by them. We have no way to verify age — there are no accounts. If you know a minor left their e-mail, write to privacidade@walkstamp.com and it will be removed. Beyond that we hold no data about minors, because we hold no data about anyone: the video never leaves the device.
Legal bases, purposes and retention
What is processed, why, on what basis and for how long:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Notification-list e-mail | Telling you when the paid plan exists | Consent (LGPD art. 7 I / GDPR art. 6(1)(a)) | Until you withdraw it, or 24 months unused |
| The fifteen usage milestones | Knowing where the tool fails, and improving it | Anonymised data (LGPD art. 12); if in doubt, legitimate interest | 18 months |
| Page views | Knowing how many people arrive, and from where | Anonymised data (LGPD art. 12); if in doubt, legitimate interest | As per Vercel's policy |
| Web server access logs | Security and legal obligation | Legal obligation — Brazilian Internet Civil Framework, art. 15 | 6 months |
| Paid-account content — runs, cases, receipts, attachments, templates, configuration, seats, tickets | Providing the contracted service | Performance of a contract (art. 7, V) | For as long as the subscription lasts, and up to 90 days after it ends |
| Invoices and the customer record attached to them | Tax and accounting obligation | Compliance with a legal obligation (art. 7, II) | The applicable statutory retention period. Name and tax ID are deleted along with the rest of the account, at 90 days |
The milestones and page views were designed not to identify anyone; should an authority nonetheless treat them as personal data, the basis is our legitimate interest in maintaining and improving the service, and you may object through the contact above.
Where the data lives
The notification-list e-mail and the usage milestones sit in a database hosted by Supabase in the São Paulo region — that is, on Brazilian soil. The site itself is hosted by Vercel, whose network is global: technical access logs and the page-view count may be processed outside Brazil, which constitutes an international transfer under LGPD art. 33, covered by the provider's own contractual clauses.
Your videos are in none of those places, because they never leave your device.
Your rights
The LGPD (Law 13,709/2018) grants you, at any time and free of charge:
- confirmation that processing exists, and access to the data;
- correction of incomplete, inaccurate or out-of-date data;
- anonymisation, blocking or erasure of unnecessary or non-compliant data;
- portability to another provider;
- erasure of data processed on the basis of your consent;
- information about who we share it with;
- information about your option not to consent, and what that entails;
- withdrawal of consent, at any time.
In practice, here that almost always means one thing: taking your e-mail off the list. Write to privacidade@walkstamp.com — we reply within 15 days, and for that request the removal is immediate. We ask for no document and no justification: the address writing to us is itself the proof that it is yours.
You may also complain to the Brazilian data protection authority (ANPD), or to your local supervisory authority, if you believe your rights were not respected.
Changes
If this policy changes, the date at the top will be updated. Material changes — especially any move to start collecting data — will be announced on this page, with the date at the top updated.
Contact
Produtize Produtos e Serviços Inteligentes Ltda. — Brazilian company registry (CNPJ) 48.417.292/0001-99.
Privacy and data subject requests:
privacidade@walkstamp.com.
Technical questions and bug reports: the same address.