reportr turns the commission data you already see in your carrier portals into clean, white-label client reports. this explains what it reads, where that data goes, and what it stores.
last updated: 10 june 2026
reportr only reads the commission data you explicitly choose to capture — either by clicking “capture” on a carrier portal tab you’re already logged into, or by uploading a pdf or csv statement. it sends that data to our server to reconcile it and build your report, and it stores your account, your reports, and basic usage so you can re-open them. it never sees your portal passwords, never runs in the background, and never sells your data.
reportr is built by ogbuilds, a uk-based studio. we operate the reportr extension and the reportr web app and backend, and we act as the data controller for the account and report data described below. it’s governed by uk data-protection law (uk gdpr).
when you click capture on a carrier or portal tab you are already logged into, the extension reads the commission figures shown on that page inside your own authenticated session — it acts on your behalf, on a page you have already opened and signed into. it does not log in for you, does not enter credentials, does not click through paywalls, and does not call private endpoints. capturing only happens on your explicit click; nothing runs in the background.
captured records are held temporarily in the browser’s chrome.storage.session (cleared when you close the browser) until you choose to generate a report. the extension only ever holds its own reportr session token — it never holds your carrier passwords or any provider oauth tokens.
solely to provide the service: to reconcile the commissions you capture or upload, render your white-label reports, keep your report history and share links, meter credits, and process subscriptions. we do not sell your data and do not use it for advertising.
we share data only with the providers we need to run the service:
reportr contains no third-party advertising trackers and no third-party analytics in the extension.
the extension and web app sign you in with a session token. in the extension it’s kept in chrome.storage.local; in the web app it’s kept in your browser’s localStorage. captured-but-not-yet-saved records live in chrome.storage.session and clear when you close the browser. we don’t use advertising cookies.
we keep your account, reports and usage while your account is active so you can re-open reports via their share links. report share links are unguessable tokens; treat them as private. you can ask us to export or delete your data, and we delete it on request and when an account is closed.
under uk gdpr you can ask us to access, correct, delete, or export your data, and you can withdraw consent for an optional integration at any time (disconnecting it removes its stored tokens). to exercise any of these, reach us via ogbuilds. you also have the right to complain to the uk ico.
some subprocessors (neon, vercel, stripe, google, meta) are based in the united states, so your data may be processed there. where that happens, transfers rely on appropriate safeguards such as the providers’ standard contractual clauses.
reportr is a business tool and is not intended for anyone under 13. we don’t knowingly collect data from children.
data is encrypted in transit (https). session tokens are signed, scoped to your account, and expire. account, report and connection data are stored in our managed postgres database; connected-integration tokens are kept server-side and never sent to the extension.
if this policy changes we’ll update the date above, and for material changes we’ll note it on this page or in the app.
questions about privacy? email support@ogbuilds.ai, or reach out via ogbuilds, the studio behind reportr.