A summary for the person filling in a security questionnaire or answering “where does our data actually go?” The contractually binding version of all of this is Gleap's Data Processing Addendum — this page is the readable one.
Conversations — tickets and every message in them, across all channels.
Contacts and companies — what you and your product send: names, addresses, custom attributes, events.
Technical data from reports — console logs, network requests, replays, device and page information.
Uploaded files — screenshots and attachments from the widget and dashboard.
Your configuration — help center content, workflows, agents, surveys and settings.
The middle two are where personal data arrives without anyone deciding to send it. Both can be limited from your SDK setup, which has its own article.
Gleap's primary infrastructure runs in the European Union, in Frankfurt, on DigitalOcean — with additional workloads on Microsoft Azure (Frankfurt) and AWS (EU, Luxembourg).
Two things sit outside that, and both matter in a questionnaire:
Uploaded files are stored in Cloudflare's object storage, and Cloudflare also provides DNS and delivery in front of the infrastructure. Screenshots and attachments can contain personal data, so this is worth naming rather than glossing over.
AI features send data to the AI providers listed on the sub-processors page, some of which process outside the EU. They only run when AI features are used, and can be disabled entirely.
US data residency is available on the Enterprise plan.
Your data stays while your account is active — there's no automatic expiry of tickets or contacts, which is what teams want from a support history.
You control the rest: deleting a contact deletes their tickets with them, and deleting a project or account removes what it held. Gleap's privacy policy sets out what happens after an account is deleted and the legal retention obligations that can outlast it.
Data is encrypted in transit, customer workspaces are logically isolated, and access to production systems is controlled and traceable. Gleap is SOC 2 Type II audited.
Availability and incidents are published at status.gleap.io.
Gleap's trust pages carry the security practices and the full sub-processor list, and the Data Processing Addendum carries the binding commitments — including the technical and organisational measures annex.
For anything not covered there, including a copy of the current SOC 2 report, write to [email protected].