Data we never collect
Form values, keystrokes, cookies, fingerprints and precise location: the data Little Friend never collects, and how the script and collector enforce it.
You can't turn these on. The script can't collect them, the collector drops them if they arrive anyway, and tests prove both.
Never collected
| What | How |
|---|---|
| Form values and input contents | lf.js sends only a form id you assign. Session replay draws a filled field as ••••• and keeps no checked box or chosen option. |
| Keystrokes | lf.js never reads which key was pressed: a key press only marks the page as active, for active time. Session replay records that a field was filled in, never what was typed. |
| Cookies | None are set, and none are read. |
| Auth headers | The script never reads them, and the collector never stores them. |
| The clipboard | Never touched. |
| Precise location | Country at most, looked up from the IP address while the request is handled. The address is never stored. |
| Query strings and fragments | Stripped before anything is sent. Only allowlisted utm values survive. |
| Fingerprints | No canvas, font, audio or device-trait tricks. Unknown stays unknown. |
What apps send
The iOS and macOS SDK sends the app's id and version, the platform and the device class (mobile, tablet or desktop), routes, event names and cleaned properties, and the UTM values of a link that opened the app. It never reads or sends a device identifier, the device model, the OS build, the locale, the time zone, what is on the screen, or any other value in a link.
Page text and session replay
lf.js never reads page text or HTML: events carry names you choose. Session replay is the one feature that records the page itself, and it is off until you turn it on in journey mode. A recording keeps each page's layout with every word masked, and shows only the text you choose. Images, video, canvas and iframes are always left out, and so is anything that looks like an email address or a phone or card number. How replay masks a page.
Used for a moment, never stored
IP addresses and full user agents arrive with every request. The collector uses them briefly to classify the visitor, verify crawlers and look up the country, then drops them. They never reach a table, a log or a dead letter queue.
In aggregate mode there is no session or visitor key anywhere: not in the request, not in storage, not in logs. If a request carries one anyway, the collector throws it away and counts the drop.
Ids and emails in URLs
URLs often contain things that identify people, so every path is reduced to a route first:
| Path on your site | What we keep |
|---|---|
/orders/8812/items?coupon=SPRING#summary | /orders/:id/items |
/u/jane.doe@example.com/settings | /u/:redacted/settings |
/invite/3b9f1c2a-8d7e-4f60-a1b2-c3d4e5f6a7b8 | /invite/:id |
/reset/Q7xk2Lm9Pz4Rt8Vb3Nc6Wd1f | /reset/:id |
/docs/install/ | /docs/install |
Personal data in event values
Property values and campaign tags that look like an email address or a long run of digits are dropped, even when you send them on purpose.
| Value | Result |
|---|---|
newsletter | Kept |
jane@example.com | Dropped |
order 4111 1111 1111 1111 | Dropped |
spring_sale | Kept |
If you find a leak
Tell us at hello@littlefriend.io and we'll treat it as a top-priority bug.