Privacy Policy
This Privacy Policy explains how Website Feedback Tool (“we,” “us,” and “our”) collects, uses, and discloses information in connection with our browser extension (the “Extension”) and our marketing website (together, the “Services”).
The short version: the Extension is a tool for leaving visual feedback on web pages. The feedback you create stays on your device unless you choose to share it. We collect a small amount of anonymous usage and crash data to fix bugs and improve the product. We do not sell your data, we do not show you ads, and we do not collect your browsing history or the contents of the pages you visit for analytics.
The Extension
Information stored only on your device
The reviews you create — your comments, the screenshots and screen recordings you capture, and your settings — are stored locally in your browser. This data never leaves your device unless you explicitly choose to share a review (see below). Uninstalling the Extension removes it.
Information uploaded when you share a review
When you click Share (or push a review to a connected AI coding agent), the Extension uploads the content needed to generate a shareable link:
- the screenshots and/or screen recordings you captured;
- the URL of the page you are reviewing;
- your comment text;
- related element metadata (such as CSS selectors and computed styles);
- a randomly generated review identifier and owner token.
This is uploaded to our backend (operated via Supabase; for users located
in Russia, to our self-hosted server at r.mrstanis.ru).
Anyone with the resulting link can view the shared review. Shared reviews and their media are automatically deleted after a short
retention window (approximately 4 days). Reviews you never share are never uploaded.
Anonymous analytics and crash diagnostics
To understand how features are used and to fix bugs, the Extension sends anonymous events to PostHog (EU region). These events contain:
- a randomly generated device identifier that is not linked to your name, email, or any account (the Extension has no account system), and which is reset if you reinstall;
- the Extension version and your browser’s interface language;
- milestone usage events (for example, “extension installed” or “review exported”);
- crash diagnostics — the error type, a truncated and sanitized error message and stack trace, and which part of the Extension failed.
We strip URLs and similar identifiers from diagnostic data before it is sent. PostHog may derive an approximate location (country/city) from your IP address. We do not collect your browsing history, the contents of the pages you visit, or the text you type, for analytics or diagnostics.
Uninstall feedback
If you uninstall the Extension, your browser may open an optional feedback form hosted on Google Forms. Completing it is entirely voluntary.
What we do not collect
The Extension does not collect your name, email address, passwords or other credentials, financial or payment information, health information, or your general browsing history.
The Website
Our marketing website uses Google Analytics to measure traffic and understand how visitors find us (including referral source and clicks to the Chrome Web Store listing). Google Analytics may set cookies and collect device/usage information such as IP address, browser type, and pages viewed. You can opt out using the official Google Analytics Opt-out Browser Add-on.
How We Use Information
We use the information described above solely to:
- provide the Extension’s core functionality (creating, storing, and sharing reviews);
- fix bugs, monitor reliability, and improve features;
- understand aggregate, anonymous usage of the Services;
- comply with the law and protect the rights, property, and safety of our users and the public.
We do not sell your data, use or transfer it to serve personalized or interest-based advertising, use or transfer it to determine creditworthiness or for lending, or use it for any purpose unrelated to the Services’ core functionality. This is consistent with the Chrome Web Store Limited Use requirements.
How We Share Information
We share information only as follows:
- Service providers (processors) who operate the Services on our behalf: PostHog (anonymous analytics and crash diagnostics), Supabase (backend and media storage), our self-hosted server in Russia (backend and media storage for users located in Russia), Web3Forms (delivering contact-form messages to our inbox), and Google Forms (optional uninstall feedback).
- Recipients of a link you share. A shared review is accessible to anyone who has its link, by design.
- Legal and safety. We may disclose information if required by law or where reasonably necessary to comply with legal process or to protect the rights, property, or safety of our users or the public.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
Data Retention
- Shared reviews and their media: automatically deleted after approximately 4 days.
- Locally stored reviews and settings: kept on your device until you delete them or uninstall the Extension.
- Anonymous analytics and diagnostics: retained by PostHog for the duration of its standard retention period.
Security
We use technical and organizational measures to protect information, including transmitting data over encrypted connections (HTTPS/TLS) and sanitizing diagnostic data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
International Data Transfers
Analytics are processed in the EU (PostHog). Shared-review data is processed by Supabase and, for users located in Russia, on our self-hosted server in Russia. Where information is transferred across borders, we take reasonable steps to protect it consistent with this Policy and applicable law.
Your Choices and Rights
- Reviews you don’t share stay on your device; uninstalling the Extension removes local data.
- You can delete a shared review (creating or updating a link removes the previous remote review), and all shared reviews expire automatically after ~4 days.
- If you connected an AI coding agent, you can regenerate or revoke its access token from the Extension at any time.
- Providing uninstall feedback is optional.
- Depending on your jurisdiction (for example, the EEA or UK), you may have rights to access, correct, or delete personal data we hold about you, or to object to or restrict its processing. To make a request, contact us at the email below.
Children
The Services are not directed to children under 13 (or under 16 in the EEA). If we learn that we have collected such information from a child, we will take reasonable steps to delete it.
Changes to This Policy
We may update this Policy as the Services evolve. We will post any changes here and revise the “Last Updated” date above. Material changes will be communicated as required by law.
Contact
Questions about this Policy or our privacy practices? Contact us at [email protected].