Privacy Policy
Last updated: 2026-07-18
This Privacy Policy explains how FrictionScope ("we", "us", "our") collects, uses, and protects your personal data when you use the service at https://frictionscope.dev.
We handle your data lawfully under the EU General Data Protection Regulation (GDPR).
1. Who we are
- Service: FrictionScope
- Website: https://frictionscope.dev
- Contact: [email protected]
If you have a concern about how we handle your data and we cannot resolve it directly, you can lodge a complaint with the data protection authority in your country of residence.
2. The Service in plain language
FrictionScope reads your own Microsoft Clarity analytics and tells you which pages on your site are frustrating visitors. It has two parts:
- A hosted web app at frictionscope.dev where you sign in, connect a site, and view the results.
- A hosted MCP server that your editor (Claude Code, Cursor, Cline, Windsurf, or any Model Context Protocol client) connects to over OAuth, so the same results are available where you write code.
Microsoft Clarity's data export API only exposes the previous one to three days. FrictionScope takes one snapshot per day and stores it, so you can see history and compare a page before and after a change. That stored history is the reason the service exists.
We do not run AI inference on your data. When you use the MCP server, your editor's own model does the reasoning. We hand it data and nothing else.
We are not affiliated with Microsoft. Clarity is a trademark of Microsoft Corporation.
3. What data we collect
3.1 Account data
When you sign in with Google (the only sign-in method), we receive and store:
- Your email address
- Your name and profile picture, as provided by Google
- A Google account identifier used to recognize you on return visits
We never receive or store your Google password.
3.2 Credentials you provide
- Microsoft Clarity API tokens. One per site you connect. You generate this in your own Clarity project and can revoke it there at any time. It is stored encrypted and is used only to make the daily snapshot request on your behalf.
3.3 Analytics data we retrieve on your behalf
Once per day, for each connected site, we request aggregate metrics from Microsoft Clarity broken down by page URL, and store them with the date. Each stored row contains:
- The page URL
- Session and bot-session counts for that page
- The percentage of sessions in which each friction signal occurred (rage clicks, dead clicks, quickback clicks, excessive scroll, error clicks, script errors)
- Average scroll depth and total engagement time
This data is aggregate and contains no information about individual visitors. Clarity's export API does not return session recordings, heatmap coordinates, IP addresses, device identifiers, or any other individual-level record, so we cannot receive them. We hold counts and rates per page, nothing more.
3.4 Technical data
- Server logs (IP address, request path, timestamp, user agent) retained for security and debugging
- Session cookies required to keep you signed in
4. Legal basis for processing
| Data | Purpose | Legal basis |
|---|---|---|
| Account data | Create and secure your account | Contract performance |
| Clarity API tokens | Retrieve the data you asked us to retrieve | Contract performance |
| Aggregate page metrics | Provide the service | Contract performance |
| Server logs | Security, abuse prevention, debugging | Legitimate interest |
5. How long we keep it
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| Clarity API tokens | Until you remove the site or delete your account |
| Daily page snapshots | Until you remove the site or delete your account. This is the product's core value, so we do not expire it on a timer. |
| Server logs | 30 days |
| Database backups | 7 days rolling |
When you delete your account, your account data, tokens, and snapshots are deleted from the live database. Backups age out within 7 days.
6. Who we share it with
We do not sell your data. We do not share it with advertisers. The following subprocessors are involved in running the service:
| Subprocessor | What it processes | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting. All application data lives here. | Falkenstein, Germany (EU) |
| Cloudflare, Inc. | DNS, CDN, and the MCP server edge worker. Sees request metadata. | Global edge network |
| Google LLC | Sign-in with Google. Provides your email, name, and profile picture. | Global |
| Backblaze, Inc. | Encrypted off-site database backups. | United States |
| Microsoft Corporation | Source of the analytics data. We send your API token to Clarity to retrieve your own data. We do not send Microsoft any personal data about you. | Global |
Backups sent to Backblaze leave the EU. They are encrypted, and the transfer relies on the vendor's Standard Contractual Clauses.
7. Where your data is stored
Primary storage is in Germany (EU). Encrypted backups are replicated to Backblaze B2 in the United States. Cloudflare serves requests from its global edge network.
8. Your rights under GDPR
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Port your data to another service in a machine-readable format
- Object to processing based on legitimate interest
- Restrict processing while a dispute is resolved
To exercise any of these, email [email protected]. We respond within 30 days.
You can revoke our access to your Clarity data at any time without contacting us, by deleting the API token inside your own Clarity project. That immediately stops all future snapshots.
9. Cookies
We use only what the service needs to function:
- Session cookie: keeps you signed in. Strictly necessary, no consent required.
- CSRF token cookie: protects against cross-site request forgery. Strictly necessary.
We do not use advertising cookies, tracking pixels, or third-party analytics on the marketing site.
10. Security
- All traffic is served over HTTPS
- Clarity API tokens are stored encrypted at rest
- Sign-in is delegated to Google; we never handle passwords
- The MCP server authenticates over OAuth and exposes read-only tools. It cannot modify your Clarity account or your site.
- Backups are encrypted before leaving the server
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.
11. Children
FrictionScope is a developer tool and is not intended for anyone under 16. We do not knowingly collect data from children.
12. Changes to this policy
If we change this policy materially, we will update the date at the top and notify account holders by email. Continued use after a change means you accept the updated policy.
13. Contact
Questions about this policy, or about your data: [email protected]