# Did It Though? privacy and data

How Did It Though? uses account information, uploaded evidence, feedback and access credentials.

## Data used to provide the service

Did It Though? uses account details such as your name and email address to sign you in and associate you with workspaces. It stores project and review metadata, uploaded screenshots and videos, annotations, comments and revision history so people and agents can carry out visual reviews. Upload only content you are authorized to share, and remove secrets or personal information that the review does not need.

The service uses session cookies for sign-in and access control. Agent tokens are stored as hashes and can be revoked by the workspace owner. Activity records associate actions such as uploads, comments and token use with the responsible account or agent token. The CLI saves its agent credential locally so later commands can authenticate.

## Who can access evidence

Workspace membership and scoped tokens control access to project data. Share links, embed links, download links and one-time upload URLs are capability credentials: anyone holding a valid link can use the access that link grants. Some links expire and links can be revoked. A link marked noindex is still a credential; noindex does not make a publicly posted link private.

The application runs on Cloudflare Workers, with review metadata in D1 and media in R2. Where billing is enabled, Stripe processes subscription payments through the service's billing integration. Information you send to the support contact is used to respond to your request.

## Retention and requests

Media availability and deletion follow the workspace's plan. A revision may be active, expired but recoverable, or deleted; these states and relevant dates are exposed in review responses. Expired media is hidden before its recovery period ends, and scheduled maintenance removes media that is past its deletion date. Changing plans can change retention. Media retention is separate from the retention of account details, comments and activity records.

For questions about personal information, access, correction or deletion, contact Pixelhop at hello@pixelhop.io and identify Did It Though? and the account concerned. Do not send passwords, API tokens or claim codes. This page describes the product's data handling; contact the team for details about your specific request or deployment.

- [Contact Pixelhop](https://diditthough.app/contact)
