Sign in

Privacy

What Prized records about how you use the product, and what it never records.

On this page6

Usage data comes from two places, the CLI on your machine and the website and dashboard; neither reads what is inside your box. How a box is reached and what the control plane holds about it are on Security and trust.

Never collected

Nothing from inside your box is sent anywhere for analytics:

  • Source code, files, and anything else on the box filesystem
  • Terminal output and shell history, the in-browser terminal included
  • Secret values and environment variable values
  • CLI arguments, flags, and paths

Website and dashboard

The site records page views, clicks, and these named product events:

  • Signing up (which sign-in provider, and where you came from)
  • Creating a box, the box reaching running, or waiting for capacity
  • Opening the browser terminal; signing in from the CLI
  • Pausing, resuming, resizing, and deleting a box; changing auto-pause
  • Copying a CLI command; the onboarding steps you view
  • Starting checkout (with the plan amount); activating a plan
  • On a campaign page: the sections you scroll to, and how much of its film you watch

Events also note whether the page is open inside a social app's built-in browser (Instagram, Facebook, Threads, TikTok, LinkedIn, Snapchat), read from the browser's user agent.

Once you sign in, events are tied to your account, including the pages you viewed before signing up in the same browser, so a broken flow can be traced to the account that hit it.

"Where you came from" is one first-party cookie, prized_src, set on the first page you land on and kept 30 days: the referring site's hostname, the landing path (invite and install tokens removed), and any campaign tags (utm_source, utm_medium, utm_campaign, ref) on the link you followed. It holds no identifier and is never rewritten by a later visit. With Do Not Track on, it is not set, a stored one is removed on your next page load, and a sign-up callback is not recorded.

Each sign-in records its time, network address, and browser, kept 90 days to investigate abuse and account takeover (Data retention); Settings → Sessions shows the address of each of yours.

Before anything leaves your browser, its URL is cut to the path: query strings and fragments are dropped, and one-time links (invites, install links) become a placeholder.

Session replay

While you are signed in, the dashboard records a replay of the interface, masked in your browser before anything is sent:

  • Every input and every piece of text is masked: a replay shows layout, clicks, and navigation, never the words on the page.
  • The terminal, the secrets panel, and the environment variables panel record as empty placeholders.

Signed-out visitors are never recorded, so the marketing pages and these docs produce no replay.

Turning it off

  • Browser. The site respects Do Not Track: with it on, the site records nothing, no page views, events, or replay.
  • CLI. A separate switch, under CLI: usage telemetry.

How long it is kept

Retention windows for box metrics, process snapshots, and CLI usage aggregates, and how zero data retention shortens them, are on Data retention.

Where it goes

  • PostHog holds the product events, the account they belong to, session replay, and error reports when a page throws, in its US cloud.
  • Vercel Web Analytics, run by the platform that hosts the site, holds aggregate page-view counts (visits per page, by country and browser). It is never told who you are, sets no cookie, and sees the same cut-down URL.

An ad blocker may block the analytics requests; that affects our telemetry, never the dashboard.