Last updated: 16 August 2026.
This policy describes how Walkstamp works today: the tool has no processing server, and there is an
optional account — described below — for anyone on a paid plan.
Until 14 August 2026 this service was called ClipContext. Only the name changed — the controller, the legal bases and the retention periods below are exactly the same.
Walkstamp is offered by Produtize Produtos e Serviços Inteligentes Ltda., a company registered in Brazil under CNPJ 48.417.292/0001-99, acting as the controller of the small amount of personal data described in this policy, under Brazilian Law 13,709/2018 (LGPD).
Data subject requests, questions and privacy complaints: privacidade@walkstamp.com. This is also the channel for the data protection officer (LGPD art. 41).
We do not receive your videos, your audio, your frames, your transcripts or the documents you generate. That has not changed, it holds on every plan, and it is the promise the product rests on — not a setting we can loosen later.
What does exist is this, all detailed below: a page-view count with no cookie and no identifier; an anonymous count of three usage milestones; your e-mail, if you leave it on the pricing page; and, for anyone on a paid plan, an account — holding the sign-in e-mail, the invoices, the support tickets and the list of cases to run, if you use the test-run screen. Using the tool still requires no account: signed out, it records, transcribes and generates documents exactly the same.
Walkstamp is a static page. When you choose a video, it is read directly from your device by the browser and stays there. Extracting the images, reading the audio, transcribing it and assembling the PDF all happen entirely on your computer, using its processing power.
The file is never sent to us. There is no temporary copy on our systems, because no system of ours is involved in the processing.
A tool nobody knows is being used cannot be improved in the right place. So there are two measurements, and both were designed not to know who you are:
If your browser sends Do Not Track or Global Privacy Control, the three milestones are not sent. And the offline version — the single file you download — is built with no measurement address inside it at all: it talks to nobody, and you can check that by searching the file for “supabase”.
The pricing page has an optional e-mail field. If you fill it in, the address and the page language are stored in a database of ours, with the date. It is the only personal data here, and it:
Anyone on a paid plan gets an account. It is the only place where we store data of yours by your choice, and it is where the one feature that writes customer content to a server of ours lives: the test-run screen. That is why it is described here field by field.
The account holds:
And, if you use the test run, it holds the fields of the task list, and nothing else: the case code, the title, the system, the ticket number, the owner's e-mail, the date the case was marked done, who marked it, the name of the generated file, its fingerprint and any note you type.
When you mark a case done, a receipt is stored too: the record of what was run (case, scenario, system, ticket, environment, result, date and format) and the fingerprint of every frame, in order. Those are numbers. It travels inside the return link itself, and it is what lets you take a document months later and check that it is the same one.
What the receipt never contains: images, transcripts or step text. The fingerprint is computed from the screens and does not allow any image to be reconstructed. The spreadsheet you upload to create a run is read, becomes the rows described above, and the file is discarded: we do not store the spreadsheet.
When you confirm a case as done there is an optional field: attach the complete
.json of that session. That file has the frame images inside it, along with the
step text and the transcript, if there is one.
Attaching it is the only thing in this product that puts content of yours on a server of ours. Because of that, and without exception:
.json files are accepted.Your video and audio still never leave your browser, attachment or no attachment. With no attachment, only the receipt is kept — numbers, no images.
Note what that means in practice: a run is a work list, and a case code or a ticket number can say what your company is testing. Write in those fields what you would write on a task-board card — system names and ticket numbers, fine; someone else's personal data, no.
A run marked “team” is visible to everyone with a seat on the same account; a “mine only” run is visible only to whoever created it. Whoever created a run can delete it at any time, and deleting takes all of its cases — and the files attached to them — with it, immediately and with no copy.
When the subscription ends, the account's content is deleted within 90 days, by a routine that runs every day: runs, cases, receipts, attachments, templates, configuration, seats, issuance history and support tickets. Before that, on request, through the contact at the end of this page.
One thing is not deleted, and it is fair to say which: the invoice. Invoices carry a statutory retention period longer than 90 days, and meeting it is a legal obligation — not our choice nor yours. The customer record survives alongside it, reduced to what describes the sale (plan, seats, term): the name and the tax ID are deleted, and no e-mail, run or file remains.
The account session uses a cookie, and it is necessary: it is what keeps you signed in. It is not used for measurement, is not readable by third-party script, and exists only on the account pages — the tool still works with no cookie at all.
The page makes a small number of connections to third-party services, and none of them carries your content:
These third parties have their own policies and may record technical connection data, such as your IP address, in the same way that happens when you visit any website.
When you use the recording feature, the browser asks your permission to capture the screen and, if you tick the option, the microphone. The image and both audio channels are processed on your own computer: frames are extracted and the audio is transcribed right there. The session video is never recorded — not on our side, which does not exist, and not on your disk. Nothing from that capture is transmitted to us.
Also optional, also off by default in every scenario, with no exception: a face is personal data of a different order than a screen, and switching that on ourselves would be deciding for the person being filmed. With it ticked, the browser asks permission for the camera and the image is drawn in a corner of the frames and clips, on your computer — it never leaves it, as nothing else does. If you are going to film someone, ask that person: we have no way to ask for you.
There is one exception, and it is yours to make: the “keep a clip of the marked moments” option. With it on, and only for the moments you mark while recording, about fifteen seconds of video with sound are kept around each mark. The rest of the session is still discarded. The option starts off in every scenario except the usability research session, where the clip is the deliverable itself — and even there, unticking it is enough.
Those clips live in this tab’s memory: closing the tab erases them. They only
reach your disk if you download the .zip package, and they still pass through no server at
all. There is also a “discard the videos” button that erases them all at once and
writes the discard date into the document — because a participant recording is personal data with an
expiry, and whoever audits a study needs to see when it stopped existing.
If the button to open a video from Google Drive is available and you use it, the browser connects to
Google to authenticate and download the file you pick. The file goes from Google straight to your
browser, without passing through any server of ours. We request the most restricted permission
that exists (drive.file), which grants access only to the files you select in the Google
window — never to the rest of your Drive. Until you click that button, no connection to Google is made.
There is also a Send to Google Docs button. It is the only function in the tool where the generated document leaves your computer: the Word file assembled in the browser is sent to Google, which converts it into a Google Docs document inside your Drive. It goes straight from here to Google, without passing through any server of ours — but from that moment on the content lives at Google, under Google's policies and not ours. That is why the button asks for explicit confirmation before sending, and why it says what it is doing. If the evidence contains sensitive data, download the file instead of sending it.
The home page stores one single thing: the language code you picked in the switcher at the top
(pt, en, es, de or fr). It exists so you are not sent back to your system
language on the next visit. It is two letters, it identifies nobody, it is never sent anywhere, and it
disappears when you clear browsing data.
The list of your system terms — the codes and proper names speech recognition gets wrong —
lives in sessionStorage with the rest: it disappears when the tab closes, is never read by
us, and never leaves your device. The correction happens in your browser, over text that was already
here.
The tool can be opened with fields already filled in from the address — for example
?caso=CT-014&chamado=NAT-1234, in a link the test coordinator sends to the team. One
warning: whatever goes in the address stays in your browser history and in the logs of whoever
serves the page. System names and ticket numbers are fine; personal data is not — type that on screen.
Anyone who activates the Team plan also stores the licence key — the same line they received by email. It is checked inside the browser against a public key that sits in the page file itself: there is no call to a licence server, it works offline, and we never learn that it was used or by whom. The “remove this licence” button erases it immediately. The client logo, when used, is read by the browser and drawn inside the document — it does not leave here either.
The tool stores one more: which combination of library and file format managed to open the transcription model on this computer. It is a configuration — version and file names — not content: it exists so the next visit does not repeat the search, which on some machines costs hundreds of megabytes of downloads. The delete the stored model button, next to the diagnostics, erases that note along with the model.
If you install the tool as an app (the shortcut the browser offers), a service worker keeps a copy of the pages and stylesheets so it opens without a network. It stores only what the browser would download from our address anyway — never video, audio, transcripts or generated documents, because none of those are network requests: they live and die inside the tab. Uninstalling the app, or clearing browsing data, removes that copy.
If you use automatic transcription, the browser caches the downloaded model so it does not have to be downloaded again. That file stays on your device, under your control, and is removed when you clear your browsing data. We have no access to it.
The evidence identification fields the tool offers — test case, system, who ran it, ticket, result — and the per-step notes are never sent anywhere. They appear only in the documents you generate and download yourself.
Two of them, system and executed by, are kept in sessionStorage while the
tab stays open, so you do not retype them for every test case. sessionStorage is cleared by
the browser itself when the tab closes: it does not survive between visits, it is not a cookie, it
is not read by us, and it never leaves your device. There is a “Forget” button next to the
fields that clears it immediately. The remaining fields and the notes are not stored even while the tab
lives — they are gone on reload.
The same sessionStorage holds the summary of the last screen recording: how
many frames were kept and why the others were not. These are counters — no image, no text — and
they exist so the diagnostics survive a page reload after something goes wrong. They vanish when
the tab closes, like everything else.
We use no first-party or third-party cookies — not for tracking, not for advertising, not for measurement. The page-view count and the three milestones described above work without cookies and without any identifier that persists between visits, which is precisely why there is no cookie banner on this site: there would be nothing to consent to.
The service is not directed at children under 13, and the notification list should not be filled in by them. We have no way to verify age — there are no accounts. If you know a minor left their e-mail, write to privacidade@walkstamp.com and it will be removed. Beyond that we hold no data about minors, because we hold no data about anyone: the video never leaves the device.
What is processed, why, on what basis and for how long:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Notification-list e-mail | Telling you when the paid plan exists | Consent (LGPD art. 7 I / GDPR art. 6(1)(a)) | Until you withdraw it, or 24 months unused |
| The three usage milestones | Knowing where the tool fails, and improving it | Anonymised data (LGPD art. 12); if in doubt, legitimate interest | 18 months |
| Page views | Knowing how many people arrive, and from where | Anonymised data (LGPD art. 12); if in doubt, legitimate interest | As per Vercel's policy |
| Web server access logs | Security and legal obligation | Legal obligation — Brazilian Internet Civil Framework, art. 15 | 6 months |
| Paid-account content — runs, cases, receipts, attachments, templates, configuration, seats, tickets | Providing the contracted service | Performance of a contract (art. 7, V) | For as long as the subscription lasts, and up to 90 days after it ends |
| Invoices and the customer record attached to them | Tax and accounting obligation | Compliance with a legal obligation (art. 7, II) | The applicable statutory retention period. Name and tax ID are deleted along with the rest of the account, at 90 days |
The milestones and page views were designed not to identify anyone; should an authority nonetheless treat them as personal data, the basis is our legitimate interest in maintaining and improving the service, and you may object through the contact above.
The notification-list e-mail and the usage milestones sit in a database hosted by Supabase in the São Paulo region — that is, on Brazilian soil. The site itself is hosted by Vercel, whose network is global: technical access logs and the page-view count may be processed outside Brazil, which constitutes an international transfer under LGPD art. 33, covered by the provider's own contractual clauses.
Your videos are in none of those places, because they never leave your device.
The LGPD (Law 13,709/2018) grants you, at any time and free of charge:
In practice, here that almost always means one thing: taking your e-mail off the list. Write to privacidade@walkstamp.com — we reply within 15 days, and for that request the removal is immediate. We ask for no document and no justification: the address writing to us is itself the proof that it is yours.
You may also complain to the Brazilian data protection authority (ANPD), or to your local supervisory authority, if you believe your rights were not respected.
If this policy changes, the date at the top will be updated. Material changes — especially any move to start collecting data — will be announced on this page, with the date at the top updated.
Produtize Produtos e Serviços Inteligentes Ltda. — Brazilian company registry (CNPJ) 48.417.292/0001-99.
Privacy and data subject requests:
privacidade@walkstamp.com.
Technical questions and bug reports: the same address.