Privacy Policy

Last updated: 16 August 2026.
This policy describes how Walkstamp works today: the tool has no processing server, and there is an optional account — described below — for anyone on a paid plan.

Until 14 August 2026 this service was called ClipContext. Only the name changed — the controller, the legal bases and the retention periods below are exactly the same.

Who is responsible

Walkstamp is offered by Produtize Produtos e Serviços Inteligentes Ltda., a company registered in Brazil under CNPJ 48.417.292/0001-99, acting as the controller of the small amount of personal data described in this policy, under Brazilian Law 13,709/2018 (LGPD).

Data subject requests, questions and privacy complaints: privacidade@walkstamp.com. This is also the channel for the data protection officer (LGPD art. 41).

Summary

We do not receive your videos, your audio, your frames, your transcripts or the documents you generate. That has not changed, it holds on every plan, and it is the promise the product rests on — not a setting we can loosen later.

What does exist is this, all detailed below: a page-view count with no cookie and no identifier; an anonymous count of three usage milestones; your e-mail, if you leave it on the pricing page; and, for anyone on a paid plan, an account — holding the sign-in e-mail, the invoices, the support tickets and the list of cases to run, if you use the test-run screen. Using the tool still requires no account: signed out, it records, transcribes and generates documents exactly the same.

How the service works

Walkstamp is a static page. When you choose a video, it is read directly from your device by the browser and stays there. Extracting the images, reading the audio, transcribing it and assembling the PDF all happen entirely on your computer, using its processing power.

The file is never sent to us. There is no temporary copy on our systems, because no system of ours is involved in the processing.

Data we do not collect

  • Videos, audio, extracted images, transcripts and generated PDFs
  • File name, size, duration or any characteristic of what you process
  • Name, phone number or personal identifier — and your e-mail only if you type one, by your choice
  • Tracking identifiers, behavioural profiles or advertising data
  • Cookies, of any kind

What is measured, and why

A tool nobody knows is being used cannot be improved in the right place. So there are two measurements, and both were designed not to know who you are:

  • Page views, through Vercel Web Analytics. No cookie and no identifier that persists between visits. It tells us how many people arrived and by which route.
  • Three usage milestones, inside the tool: that it was opened, that a video was opened successfully, and that an output file was downloaded. Alongside goes the page language, where the video came from (file, Drive, recording or sample) and the format downloaded. Nothing else. No file name, size, duration, content or session identifier — there is no way to tie two milestones to the same person, or this visit to the next.

If your browser sends Do Not Track or Global Privacy Control, the three milestones are not sent. And the offline version — the single file you download — is built with no measurement address inside it at all: it talks to nobody, and you can check that by searching the file for “supabase”.

The paid-plan notification list

The pricing page has an optional e-mail field. If you fill it in, the address and the page language are stored in a database of ours, with the date. It is the only personal data here, and it:

  • is never cross-referenced with the measurements above — they have nothing to cross-reference with;
  • is never sold, shared or added to a third-party list;
  • serves one purpose only: telling you when the paid plan exists;
  • is deleted as soon as you ask, through the contact at the end of this page.

The paid-plan account, and the test run

Anyone on a paid plan gets an account. It is the only place where we store data of yours by your choice, and it is where the one feature that writes customer content to a server of ours lives: the test-run screen. That is why it is described here field by field.

The account holds:

  • the sign-in e-mail, which is the identity of the account and where the sign-in link goes;
  • the invoices and subscription status, coming from Stripe;
  • the support tickets you open, with the text you wrote;
  • on the Team plan, the seats: each team member's e-mail and what they have issued;
  • the document templates and the branding you configure (company name, logo address, label, environment).

And, if you use the test run, it holds the fields of the task list, and nothing else: the case code, the title, the system, the ticket number, the owner's e-mail, the date the case was marked done, who marked it, the name of the generated file, its fingerprint and any note you type.

When you mark a case done, a receipt is stored too: the record of what was run (case, scenario, system, ticket, environment, result, date and format) and the fingerprint of every frame, in order. Those are numbers. It travels inside the return link itself, and it is what lets you take a document months later and check that it is the same one.

What the receipt never contains: images, transcripts or step text. The fingerprint is computed from the screens and does not allow any image to be reconstructed. The spreadsheet you upload to create a run is read, becomes the rows described above, and the file is discarded: we do not store the spreadsheet.

The session attachment — the one exception, and it is yours

When you confirm a case as done there is an optional field: attach the complete .json of that session. That file has the frame images inside it, along with the step text and the transcript, if there is one.

Attaching it is the only thing in this product that puts content of yours on a server of ours. Because of that, and without exception:

  • it never goes on its own — the field starts closed and you have to pick the file;
  • what it means is written next to the field, at the moment of the choice, not only here;
  • it lives in private storage with no public address: downloading goes through our server, which checks your session and returns a signed address that expires in two minutes;
  • whoever can see the case can see the attachment — on a team run, that is the whole team;
  • there is a delete attachment button, and it deletes the file, not just the record pointing at it;
  • the limit is 32 MB per case, and only .json files are accepted.

Your video and audio still never leave your browser, attachment or no attachment. With no attachment, only the receipt is kept — numbers, no images.

Note what that means in practice: a run is a work list, and a case code or a ticket number can say what your company is testing. Write in those fields what you would write on a task-board card — system names and ticket numbers, fine; someone else's personal data, no.

A run marked “team” is visible to everyone with a seat on the same account; a “mine only” run is visible only to whoever created it. Whoever created a run can delete it at any time, and deleting takes all of its cases — and the files attached to them — with it, immediately and with no copy.

When the subscription ends, the account's content is deleted within 90 days, by a routine that runs every day: runs, cases, receipts, attachments, templates, configuration, seats, issuance history and support tickets. Before that, on request, through the contact at the end of this page.

One thing is not deleted, and it is fair to say which: the invoice. Invoices carry a statutory retention period longer than 90 days, and meeting it is a legal obligation — not our choice nor yours. The customer record survives alongside it, reduced to what describes the sale (plan, seats, term): the name and the tax ID are deleted, and no e-mail, run or file remains.

The account session uses a cookie, and it is necessary: it is what keeps you signed in. It is not used for measurement, is not readable by third-party script, and exists only on the account pages — the tool still works with no cookie at all.

External connections

The page makes a small number of connections to third-party services, and none of them carries your content:

  • jsDelivr — the content delivery network that serves the PDF generation and transcription libraries. It only receives the request for the library file.
  • Hugging Face — where the transcription model is downloaded from, and only if you trigger automatic transcription. It receives the request for the model, never your audio.
  • Supabase — the database that receives the three usage milestones and, if you fill it in, the notification-list e-mail. It never receives video, audio or transcripts.
  • Vercel — the page's hosting and the page-view count. Like any web server, it technically logs requests to the site.

These third parties have their own policies and may record technical connection data, such as your IP address, in the same way that happens when you visit any website.

Screen and microphone recording

When you use the recording feature, the browser asks your permission to capture the screen and, if you tick the option, the microphone. The image and both audio channels are processed on your own computer: frames are extracted and the audio is transcribed right there. The session video is never recorded — not on our side, which does not exist, and not on your disk. Nothing from that capture is transmitted to us.

Webcam in a corner

Also optional, also off by default in every scenario, with no exception: a face is personal data of a different order than a screen, and switching that on ourselves would be deciding for the person being filmed. With it ticked, the browser asks permission for the camera and the image is drawn in a corner of the frames and clips, on your computer — it never leaves it, as nothing else does. If you are going to film someone, ask that person: we have no way to ask for you.

Clip of the marked moments

There is one exception, and it is yours to make: the “keep a clip of the marked moments” option. With it on, and only for the moments you mark while recording, about fifteen seconds of video with sound are kept around each mark. The rest of the session is still discarded. The option starts off in every scenario except the usability research session, where the clip is the deliverable itself — and even there, unticking it is enough.

Those clips live in this tab’s memory: closing the tab erases them. They only reach your disk if you download the .zip package, and they still pass through no server at all. There is also a “discard the videos” button that erases them all at once and writes the discard date into the document — because a participant recording is personal data with an expiry, and whoever audits a study needs to see when it stopped existing.

Google Drive

If the button to open a video from Google Drive is available and you use it, the browser connects to Google to authenticate and download the file you pick. The file goes from Google straight to your browser, without passing through any server of ours. We request the most restricted permission that exists (drive.file), which grants access only to the files you select in the Google window — never to the rest of your Drive. Until you click that button, no connection to Google is made.

There is also a Send to Google Docs button. It is the only function in the tool where the generated document leaves your computer: the Word file assembled in the browser is sent to Google, which converts it into a Google Docs document inside your Drive. It goes straight from here to Google, without passing through any server of ours — but from that moment on the content lives at Google, under Google's policies and not ours. That is why the button asks for explicit confirmation before sending, and why it says what it is doing. If the evidence contains sensitive data, download the file instead of sending it.

Storage in your browser

The home page stores one single thing: the language code you picked in the switcher at the top (pt, en, es, de or fr). It exists so you are not sent back to your system language on the next visit. It is two letters, it identifies nobody, it is never sent anywhere, and it disappears when you clear browsing data.

The list of your system terms — the codes and proper names speech recognition gets wrong — lives in sessionStorage with the rest: it disappears when the tab closes, is never read by us, and never leaves your device. The correction happens in your browser, over text that was already here.

The tool can be opened with fields already filled in from the address — for example ?caso=CT-014&chamado=NAT-1234, in a link the test coordinator sends to the team. One warning: whatever goes in the address stays in your browser history and in the logs of whoever serves the page. System names and ticket numbers are fine; personal data is not — type that on screen.

Anyone who activates the Team plan also stores the licence key — the same line they received by email. It is checked inside the browser against a public key that sits in the page file itself: there is no call to a licence server, it works offline, and we never learn that it was used or by whom. The “remove this licence” button erases it immediately. The client logo, when used, is read by the browser and drawn inside the document — it does not leave here either.

The tool stores one more: which combination of library and file format managed to open the transcription model on this computer. It is a configuration — version and file names — not content: it exists so the next visit does not repeat the search, which on some machines costs hundreds of megabytes of downloads. The delete the stored model button, next to the diagnostics, erases that note along with the model.

If you install the tool as an app (the shortcut the browser offers), a service worker keeps a copy of the pages and stylesheets so it opens without a network. It stores only what the browser would download from our address anyway — never video, audio, transcripts or generated documents, because none of those are network requests: they live and die inside the tab. Uninstalling the app, or clearing browsing data, removes that copy.

If you use automatic transcription, the browser caches the downloaded model so it does not have to be downloaded again. That file stays on your device, under your control, and is removed when you clear your browsing data. We have no access to it.

The evidence identification fields the tool offers — test case, system, who ran it, ticket, result — and the per-step notes are never sent anywhere. They appear only in the documents you generate and download yourself.

Two of them, system and executed by, are kept in sessionStorage while the tab stays open, so you do not retype them for every test case. sessionStorage is cleared by the browser itself when the tab closes: it does not survive between visits, it is not a cookie, it is not read by us, and it never leaves your device. There is a “Forget” button next to the fields that clears it immediately. The remaining fields and the notes are not stored even while the tab lives — they are gone on reload.

The same sessionStorage holds the summary of the last screen recording: how many frames were kept and why the others were not. These are counters — no image, no text — and they exist so the diagnostics survive a page reload after something goes wrong. They vanish when the tab closes, like everything else.

Cookies

We use no first-party or third-party cookies — not for tracking, not for advertising, not for measurement. The page-view count and the three milestones described above work without cookies and without any identifier that persists between visits, which is precisely why there is no cookie banner on this site: there would be nothing to consent to.

Children

The service is not directed at children under 13, and the notification list should not be filled in by them. We have no way to verify age — there are no accounts. If you know a minor left their e-mail, write to privacidade@walkstamp.com and it will be removed. Beyond that we hold no data about minors, because we hold no data about anyone: the video never leaves the device.

Legal bases, purposes and retention

What is processed, why, on what basis and for how long:

The milestones and page views were designed not to identify anyone; should an authority nonetheless treat them as personal data, the basis is our legitimate interest in maintaining and improving the service, and you may object through the contact above.

Where the data lives

The notification-list e-mail and the usage milestones sit in a database hosted by Supabase in the São Paulo region — that is, on Brazilian soil. The site itself is hosted by Vercel, whose network is global: technical access logs and the page-view count may be processed outside Brazil, which constitutes an international transfer under LGPD art. 33, covered by the provider's own contractual clauses.

Your videos are in none of those places, because they never leave your device.

Your rights

The LGPD (Law 13,709/2018) grants you, at any time and free of charge:

  • confirmation that processing exists, and access to the data;
  • correction of incomplete, inaccurate or out-of-date data;
  • anonymisation, blocking or erasure of unnecessary or non-compliant data;
  • portability to another provider;
  • erasure of data processed on the basis of your consent;
  • information about who we share it with;
  • information about your option not to consent, and what that entails;
  • withdrawal of consent, at any time.

In practice, here that almost always means one thing: taking your e-mail off the list. Write to privacidade@walkstamp.com — we reply within 15 days, and for that request the removal is immediate. We ask for no document and no justification: the address writing to us is itself the proof that it is yours.

You may also complain to the Brazilian data protection authority (ANPD), or to your local supervisory authority, if you believe your rights were not respected.

Changes

If this policy changes, the date at the top will be updated. Material changes — especially any move to start collecting data — will be announced on this page, with the date at the top updated.

Contact

Produtize Produtos e Serviços Inteligentes Ltda. — Brazilian company registry (CNPJ) 48.417.292/0001-99.
Privacy and data subject requests: privacidade@walkstamp.com.
Technical questions and bug reports: the same address.