Privacy
Last updated 27 August 2026
Short version: Try That UI is private by default, but the hosted product is not browser-only. Signed-in workspaces can send and store the screens, screenshots, repository metadata, notes, experiments, and decisions needed to provide synchronization and review features. Nothing is written to a connected repository without a separate, explicit approval.
Information you provide
You may provide an account email, screen URLs, screenshots, source references, repository selections, notes, experiment settings, feedback, and approval decisions. If you use a local or signed-out mode identified as local in the product, its workspace state can remain in that browser. When you sign in or use a hosted feature, the product may transmit and persist the relevant workspace data on our servers so it can survive reloads, synchronize across devices, and be available to authorized workspace members.
Connected services and repositories
GitHub and GitLab connections use the scopes displayed during provider consent. Read access may be used to list repositories and inspect the repository or revision you choose. Repository write, pull-request, merge, and deployment operations are separate capabilities: they remain disabled unless configured and require the approvals shown in the product. Disconnecting a provider stops future access; deleting provider-derived workspace data is a separate action.
The optional X Bookmarks feature uses read-only OAuth scopes to retrieve the connected owner's bookmarks and related public post metadata. Tokens are kept server-side and protected at rest. Imported rows remain private unless an authorized user deliberately submits an item for publication.
Screenshots, rendering, and AI-assisted features
When you upload a screenshot or request hosted capture, rendering, source analysis, or proposal generation, the relevant image, page material, source excerpt, or instruction may be processed by our hosting, storage, sandbox, or configured model provider. The product identifies when external processing or consent is required. Do not submit secrets or material you are not authorized to process.
What we record
We keep first-party aggregate records to understand whether people can start a review, add a source, inspect Current and Proposed, make a decision, use a browser handoff, connect a provider, and recover from errors. The single allowlist contains only page views with a coarse route, intent for named controls and surfaces, bounded funnel steps, bounded error categories, and job-latency buckets. We may group totals by a one-way server-side tenant hash, a coarse region (NA/EU/APAC/LATAM/MEA/other/unknown), device class, and human/bot/automation/unknown traffic class. Counts in small cells are bucketed.
First-party aggregate analytics never includes source URLs, repository names, page bytes, DOM, text, screenshots, cookies, auth or session ids, IP addresses, precise location, full user-agent text, query strings, hashes, secrets, provider identities, or free-form notes. Optional Clarity, GA4, or Cloudflare Web Analytics scripts are disabled unless the owner explicitly configures a public provider identifier and approval flag; DNT/GPC and an explicit tenant or user opt-out suppress them before loading. A transient browser-session token is kept only in session storage, keyed, and reduced to a day-scoped hash for an explicitly approved aggregate session counter; it is not persisted as a cross-site identifier. Before anything is counted, the event is validated against the allowlist.
What we do not do
- We do not sell or rent your personal information.
- We do not build advertising or behavioural profiles.
- We never ask for your X password. If you opt in through X's consent screen, we access only the allowlisted owner's read-only bookmarks and requested profile/post fields.
- We do not write to, merge, or deploy a connected repository without the separate approval required for that operation.
Service providers
Vercel hosts and protects the service and processes ordinary request and server-log data. Supabase may provide account, database, and private object-storage services. GitHub, GitLab, X, WorkOS, Pipedream, Stripe, model providers, and analytics providers process data only when their corresponding feature is configured or used. Their own terms and privacy notices apply. The exact enabled capability is reported in the product rather than assumed from this list.
Retention, deletion, and your control
Local browser data can be cleared or exported from that browser. Hosted workspace records are retained while needed to operate the beta, protect the service, and satisfy legal obligations. Provider connections can be disconnected independently from deleting imported or synchronized records. To request access, correction, export, or deletion of hosted account data, email hello@trythatui.com. We may need to verify the request before acting on it.
Security and account responsibility
We use access controls, signed sessions, tenant boundaries, private storage, bounded provider permissions, and operational monitoring intended to protect hosted data. No service can guarantee absolute security. Keep credentials out of screenshots and notes, protect your account, and tell us promptly if you believe an account or connection has been compromised.
Children
This site is a professional tool and is not directed to children under 13.
Changes and contact
If this policy changes materially, the date above will change. Privacy and support questions can be sent to hello@trythatui.com.