PerformanceInsights.ai
Legal

Privacy Policy

How PerformanceInsights.ai ("we," "us") collects, uses, and protects personal data across our website and the Dump Triage service.

Last updated 2026-09-23

Short version: we're a small team running a pilot Windows crash-dump triage service. We collect the minimum we need to run your account and analyze the dumps you send us, we don't sell personal data, and we tell you below exactly which third parties see what. Questions or requests: hello@performanceinsights.ai.

Scope & roles

This policy covers performanceinsights.ai and the Dump Triage service. For Dump Triage, most personal data we handle comes from your uploaded crash dumps — memory snapshots that can incidentally contain personal data about your own end users, employees, or systems (usernames, file paths, tokens, or other fragments present in process memory at the time of the crash). In that relationship, you are the data controller and we are the data processor, acting only on your instructions under our Terms of Service and, where applicable, a data processing agreement. For your own account data (organization name, contact details, billing), and for anyone who visits our website, we are the controller.

What we collect

DataSourcePurpose
Organization name, contact email, plan, API keyYou, at signupOperate your account, authenticate API requests, send you reports
Crash dump files and any personal data they containYou, on uploadPerform the triage analysis you requested
Debugger command transcripts (redacted before analysis)Generated during analysisProduce the root-cause report; audited for quality/security
Webhook URL / secretYou, at setupDeliver completed reports to your system
Command-level audit log (never command output)Generated during analysisSecurity auditing and support
Basic site visit data (page requests, no cookies or analytics as of this policy's date)Standard web server logsOperate and secure the site

We currently don't use cookies, tracking pixels, or third-party analytics on this website. If that changes, this policy — and, where required, a consent mechanism — will be updated first.

Who we share it with

We don't sell personal data. We share it only with the subprocessors necessary to run the service. Our Subprocessors page lists each one, what it receives and where. In short:

  • Hetzner (Germany) hosts our API, database and encrypted dump storage.
  • Google Cloud (United States) runs the Windows debugger. The raw, decrypted dump, and any private symbol files you've uploaded, are copied to a worker VM there for the analysis.
  • Anthropic (United States) receives redacted debugger transcripts for the AI-assisted analysis steps, never the raw dump file.
  • Resend (United States) sends our emails, so it sees your contact address, organization name and the email text, including crash details in alerts to our staff.
  • Microsoft's public symbol server receives module and symbol identifiers, not dump contents.

We may also disclose data if required by law, or to protect our rights, users, or the public.

Reuse of resolved cases

When one of our engineers resolves an escalated case, they can add a short summary of it to an internal knowledge base: the crash or exception code, the faulting module's name, a crash signature, a root-cause category and a note written by the engineer. It doesn't include the dump file or debugger transcripts. The code, module name and signature are values the debugger reported, and the note is written by our engineer. When a later dump from any customer has the same crash or exception code and faulting module (or, failing that, the same crash signature), up to five matching summaries are included in the AI-assisted analysis of that dump. The module name, root-cause category and engineer's note are sent to Anthropic as part of that analysis. Today our engineers decide which cases are added. If you'd rather none of your cases are used this way, email hello@performanceinsights.ai and we'll exclude them and remove any already added.

Retention

The dump file and the full debugger transcripts produced from it are deleted 30 days after upload by default, or after the retention period configured for your account. What remains of the dump's record is metadata only: its size, type, upload date, file hash and a keyed hash of the uploading machine's name. Our internal audit log keeps the fact that your account uploaded it.

The structured analysis results (the report's findings, and for escalated cases the escalation notes) are currently kept after that. Case summaries added to the knowledge base (see Reuse of resolved cases) are also kept. We're adding deletion for both (tracking issue); until then, email us and we'll delete them on request.

Private symbol files you upload are kept until you delete them, which you can do through the API at any time.

Account records (organization, contact, billing) are retained for the life of the account plus a standard period for legal/accounting purposes. Audit logs are retained longer, for security-investigation purposes, and contain command text only, never dump or transcript contents.

Security

Dumps are encrypted at rest. Each analysis runs on a worker VM that's started for the job and stopped afterwards, and whose dump folders are emptied before every job. Workers only accept connections from our own servers and our engineers' addresses. We keep an audit log of the commands run against each dump and of staff actions on escalated cases, and we run a redaction pass on debugger output before any of it reaches a third-party AI model. We're still hardening parts of this during the pilot, including restricting the workers' outbound network access and encrypting the connection between our servers and the workers; see our public tracking issue for status. No system is perfectly secure; we'll notify affected customers without undue delay if we become aware of a breach affecting their data.

Your rights — EU/UK (GDPR)

If you're in the EU, EEA, or UK, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Our lawful bases are contract performance (running your account, delivering the service) and legitimate interest (security, fraud prevention, service improvement). Dump Triage currently analyses every dump in the United States (see Subprocessors), so personal data in a dump is transferred there. We aren't yet onboarding customers who need their data processed in the EU; before we do, we'll put Standard Contractual Clauses and transfer assessments in place for each transfer and update this section. To exercise a right, contact hello@performanceinsights.ai; we aim to respond within 30 days. If your data reached us through a dump uploaded by one of our customers, we'll generally direct you to that customer as the controller, unless they're unreachable.

Your rights — US state privacy laws

Depending on your state of residence (including California under the CCPA/CPRA, and similar laws in Virginia, Colorado, Connecticut, Utah, and other states), you may have the right to know what personal data we hold about you, to delete it, to correct it, to obtain a portable copy, and to opt out of the sale or "sharing" of personal data — we don't sell or share personal data as those terms are defined, so there's nothing to opt out of today. We don't discriminate against anyone for exercising a privacy right. To submit a request, email hello@performanceinsights.ai; we'll verify your identity before acting on it and respond within the timeline your state's law requires (typically 30–45 days).

Children's privacy

Dump Triage is a B2B service and our website isn't directed at children. We don't knowingly collect personal data from anyone under 16.

Changes to this policy

We'll update the "last updated" date above when this policy changes, and for material changes we'll notify active customers directly.

Contact

Questions, requests, or concerns about this policy: hello@performanceinsights.ai.