Privacy Policy
How we collect, use, and protect your data.
Privacy Policy
Applies to: the StepMarker Chrome extension and its companion server.
Last updated: 2026-07-18
What we provide
StepMarker helps users turn browser workflows into presentable, editable, and exportable instructional material. Users can record web page actions, capture key step screenshots, generate step annotations, edit step copy, and export ZIP screenshot packages, HTML guides, PDFs, or GIFs.
Data we collect
Account data
- Clerk account identifier.
- Clerk account email, display name, and avatar.
- Clerk session token.
- Plan, quota, usage, and billing status.
Recording data
Only after the user explicitly starts a recording, the extension collects data needed to generate operation guides on the current browser page:
- Operation event types, such as click, right-click, input, scroll, focus, hover, and page navigation.
- Event timestamps.
- The target element's tag name, selector, visible text, selected attributes, position, and size.
- Mouse position, viewport size, and scroll information.
- Screenshots associated with events.
- Step titles, intent descriptions, notes, annotation positions, and template choices filled in or modified by the user in the editor.
Server-processed data
When the user signs in and connects to the server, the extension sends the data required to generate annotations to the server:
- Sanitized operation events.
- Screenshots related to step annotations.
- The user's chosen language, template, and custom rules.
- Recording project metadata.
- Usage counters for annotations, recordings, and exports.
- Cost logs of AI provider calls, such as status codes, retry counts, character counts, and token usage.
- If voice generation is enabled: narration text, voice generation job metadata, and generated audio assets.
Payment data
In production, Waffo hosted checkout, customer-session subscription cancellation, and server-side webhooks are used to manage paid status. The extension does not directly handle bank card numbers or payment credentials. The server only stores the payment status, plan, period end time, payment event IDs, and payment provider identifiers needed to manage subscriptions and quotas.
Data we do not collect
- The extension does not store model provider API keys.
- The extension does not store server-side AI prompts.
- The extension does not proactively read the browsing history list.
- The extension does not capture page operation events unless a recording has been started.
- The extension is not used for advertising profiling or cross-site tracking.
Sensitive data handling
Before calling AI annotation, the server sanitizes event content:
- Email addresses are replaced with
[email]. - Long numbers such as phone numbers and bank card numbers are replaced with
[number]. - Common token or secret shapes are replaced with
[token]. - Sensitive attributes such as password, token, api-key, authorization, and cookie are replaced with
[filtered]. - Values of password, email, phone, and credit card input fields are replaced with
[filtered]. - Individual text segments are length-limited to avoid uploading overly long page content.
Because screenshots may contain information visible on the page, users should avoid recording pages with highly sensitive information, or delete the related steps before exporting or sharing.
Purposes of use
We use the data above to:
- Record browser workflows explicitly chosen by the user.
- Generate screenshots, GIFs, PDFs, and HTML guides.
- Generate and edit step descriptions, text annotations, and highlights.
- Generate AI voice narration when requested by the user; product UI and help materials should clearly disclose that the voice is AI-generated and not a real human recording.
- Identify account identity and sync plans and quotas.
- Prevent quota bypass, abuse, and abnormally high-cost calls.
- Process subscriptions, refunds, cancellations, and renewal failures.
- Respond to user data deletion requests.
- Diagnose server errors and AI provider call failures.
Local storage
The extension stores on the user's device:
chrome.storage.local: recording state, event metadata, server address, Clerk session configuration, template selection, annotation config, and temporary export state.- IndexedDB: event screenshots, in a database named
op-recorderwith an object store namedscreenshots. - Downloads folder: ZIP, HTML, PDF, or GIF files actively exported by the user.
Users can stop recording, start a new recording, or delete account data to clear the current local recording state. Files exported to the downloads folder are managed by the user.
Server storage
The StepMarker server uses a managed database and private object storage to keep the data needed for accounts, usage, recordings, billing, and cost logs:
- Production database provider:Railway PostgreSQL。
- Production object storage provider:Cloudflare R2。
- Data region:United States。
- Payment provider:Waffo Pancake。
- AI provider:OpenAI。
Key screenshots produced by user-initiated recordings are stored by reference in private object storage and accessed only through time-limited signed URLs. We run regular backups, log cleanup, and access auditing on production data.
Data retention and deletion
- Users can invoke "Delete account data" inside the extension at any time.
- This deletes your server-side recordings, usage, billing status, billing events, cost logs, alert events, and voice jobs/assets.
- After successful deletion, the server stores an irreversible hash revocation marker of the current session token until the token expires, to block the old session from accessing the service.
- The extension also clears the local recording state and Clerk session configuration.
Retention periods:
- Server-side recordings and exports: 30 days for free users, 180 days for paid users.
- Cost logs and security audit logs: 90 days.
- Data deletion requests made via email are completed within 30 days of receipt.
Data sharing
We only share data to the extent necessary to provide product functionality:
- Clerk: for user sign-in and authentication.
- AI providers: the server sends sanitized events and necessary screenshots when generating annotations; when voice generation is enabled, narration text is sent to generate AI voice.
- Waffo Pancake: for hosted checkout, subscription cancellation, subscription status, and webhook events.
- Cloud infrastructure providers: for hosting the server, database, logs, and object storage.
We do not sell user data, and we do not use recorded content for ad targeting.
Clerk and Limited Use
Clerk account information is only used for sign-in, displaying the current user, managing plans and quotas, and processing account deletion. It is not used for ad targeting, selling data, or cross-site tracking unrelated to product functionality. Social sign-in and email codes, verification links, or password checks are handled by Clerk; this product does not store passwords or run a separate email-verification service.
Security measures
- HTTPS is enforced everywhere.
- AI prompts, model configuration, and provider API keys are only read on the server; the extension only stores Clerk session configuration, not model provider keys.
- The server verifies the Clerk session token in production.
- The database uses encrypted connections, and object storage is private, read only through time-limited signed URLs.
- Billing webhooks use HMAC-SHA256 signature verification and idempotent event handling.
- Annotation endpoints are rate-limited per user; the server records provider call status and retry counts for cost and anomaly troubleshooting.
- Production logs are redacted, admin access follows least privilege, and abnormal costs trigger alerts.
Children's privacy
This product is intended for individuals or organizations that need to create web operation demonstrations, and is not directed at children. If a child's account or unauthorized data is found to have been submitted, it should be deleted through official support channels.
Contact
- Legal entity:xiaolouge (independent developer)
- Privacy contact email:privacy@stepmarker.com
- Support email:support@stepmarker.com
- Contact address:Available on request via privacy@stepmarker.com