Privacy Policy
Last updated: August 8, 2026
On this page
1. Overview
BrokenProduct ("BrokenProduct", "we", "us", or "our"), operated out of Ahmedabad, Gujarat, India, provides an AI-powered UX audit service for SaaS products, web apps, websites, landing pages, and mobile apps. This policy explains what data we collect when you use our browser extension, our screenshot upload tool, or brokenproduct.com, why we collect it, how long we keep it, and the rights you have over it.
By using BrokenProduct, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the service.
2. Data we collect
We collect only what is needed to deliver a UX audit and to run the waitlist, account, and billing side of the product:
- Account data: your name and email address when you sign up, join the waitlist, or create an account.
- Product screenshots: screenshots of the screens you capture with the browser extension, or upload directly, for the purpose of the audit.
- Capture metadata: the time spent on each captured screen and click position data, used to help our reviewers understand how you interact with your own product. We do not capture keystrokes, form field contents, or passwords.
- Founder context: any optional notes you add when submitting an audit, describing what you want us to focus on.
- Billing information: handled directly by our payment processor. BrokenProduct does not store your full card number.
- Usage data: standard technical information such as browser type, device type, and pages visited on brokenproduct.com, collected via analytics as described in Cookies and tracking technologies.
- Attribution data: if you arrive via a specific link, ad, or campaign, we record the referring source, campaign parameters (such as
utm_source), and, when you submit a form, that source alongside your submission, so we know which channels are actually bringing us founders. This is described in Cookies and tracking technologies.
3. How we handle screenshots
The BrokenProduct browser extension only captures screens while capture mode is active and you have explicitly started an audit session. It never runs silently in the background outside of an active session, and it never reads or transmits page content beyond a screenshot of what is visibly on screen at the moment of capture.
Because you are typically logged in to your own product when you capture screens, your screenshots may include your product's real data, such as example customer names or account details visible in your dashboard. You are in control: the extension lets you review and delete any captured screen before you submit it for audit.
4. How we use your data
We use the data described above to:
- Generate and deliver your UX audit report, including AI analysis and human review by the BrokenProduct team.
- Operate your account, process credit purchases, and communicate about your audits.
- Respond to support requests and re-audit requests.
- Improve the accuracy and usefulness of our audit framework, using aggregated or anonymised patterns only, never your product's specific content, without a separate opt-in.
- Send you product updates and waitlist notifications, which you can opt out of at any time.
- Understand which pages, campaigns, and referral sources bring visitors to brokenproduct.com and lead to signups, so we can measure and improve our marketing, where you have given the relevant cookie consent described in Cookies and tracking technologies.
We never sell your data, and we never use your screenshots or product content to train third-party AI models outside of delivering your audit. Marketing analytics is always performed on aggregated traffic and attribution data, never on your product screenshots or their content.
5. Storage and retention
Screenshots and capture metadata are stored on encrypted servers located in the EU (Frankfurt region) and are automatically deleted 7 days after your audit report is delivered. If you do not submit your captured screens for audit, they are deleted automatically after 30 days of inactivity.
Account data (name, email, billing history) is retained for as long as your account is active, and for a reasonable period afterward to comply with tax, accounting, and legal obligations. You can request deletion of your account data at any time, see Your rights below.
6. Who we share data with
We do not sell or rent your data. We share data only with:
- The BrokenProduct review team, who review AI-generated findings before your report is delivered.
- Service providers who host our infrastructure, process payments, or send transactional email on our behalf, each bound by contractual confidentiality and data protection obligations.
- Analytics and marketing providers, currently Google Analytics, who process usage and attribution data on our behalf, only for cookie categories you have consented to. See Cookies and tracking technologies.
- Authorities, only where required by law, to protect our legal rights, or to prevent fraud or abuse.
7. Cookies and tracking technologies
brokenproduct.com uses cookies and similar local-storage technologies in three categories. You choose which non-essential categories to allow using the cookie banner shown on your first visit, or at any time via the control in the footer.
- Necessary (always on): stores your cookie preference itself, keeps the waitlist form and navigation working, and cannot be switched off because the site cannot function without it. No consent is required for this category under applicable law.
- Analytics: Google Analytics, used to understand aggregate traffic, which pages are visited, and how the site is used, in order to improve it. We enable this only if you accept the "Analytics" category. IP addresses are anonymised.
- Marketing and attribution: used to record which campaign, ad, or referral link brought a given visit to brokenproduct.com (for example
utm_source,utm_campaign, or a click identifier from an ad platform), so we can measure which marketing channels work and, in future, run retargeting campaigns. We enable this only if you accept the "Marketing" category, and it is never combined with your product screenshots or audit content.
Separately, when you actively submit the waitlist form, we record the campaign or referral source for that specific visit alongside your email as a normal part of processing your signup, in the same way we would note "how did you hear about us". This is not cross-visit tracking and applies regardless of your cookie choice, because it is necessary to operate the waitlist and understand direct signups.
Consent choices are stored for 12 months, after which you will be asked again. You can withdraw or change your consent at any time via the Cookie Preferences control, or by blocking cookies in your browser settings, without affecting your ability to use the core site.
8. Security
We use industry-standard measures to protect your data, including encryption in transit and at rest, access controls limiting screenshot access to the review team, and regular review of our infrastructure. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work to keep your data protected at every stage of an audit.
9. Your rights (GDPR)
If you are located in the European Economic Area (EEA), the UK, or another jurisdiction with similar data protection laws, you have the following rights over your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your personal data, including uncompleted or previously submitted screenshots, subject to any legal retention requirements.
- Restriction: ask us to limit how we process your data in certain circumstances.
- Portability: request your data in a structured, commonly used, machine-readable format.
- Objection: object to processing based on legitimate interest, including for direct marketing.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting processing that already took place.
To exercise any of these rights, email hello@brokenproduct.com with your request. We respond within 30 days. If you believe we have not handled your data correctly, you also have the right to lodge a complaint with your local data protection supervisory authority.
Our legal basis for processing is: performance of a contract (delivering the audit you requested), consent (marketing communications and optional analytics), and legitimate interest (fraud prevention, service improvement).
10. Children's privacy
BrokenProduct is a business tool intended for founders, product teams, and designers. It is not directed at, and we do not knowingly collect data from, anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as BrokenProduct evolves. If we make material changes, we will update the "last updated" date above and, where appropriate, notify active account holders by email. Continued use of BrokenProduct after a change takes effect constitutes acceptance of the updated policy.
12. Contact us
Questions about this policy or your data can be sent to hello@brokenproduct.com. We respond within 24 hours on business days.