Privacy Policy
Last updated: 10 September 2026
The short version. ReviewMySites stores the account you create and the feedback you write — comments, the pages they were left on, and any screenshots you attach. We do not sell any of it, we do not run advertising or third-party analytics, and we do not track you across other websites. The RMS - Screenshots browser extension collects nothing at all: it takes a picture of the tab only when you attach a screenshot to a comment, hands that image to the ReviewMySites page that asked for it, and sends nothing anywhere itself.
1. Who this covers
This policy applies to the ReviewMySites website, the ReviewMySites web application, the embeddable review script that customers add to their own websites, and the RMS - Screenshots Chrome extension. Together these are “the Service”.
Where a customer installs ReviewMySites on their own website and invites their team or clients to leave feedback, that customer decides what is collected and why. In that arrangement they are the data controller and we act as their processor, handling the data on their instructions. If you were invited to review a site and have a question about that project’s data, the customer who owns it is the right first contact — though you are welcome to reach us at privacy@reviewmysites.com and we will help you find them.
2. What we collect
Account information
Your name, email address, and a profile image if you choose to add one. Your password is never stored in a readable form — authentication is handled by Supabase, which stores a cryptographic hash.
Feedback you write
The content of your comments and replies, and the context needed to put each comment back in the right place and make it useful to whoever reads it next:
- The URL of the page the comment was left on
- A description of the element it points at, and its position relative to that element
- The browser, operating system and viewport size in use when it was written — a bug report is usually worthless without them
- Status, priority, reactions, mentions, and the activity trail
- Any screenshot or file you attach
Screenshots
A screenshot is captured only when you attach one to a comment. It is a picture of the visible area of the tab at that moment, so it will contain whatever was on screen — including anything private that happened to be visible. Screenshots are stored in Cloudflare R2 and are visible to the people with access to that project.
Technical information
Our hosting provider keeps standard server logs, which include IP addresses and request details, for security and reliability. We use IP addresses to rate-limit anonymous requests. We do not run third-party analytics, advertising, or cross-site tracking of any kind.
3. The RMS - Screenshots extension
The extension exists for one narrow reason. Attaching a screenshot in a browser normally means Chrome’s “share your screen” prompt, which is tied to the page you granted it on, dies when you follow a link, and leaves a sharing indicator on screen while it lasts. The extension takes the picture from the tab instead.
The extension collects, stores and transmits no data of its own. It has no servers, no account, and no analytics. Specifically:
- It captures the visible tab only when a ReviewMySites overlay on that page asks it to, which happens only when you attach a screenshot to a comment. There is no capture button and no background activity.
- The resulting image is handed to the ReviewMySites page that requested it. The extension itself sends it nowhere. What happens to it next is covered by the rest of this policy.
- It does not read, modify, or transmit the content of any page, and it never captures a tab other than the one you are looking at.
- It records nothing of any kind, and captures no video or audio.
Permissions. The extension requests access to all sites (<all_urls>) because Chrome’s tabs.captureVisibleTab API is available only to extensions holding broad host access — it cannot be scoped to a single site. That access is declared as optional: it is not granted when you install the extension, and it is requested from the extension’s own setup screen, which explains what it is for before Chrome’s dialog appears. The same switch revokes it, as does removing it from chrome://extensions. The extension re-checks the grant before every single capture rather than remembering it, so revoking takes effect immediately.
4. Why we use it
- To provide the Service — showing comments to the people they were written for
- To send transactional email you have asked for: invitations, mentions, status changes, password resets
- To keep the Service secure and available, including rate limiting and bot protection
- To respond to you when you contact us
We do not sell personal data, and we do not use it to train machine learning models.
5. Who it is shared with
Within the Service, your comments are visible to the people with access to the project they belong to — the workspace members, and anyone holding a share link that the project owner has created. Outside the Service, we share data only with the providers that run it:
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database and authentication — accounts, workspaces, projects, comments | Account details, comment content and context |
| Cloudflare R2 | Object storage for screenshots and thumbnails | Screenshot images |
| Resend | Transactional email — invitations, notifications, password resets | Email address, name, notification content |
| Upstash | Rate limiting, to keep the API available | Account ID or IP address, held briefly |
| Cloudflare Turnstile | Distinguishing people from bots on sign-up and sign-in | IP address and browser signals, handled by Cloudflare |
| Vercel | Hosting and content delivery | Standard server request logs |
We may also disclose data where the law requires it, or to protect the rights and safety of our users. If ReviewMySites is ever acquired or merged, data may transfer as part of that transaction; we will say so here before it takes effect.
6. How long we keep it
Comments and their attachments are kept for as long as the project exists. Deleting a project or closing your account removes the associated data from our live systems; backups age out on their own schedule shortly afterwards.
If a paid workspace lapses, it becomes read-only rather than disappearing, and its screenshots are retained for a further year before removal — long enough that recovering a lapsed account does not mean losing its history. Server logs are kept for a short period for security purposes.
7. Your rights
You can access and correct your account details from your profile settings, edit or delete your own comments, and choose which notification emails you receive. Every notification email also carries an unsubscribe link.
Depending on where you live, you may also have the right to a copy of your data, to have it corrected or erased, to restrict or object to how it is used, and to complain to your data protection authority. Write to privacy@reviewmysites.com and we will answer within 30 days. Where we are acting on a customer’s behalf, we will pass the request to them and help them fulfil it.
8. Cookies and local storage
We use cookies for one purpose: keeping you signed in. We also use your browser’s local storage to remember interface preferences, such as light or dark mode. There are no advertising or analytics cookies, so there is no consent banner to dismiss.
9. International transfers
Our providers operate in several countries, so your data may be processed outside the country you live in. Where data leaves the European Economic Area or the United Kingdom, our providers rely on Standard Contractual Clauses or an equivalent safeguard.
10. Children
ReviewMySites is a tool for professional teams and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us information, contact us and we will delete it.
11. Security
Data is encrypted in transit, access to each project is enforced at the database level by row-level security rather than only in application code, and comment authors’ email addresses are stripped from API responses. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority without undue delay.
12. Changes
When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will tell you by email or in the application before it takes effect.
13. Contact
Questions, requests, or anything else about privacy: privacy@reviewmysites.com