Privacy
Your HAR stays in your browser.
ReqRescue is designed so its hosted server does not need your trace in order to analyze it.
Local trace processing
HAR reading, validation, triage, redaction, previews, reports, and exports run locally in a browser worker. ReqRescue does not send HAR contents, file names, URLs, headers, cookies, bodies, or generated reports to its application server.
Product events
The hosted build records a small allowlist of product events, such as opening the page, completing the demo, or exporting a report. Each event may contain a random pseudonymous session identifier stored in your browser, an acquisition source, or optional feedback you choose to type. Feedback is limited to 220 characters. Do not place secrets or personal data in feedback.
Supporter verification and local storage
If you verify an honorware purchase, your entered license key is sent directly from your browser to Gumroad. ReqRescue does not receive the key. The unlock flag, pseudonymous session identifier, and any saved incident briefs remain in this browser's local storage until you clear site data.
Hosting records
Cloudflare may process ordinary technical request data needed to serve and protect the website, such as IP address, user agent, and request timing, under its own infrastructure policies. That is separate from HAR processing, which remains local.
Redaction limitations
No automated sanitizer can recognize every private value or product-specific identifier. ReqRescue removes bodies, credentials, common secrets, private hosts, IP addresses, and unknown vendor fields, but you must review a sanitized export before sharing it.
Last updated: July 27, 2026.