Sapito — Privacy Policy
Last updated: September 22, 2026
Sapito is an internal bug reporting tool built and operated by Virtual Latinos for its own staff. It is not offered to the general public, and it cannot be used without a Virtual Latinos Google account.
Who this applies to
Sapito is used by Virtual Latinos employees and contractors to report defects they encounter on Virtual Latinos' own internal platforms. Signing in requires a @virtuallatinos.com Google account; accounts outside that domain are refused.
What Sapito collects
Sapito collects the following, and only when an employee chooses to file a bug report:
Identity information
- The name and email address of the Google account used to sign in.
- This is resolved by Virtual Latinos' own server from the authenticated session. It is not supplied by the browser and cannot be altered by the person filing the report.
The contents of the page being reported
- A screenshot of the visible area of the page, or a screen recording, captured only when the employee explicitly requests one.
- The web address of the page.
- The browser's console error messages from that page.
- A log of the network requests the page made, including request and response contents, for up to the most recent 30 requests.
- The browser version, operating system and window dimensions.
Whatever the employee types
- The title and description they write, and any drawing they add on top of the screenshot.
Authentication information
- A short-lived sign-in token, held in the browser's session storage and erased when the browser closes. It is valid for 15 minutes and is bound to a single project.
What Sapito does not collect
- Browsing history. Sapito records the address of a page only when a report is filed from it. It does not build or transmit any record of pages visited.
- Keystrokes, mouse movement or on-page behaviour. There is no activity monitoring of any kind.
- Anything from sites outside Virtual Latinos' platforms. Sapito's capture runs only on the internal platform addresses registered by Virtual Latinos. On any other site it does nothing.
- Passwords. Sapito never handles credentials. Sign-in is delegated entirely to Google.
- Location, health, financial or payment information.
When collection happens
Console messages and network activity are held temporarily in the browser's memory while an employee is on a registered Virtual Latinos platform page, so that the evidence still exists if something goes wrong and a report is filed moments later. This buffer is capped, is discarded when the page closes, and never leaves the browser unless the employee submits a report.
Screenshots and screen recordings are captured only when the employee presses the button that takes one, and screen recording additionally requires Chrome's own screen-sharing permission prompt, which the employee must accept each time.
How the information is used
Collected information is used for one purpose: allowing Virtual Latinos' technical staff to understand, reproduce and fix the reported defect, and to follow up with the person who reported it.
It is not used for any other purpose. Specifically, Virtual Latinos does not:
- sell or transfer this information to third parties;
- use or transfer it for purposes unrelated to reporting and fixing defects;
- use or transfer it to determine creditworthiness or for lending purposes;
- use it to evaluate, monitor or measure the performance of the employees who file reports.
Where the information goes
Reports are transmitted directly to Virtual Latinos' own backend service and stored on infrastructure Virtual Latinos controls: a private database and a private storage bucket operated on Cloudflare. No third-party analytics, advertising or tracking service receives any of it.
Access is restricted. An employee can see the reports they filed themselves. Administrators can see reports only for the specific platforms they have been granted access to. Screenshots and recordings are served only through the authenticated backend, never from a public address.
Safeguards
- Web addresses recorded in the network log have their query strings removed before storage, so credentials or tokens that appear in a URL are not retained.
- The identity attached to a report is determined by the server from the signed-in session, so it cannot be forged by the client.
- Stored credentials for optional integrations are encrypted and are never returned to the browser.
Optional integrations
If a Virtual Latinos administrator connects a project to an external issue tracker such as Notion or Jira, an administrator may choose to create a ticket there from a report. That ticket carries the report's title, description, console errors, page address, the reporter's name, and a link back to Sapito. Screenshots and recordings remain behind Virtual Latinos' sign-in and are linked to rather than copied.
How long it is kept
Reports and their attachments are retained for as long as they remain useful for engineering purposes. They are not deleted on a fixed schedule. Any report can be deleted on request — see Contact, below.
Your choices
Employees may request that a report they filed be deleted, or ask what has been collected about them, by contacting the address below. Uninstalling the extension stops all collection immediately; reports already filed remain in the system subject to the retention period above.
Changes to this policy
If this policy changes materially, the updated version will be published at this address and the date at the top will be revised.
Contact
Questions about this policy, requests to see what has been collected, and requests to delete a report: techtools@virtuallatinos.com
Virtual Latinos