Compass builds its picture of your users from data Chameleon already has, and, once session tracking is on, from what users click and which pages they visit. It never records what your users type.
Availability & usage
đ Applies to Compass
đ§âđź Admins can pause session recaps in AI Controls
What does Compass use without Session tracking?
Your Features list and profile summaries are built from what Chameleon already has:
The User Properties and Company Properties you send through your installation
How recently and how often each user visits
Users' answers to your Microsurveys
Your public website, docs, and pricing page, to work out your Features
What does Session tracking collect?
With Session tracking on, Compass records each user's activity in your product:
Pages visited: the page URL, with known sensitive parameters removed (such as email, user ID, phone, location, passwords, API keys and sign-in codes). See the full list in What user data does Chameleon collect by default?
Page titles: the page's main heading, or its title
Clicks: the visible text of what was clicked (up to 128 characters), such as a button, link or menu option label
Element details: basic details about each element clicked, such as its type and label, and where on the screen it was clicked
Other actions: form submits, drag and drop, switching tabs, and cut, copy and paste
Text fields: that something was entered, and how many characters, never the text itself
Files: the names of files dragged into the page, never their contents
Events: Chameleon Events you track, and their properties
Timing and IDs: a timestamp for each action, plus the Chameleon user and account IDs already in your installation
What does Compass never collect?
What users type. For text fields, Compass only notes that something was entered and how long it was
Anything cut, copied, or pasted. It's recorded as a length, never the content
Passwords. Password fields are ignored entirely
Payment details
File contents. Only the names of files dragged into the page
â ď¸ Compass records what's visible on screen where users click, and the address of each page. If your product shows sensitive information in those places, such as a record ID in a page address or a person's name in a list someone clicks, that's collected too. Review what your product shows before you turn on session tracking, and contact us if you have questions.
Can I exclude pages or elements from session tracking?
Session tracking covers every page where your Chameleon installation runs.
Does Compass process personal data?
That depends on what your team sends to Chameleon. Chameleon doesn't independently collect names, email addresses or other personal identifiers. But if your identify call or your Events pass them (for example email, name or role), they're part of the data Compass reads.
Some privacy frameworks define personal data broadly. Under GDPR, for example, IP addresses may count, depending on jurisdiction and context. If your organization has specific data classification requirements, we recommend reviewing your Chameleon identify calls and Events before you turn on Session tracking.
Does Compass train AI models on our data?
No. Chameleon doesn't train AI or machine learning models on your data or on your users' data. Activity and profile data are sent to AI models only to write summaries and recaps.
How is Compass data processed and stored?
|
|
Subprocessors | Compass uses Chameleon's existing subprocessors, including OpenAI for AI processing. All are listed in our Trust Center, under our GDPR, CCPA and SOC 2 frameworks |
Storage | All data is stored within Chameleon's own infrastructure and retained in accordance with Chameleon's standard data retention policies. Profile and session summaries persist as part of your Chameleon account data |
Controller / processor | Chameleon acts as the data processor. Your organization remains the data controller and controls which user attributes it sends to Chameleon |
Who decides whether Session tracking is on?
Session tracking is on by default for new accounts. An Admin can switch it off or back on at any time with the Sessions Summaries toggle in AI Controls.
â
How do I stop collection or delete data?
Switch Session tracking off in AI Controls at any time. To have collected session data deleted, email the security team. For certifications, the full subprocessor list and downloadable security docs, visit our Trust Center.
â
