# What your visitors see

## The feedback form

The visitor clicks the floating **Give feedback** button or your own trigger link. The panel, titled **Send feedback**, has:

- **Report a bug** / **Suggest**: the type, when your site collects both.
- **Summary** (optional, up to 255 characters) and **Details** (required, up to 5000 characters).
- **Your email** (required) and **Your name**. These are hidden when your page has identified the visitor. See [Identifying your users](identity.md).
- A checkbox to attach a screenshot of the page.
- **Send**.

Visitors close the panel with Escape, the × button, or by clicking outside it. They can switch language from the panel.

After sending, an identified visitor sees "Thank you. Your feedback has been sent." A visitor who is not identified sees "Almost there. Check your inbox to confirm your email, and we will pass this on." Their report reaches you once they click the link in that email.

## Screenshots

When the visitor ticks the screenshot box:

- In Chrome, Edge and other Chromium browsers, the browser asks permission to share the current tab. If the visitor refuses, or picks something other than the current tab, no screenshot is attached.
- In Firefox and Safari there is no prompt: the visible part of the page is drawn by the widget instead.

The widget itself, and any element with the `data-ur-mask` attribute, is hidden during the capture. Add `data-ur-mask` to anything that should never appear in a screenshot, such as account numbers or personal details. Screenshots are PNG, up to 5 MB. If the capture fails, the report is still sent without it.

The checkbox warns visitors that a screenshot may capture personal data on screen.

## What is captured automatically

With every report, the widget sends:

- the page URL and page title;
- the browser, viewport and screen size, language and referrer;
- JavaScript errors and unhandled promise rejections on the page (up to 20);
- failed `fetch` requests (up to 20). Requests made with XMLHttpRequest are not captured.

Before storing a report, Userreact replaces likely personal data and secrets in the referrer, console errors and failed requests with `[redacted]`: email addresses, tokens and API keys, card-like numbers, and URL parameters such as `token`, `api_key`, `password`, `secret` or `signature`. The page URL of the report itself is kept as it is.

## When the widget says "Feedback is not available on this site right now"

The visitor sees this when the report is refused for a reason they cannot fix by retrying:

- the page is not on the site's domain, a subdomain, or one of its accepted origins;
- the site is archived;
- the public key in the snippet is wrong;
- the account has reached its plan's report limit. See [Plans and limits](plans.md).

The exact reason is written to the browser console, starting with `[userreact]`.

Other messages: "Too many attempts. Please wait a minute and try again." (too many reports in a short time), "Please check the form and try again." (a field is invalid), and "We could not send your feedback. Please try again." (anything else, such as a network error).

## Limits on sending

To stop abuse, each site accepts up to 120 reports a minute, 10 a minute from one visitor's connection, and 5 a minute from one email address.