SDK Data & Privacy
The complete answer to "what does this SDK send?" — every data category the ClientLens SDK collects, everything it never touches, and the flag that turns each one off.
Applies to the React Native, Flutter, iOS, and Android SDKs
Contents
1. What the SDK Collects
The ClientLens SDK only transmits data when a feedback report is created — it does not continuously track users, record sessions, or collect analytics in the background. A report can contain:
- The feedback itself: comment text, type, priority, and optional voice note
- Screenshots: only the screens the reporter captures and chooses to send (up to 3 per report)
- Device context: device model, OS name and version, app version and build number, screen dimensions, pixel ratio, network type (wifi/cellular), and available memory
- App context: current screen name, navigation stack, and any custom metadata your code attaches via setMetadata()
- Recent console logs and network request logs (URLs, status codes, and timing — capped and truncated), if enabled
- User identity only if your code explicitly sets it via setUser() — the SDK never reads contacts, location, advertising IDs, or identifiers on its own
2. Automatic Crash & Error Capture
In production mode, the SDK can automatically submit a report when the app hits an unhandled error or a failing API call. These reports include the error message, stack trace, device context, and recent logs, and are marked with source auto_crash or auto_api_error.
This behavior is fully under your control: it only runs in production mode, and you can disable it entirely by running the SDK in development mode or disabling the SDK at runtime. Automatic reports follow the same data rules as manual reports.
3. What Is Never Collected
- No location data, GPS, or geofencing
- No contacts, photos, files, or other on-device content
- No advertising identifiers (IDFA/AAID) or device fingerprinting
- No keystrokes, gesture recording, or session replay
- No background screenshots — screen content is only captured when a report is being created (or at the moment of a crash, if automatic capture is enabled)
- No third-party trackers or analytics SDKs bundled inside ClientLens
4. Turning Things Off
Every capture category can be disabled in the SDK configuration:
- captureConsoleLogs: false — never attach console output to reports
- captureNetworkLogs: false — never attach network request logs
- mode: development — disables all automatic crash/error reporting; only manual reports are sent
- enabled: false or ClientLens.disable() — turns the SDK off completely at runtime (e.g. for users who opt out)
- Voice notes and screen recording are user-initiated and can be left out of a report by the reporter
The same flags exist across the React Native, Flutter, iOS, and Android SDKs. See each SDK README for exact syntax.
5. Storage & Retention
Feedback data is stored on ClientLens servers and is only visible to the members of the project it belongs to. Screenshots and recordings are stored in access-controlled storage and served only to authenticated project members.
Deleting a feedback item removes it from your dashboard, and its attachments are removed by scheduled cleanup. Deleting a project, or your account, permanently removes all associated feedback, screenshots, and recordings. You can export all of your account data at any time from Settings (GDPR data export).
6. Transmission & Security
All SDK traffic goes over HTTPS/TLS to clientlens.online, authenticated with your per-project key. Reports created while the device is offline are queued locally inside your app sandbox and sent when connectivity returns — nothing is written outside your app's storage.
Project keys authorize feedback submission only. They cannot read feedback back, list projects, or access any account data, so shipping them inside your app is safe by design. You can rotate a project key at any time from the project settings.
7. Your Responsibilities as a Developer
You are the data controller for what your app sends. In practice:
- If your app screens can display sensitive personal data, consider disabling automatic crash screenshots or masking sensitive views before enabling production mode
- Only attach personal data through setUser()/setMetadata() if you have a lawful basis for processing it
- Mention feedback collection in your app's privacy policy — the App Store and Play Store both expect it
- For App Store submissions: the ClientLens iOS SDK ships with a privacy manifest (PrivacyInfo.xcprivacy), so Xcode privacy reports include it automatically
Client asking about compliance?
Send them this page, or reach out if you need something specific for a security review.