Privacy Policy

Last updated: 10 September 2026

The short version. ReviewMySites stores the account you create and the feedback you write — comments, the pages they were left on, and any screenshots you attach. We do not sell any of it, we do not run advertising or third-party analytics, and we do not track you across other websites. The RMS - Screenshots browser extension collects nothing at all: it takes a picture of the tab only when you attach a screenshot to a comment, hands that image to the ReviewMySites page that asked for it, and sends nothing anywhere itself.

1. Who this covers

This policy applies to the ReviewMySites website, the ReviewMySites web application, the embeddable review script that customers add to their own websites, and the RMS - Screenshots Chrome extension. Together these are “the Service”.

Where a customer installs ReviewMySites on their own website and invites their team or clients to leave feedback, that customer decides what is collected and why. In that arrangement they are the data controller and we act as their processor, handling the data on their instructions. If you were invited to review a site and have a question about that project’s data, the customer who owns it is the right first contact — though you are welcome to reach us at privacy@reviewmysites.com and we will help you find them.

2. What we collect

Account information

Your name, email address, and a profile image if you choose to add one. Your password is never stored in a readable form — authentication is handled by Supabase, which stores a cryptographic hash.

Feedback you write

The content of your comments and replies, and the context needed to put each comment back in the right place and make it useful to whoever reads it next:

Screenshots

A screenshot is captured only when you attach one to a comment. It is a picture of the visible area of the tab at that moment, so it will contain whatever was on screen — including anything private that happened to be visible. Screenshots are stored in Cloudflare R2 and are visible to the people with access to that project.

Technical information

Our hosting provider keeps standard server logs, which include IP addresses and request details, for security and reliability. We use IP addresses to rate-limit anonymous requests. We do not run third-party analytics, advertising, or cross-site tracking of any kind.

3. The RMS - Screenshots extension

The extension exists for one narrow reason. Attaching a screenshot in a browser normally means Chrome’s “share your screen” prompt, which is tied to the page you granted it on, dies when you follow a link, and leaves a sharing indicator on screen while it lasts. The extension takes the picture from the tab instead.

The extension collects, stores and transmits no data of its own. It has no servers, no account, and no analytics. Specifically:

Permissions. The extension requests access to all sites (<all_urls>) because Chrome’s tabs.captureVisibleTab API is available only to extensions holding broad host access — it cannot be scoped to a single site. That access is declared as optional: it is not granted when you install the extension, and it is requested from the extension’s own setup screen, which explains what it is for before Chrome’s dialog appears. The same switch revokes it, as does removing it from chrome://extensions. The extension re-checks the grant before every single capture rather than remembering it, so revoking takes effect immediately.

4. Why we use it

We do not sell personal data, and we do not use it to train machine learning models.

5. Who it is shared with

Within the Service, your comments are visible to the people with access to the project they belong to — the workspace members, and anyone holding a share link that the project owner has created. Outside the Service, we share data only with the providers that run it:

ProviderWhat it doesWhat it sees
SupabaseDatabase and authentication — accounts, workspaces, projects, commentsAccount details, comment content and context
Cloudflare R2Object storage for screenshots and thumbnailsScreenshot images
ResendTransactional email — invitations, notifications, password resetsEmail address, name, notification content
UpstashRate limiting, to keep the API availableAccount ID or IP address, held briefly
Cloudflare TurnstileDistinguishing people from bots on sign-up and sign-inIP address and browser signals, handled by Cloudflare
VercelHosting and content deliveryStandard server request logs

We may also disclose data where the law requires it, or to protect the rights and safety of our users. If ReviewMySites is ever acquired or merged, data may transfer as part of that transaction; we will say so here before it takes effect.

6. How long we keep it

Comments and their attachments are kept for as long as the project exists. Deleting a project or closing your account removes the associated data from our live systems; backups age out on their own schedule shortly afterwards.

If a paid workspace lapses, it becomes read-only rather than disappearing, and its screenshots are retained for a further year before removal — long enough that recovering a lapsed account does not mean losing its history. Server logs are kept for a short period for security purposes.

7. Your rights

You can access and correct your account details from your profile settings, edit or delete your own comments, and choose which notification emails you receive. Every notification email also carries an unsubscribe link.

Depending on where you live, you may also have the right to a copy of your data, to have it corrected or erased, to restrict or object to how it is used, and to complain to your data protection authority. Write to privacy@reviewmysites.com and we will answer within 30 days. Where we are acting on a customer’s behalf, we will pass the request to them and help them fulfil it.

8. Cookies and local storage

We use cookies for one purpose: keeping you signed in. We also use your browser’s local storage to remember interface preferences, such as light or dark mode. There are no advertising or analytics cookies, so there is no consent banner to dismiss.

9. International transfers

Our providers operate in several countries, so your data may be processed outside the country you live in. Where data leaves the European Economic Area or the United Kingdom, our providers rely on Standard Contractual Clauses or an equivalent safeguard.

10. Children

ReviewMySites is a tool for professional teams and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us information, contact us and we will delete it.

11. Security

Data is encrypted in transit, access to each project is enforced at the database level by row-level security rather than only in application code, and comment authors’ email addresses are stripped from API responses. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority without undue delay.

12. Changes

When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will tell you by email or in the application before it takes effect.

13. Contact

Questions, requests, or anything else about privacy: privacy@reviewmysites.com