Analytics disclosure

Varve measures only a few aggregate product and website questions. Unknown consent fails closed, and no autocapture, session replay, cookie, or fingerprint is used. The Plausible loader is injected only after consent, with its automatic capture features disabled.

Website events

EventFieldsPurposeStatus
website_page_viewednormalized routeUnderstand which documentation and product pages are useful.emitted
website_download_startedrelease, platform, architecture, package type, release channelMeasure the download funnel and platform demand.emitted
website_outbound_clickeddestination categoryUnderstand whether GitHub, documentation, or community links help visitors.emitted
website_contact_clickedchannel categoryUnderstand which support/contact channels are used.emitted

Desktop events

Desktop events attribute to the pseudo-page varve.studio/app so they never mix with website pageviews. A periodic flush timer and a beforeunload handler ensure events reach the provider even if the app shuts down.

EventFieldsPurposeStatus
app_launchedsurfaceCount opted-in product sessions.emitted
document_createdblank, template, or import sourceUnderstand activation without seeing the document.emitted
feature_usedclosed feature categoryPrioritize features with meaningful adoption.emitted (high-signal subset)
export_completed / export_failedformat and coarse duration or error categoryFind export reliability and performance problems.emitted
renderer_fallbackfrom, to, reasonFind platform-specific renderer fallback issues.emitted
browser_demo_launchedentry sourceCount demo sessions from the website.emitted
browser_demo_desktop_downloadrelease, platform, architecture, package typeMeasure demo-to-desktop conversion.emitted

Never collected

Documents, canvas pixels, screenshots, exported artwork, clipboard data, filenames, paths, project or layer names, user text, comments, URLs from designs, imported metadata, image hashes, geometry, generated code, AI prompts, raw exception strings, raw stacks, device identifiers, authentication identities, advertising identifiers, and arbitrary payload fields are prohibited by the schema and runtime privacy boundary.

Consent and transport

Website consent is separate from desktop usage analytics, diagnostics telemetry, and crash reporting. The client uses a bounded in-memory queue, never blocks editing or navigation, and discards pending events when consent is revoked or the process ends. The production deployment is configured for the aggregate Plausible site at varve.studio; local and unconfigured builds remain endpoint-free.

Read the full privacy policy.