Telemetry Transparency
Version 0.2 · Pending legal review
The short version
Telemetry is operational information about how the software is used — not your documents, and nothing from inside them.
Today, none of it reaches us. The products record operational information on your own machine, where you can look at it and delete it. Nothing is transmitted.
One thing does leave, if you let it: an error report when something goes wrong. You can switch it off, and you are asked on first run.
That is the whole picture. The rest of this document explains how we classify what we would ever collect, what is switched on today, and what we would do before any of it changed.
What actually happens today
| What it is | Where it goes | Can you turn it off? | |
|---|---|---|---|
| Operational records | Counts and events describing how you used the software — pages reviewed, candidates found per type, how often engine suggestions were accepted or changed, settings changes | Nowhere. It stays on your machine. | It cannot be switched off, because there is nothing to switch off — it never leaves. You can view it and clear it at any time |
| Error reports | Stack traces, error messages, software version, operating-system family, and a pseudonymous device identifier when something goes wrong | An EU-resident error-tracking provider named in our sub-processor list | Yes, unconditionally. You are asked on first run and can change it in Settings whenever you like |
| Everything else | — | — | — |
File paths, exception messages, request bodies and the contents of variables are stripped on your machine before an error report is sent.
Seeing what has been recorded
Settings → View telemetry log shows every operational event the software has recorded on your machine: what it was, when, and what it contains. There is a button to clear it.
We think this matters more than an off-switch would. An off-switch asks you to trust that it works. A visible log and a delete button let you check.
How we classify telemetry
Four classes, by how sensitive the data is. This is the framework that would govern anything we ever collected.
Class A — Operational counts
Counts and aggregates describing use of the software. No document content. Pseudonymous identifiers generated on your own device.
In SureRedact: pages reviewed per Matter; candidates found per type; how often engine suggestions were accepted, edited or rejected; time-on-decision in buckets; failure events; settings changes.
In SurePrepare: records imported per source; which filter signals fired and how often; deduplication cluster sizes in buckets; triage decision counts.
Today: recorded on your machine, never transmitted.
Class B — Transformed learning artefacts
Strongly transformed material derived from operator decisions — hashed keywords, anonymised signal vectors, decision-context features. No record content.
Today: not collected in any tier. If it ever were, it would be explicit opt-in, with a preview of the exact artefacts before anything left your machine.
Class C — Masked exemplars
Masked snippets from the records where the filter and the operator disagreed, or where a decision took unusually long — the cases that would teach a detector something. Names, dates and addresses are masked before the snippet leaves the device.
Today: not collected in any tier. If it ever were, it would be explicit opt-in with a preview of the masked content, so you would see exactly what masking had done before agreeing to it.
Class D — Raw or near-raw content
Raw documents, full-fidelity emails, or extracts that would identify someone by their content.
Never permitted. The code path that would emit it does not exist in the shipped software.
The single exception is a specific, written, time-bounded support arrangement where you ask us to look at a file to debug a problem you have reported. That is you sending us something deliberately, not the product doing it.
What would happen before any of this changed
If we ever build a service to receive telemetry, you will know before it starts.
- A notice on our website at least 30 days before it takes effect, and an email to current customers.
- The classification above will say what class it is, and Class B and Class C would remain explicit opt-in with a preview.
- A real off-switch will exist before anything is transmitted, and it will not be tied to any paid feature — no upgrade banners suppressed in exchange, no rationing, no design intended to discourage you. This is contractual under §5.3 of our Terms.
- If telemetry ever improves the products, we will publish what it built — which detector improved, by how much, on which test suite — rather than asking you to take it on faith.
Your rights
Because operational records stay on your machine, they are not personal data we hold, so there is nothing for us to give you a copy of or to delete. You already have both: the log is visible in Settings and there is a clear button.
Error reports are personal data we hold, though they carry a pseudonymous device identifier rather than your name. Your rights under the Privacy Notice apply — access, erasure, objection — and the fastest route is to switch error reporting off, which stops it at source.
Changes to this document
A material change — a new event type, a new retention period, a change to what is switched on by default, or any transmission that did not happen before — is notified on our website within 10 working days, recorded below, and emailed to current customers at least 30 days ahead where their contract includes telemetry-change rights.
Change history
| Date | Version | Change |
|---|---|---|
| 2026-05-09 | v0.1 | Initial draft. |
| 2026-08-12 | v0.2 | Correction and rewrite. The previous version described telemetry being received, stored and retained by us, with a sub-processor hosting an ingestion endpoint. No such service exists and no telemetry has ever been transmitted to us. It also described a quarterly report on what telemetry had built, including illustrative figures that could be mistaken for real ones, and an opt-in flow for classes that are not collected. It opened by claiming we publish a Telemetry Legal Classification Matrix; we do not — it is an internal contract artefact. All removed. This version describes what the software actually does: operational records stay on your machine where you can see and clear them, and error reports are the only thing that leaves, switchable off. |
Questions
policy@surematters.com. We aim to reply within 5 working days on substance, and 1 working day on a point of wording.
Drafted with AI assistance and reviewed by a named person, per our AI Policy.