LEGAL

Privacy Policy

Effective October 4, 2026 · Last updated October 4, 2026

This policy explains what the critter Chrome extension, the critter.design website and the services behind them collect, why we collect it, who else handles it, how long we keep it, and the choices you have. This policy describes critter 0.6 and later.

In short

1. Who we are and how to contact us

critter (“critter”, “we”, “us”) is the product offered at critter.design. This policy covers:

It does not cover the websites you visit or comment on, or the services of Google, GitHub, X, Anthropic and other providers. Their own privacy policies apply to them.

For any privacy question or request, including requests about data we received from Google, GitHub or X and requests to remove a public comment, write to hello@critloop.ai.

2. What the extension keeps on your device

The extension stores the following in Chrome’s extension storage, the extension’s local storage and IndexedDB on your computer. We don’t receive it unless a later section says so.

To remove this data, sign out and then remove the extension or clear its data in Chrome. The extension does not yet have a single “delete everything” control.

What the extension reads from web pages

Requests to other servers

3. Comments you post

You can comment on any public web page without an account. When you post a public comment, our comment service stores:

Images. Where image attachments are available, you can attach a screenshot or image to a public comment. We store the image with any annotations drawn into it, a thumbnail, its title (and, for an image you imported, its file name), when it was captured, where on the page it was taken, its size, and its page address. Images show whatever was on your screen, and nothing in them is blurred or removed, so check them before posting.

Who can see public comments. Anyone who opens the same page address with critter can read its comments, images and any GitHub handles shown. Please don’t post personal information about yourself or others.

Loading comments. While the Comments or Chat view is open, the side panel sends the cleaned address of the current page, together with your random browser ID, to our comment service to load that page’s comments, and repeats this every minute for the Feed badge. The address includes the page’s path and any query parameters we don’t recognise as tracking or secret, such as search terms or IDs. Parameters are matched by name, so a secret in the path or under an unusual name may still be sent. Close the Comments and Chat views, or the side panel, on pages whose address you don’t want looked up. Looking up comments writes nothing to our comment database. Google Cloud’s standard request logs record the time, your IP address and browser type for each request, without the page address, and keep them for about 30 days (see section 11). Addresses of local and intranet pages (localhost, private IP ranges and intranet host names) are never sent: comments on those pages stay in your browser.

Abuse limits. To stop spam, we count posts and image uploads per browser and per network. For the network count we store a keyed hash of your IP address. The key changes every day, but past keys are kept in the same database, so these records are pseudonymous rather than anonymous. Nothing deletes them automatically yet: they stay until we remove them. Our comment database never stores your raw IP address, and these records are not shown with your comments.

Deleting comments. You can delete a comment from the browser that posted it, or while signed in to the same account if it shows your GitHub handle. Deleting a comment also deletes its replies. If you remove the extension or clear its data, your browser can no longer delete its earlier anonymous comments: write to us and we will help. Anyone can ask us to remove a comment that is about them. We may also remove comments that are unlawful or abusive.

Comments inside a company are covered in section 5.

4. Your account

An account is optional. You need one to join a company, use repository features or show your GitHub handle on comments.

Sign-in methods. You can sign in with Google, GitHub, X, or an email address and password. Sign-in is handled by Firebase Authentication, a Google service. Google, GitHub and X sign-in run through critter’s sign-in page on Firebase Hosting, which keeps no session of its own.

What Firebase Authentication stores: your email address, your password in hashed form (for email sign-in), the sign-in methods you have linked with each provider’s account ID, your name and profile photo address, and when the account was created and last used. Firebase sends verification and password-reset emails for us, and keeps its own security logs, including IP addresses, under Google’s terms.

Your password goes from the side panel straight to Firebase Authentication. critter never stores it.

Our account record. When you sign in from the extension, our server copies these details from Firebase into a record of your account: account ID, email and whether it is verified, name, photo address, linked sign-in methods and each provider’s account ID, your last sign-in method, and creation, last sign-in and update times. We use it to know who uses critter, to support you and to keep the service secure. Only our server can read or write it; other users can’t see it. It is refreshed when you sign in, and at most every 6 hours while you stay signed in.

Provider tokens. During sign-in, the token from Google, GitHub or X is passed to Firebase Authentication to verify your account. critter then discards the Google and X tokens and keeps only the GitHub token, in your browser (see section 2). If your email already has an account with another sign-in method, the new sign-in is held in memory for up to 10 minutes so you can link the two.

What we get from each sign-in provider

Shared infrastructure. critter’s Firebase and Google Cloud project, including its sign-in accounts, is also used by another app, Township. People who administer that project can access the data stored in it. Google’s, GitHub’s and X’s sign-in screens may show the name “township” or the address township-9ec0d.firebaseapp.com, because critter’s sign-in runs in that shared project. You are still signing in to critter, and this policy applies to the data critter receives.

Google user data

If you sign in with Google, we receive your Google account ID, email address and whether it is verified, name and profile photo address. We use them only to create and identify your critter account, to show who is signed in, and to link your sign-in methods. They are stored in Firebase Authentication, in our account record, and in your browser’s remembered account. If you join a company, your name (and your photo on company comments) is shown to its members, and your email is stored with your membership. If you invite a teammate, your name appears in the invite email, sent through Resend. We don’t share them with anyone else except Google, which runs Firebase for us. We don’t keep your Google access token, send Google data to AI model providers, use it to train AI models, or use it for advertising.

5. Companies, repositories and the Mac helper

These features are optional and are for teams who review web projects together.

The Feed (a shared repository wall) appears in the extension but isn’t switched on yet, and shared screenshots for company comments aren’t available: their online services are not running. We will update this policy before they launch.

The Mac helper. The optional helper is installed by a script that downloads Node.js from nodejs.org and the helper from critter.design into ~/.critloop on your Mac. It talks only to the extension in your browser. It opens and clones projects, runs your package manager and development server, applies edits you approve, and keeps undo records with before-and-after file contents on your Mac. It uses git with your own credentials to fetch from and push to GitHub. It sends nothing to critter’s servers and has no telemetry.

6. AI features

With your own Anthropic API key. When you send an Edit or Review request in Chat, the extension sends it straight from your browser to Anthropic. A request can include your message, the notes and elements you selected (including their visible text and page addresses), up to five screenshots, the conversation so far, a summary of the connected repository (its routes, file and component names, and sample source code), and the repository files the assistant reads. Refreshing the model list sends only your key. These requests don’t pass through our servers and we don’t store them. Anthropic handles them under your agreement with Anthropic and its privacy policy.

Managed AI (not yet available). We are building an optional AI service that would work without your own key, run requests through our servers and AI providers such as Anthropic, OpenAI and TypeSafe, and offer paid credits through Stripe. It is not part of the current release. Before it launches, we will update this policy and ask for your agreement in the extension. No payment information is collected today.

AI output can be wrong. Review proposed changes before you use them.

7. The website

8. How we use information

We use information only to provide and improve critter’s single purpose, commenting on web pages and turning that feedback into code changes, and the features described above. That includes keeping the service working, secure and reliable.

Purposes and legal bases (for people in the EEA and UK)
PurposeLegal basis
Running comments, accounts, companies, invites and repository features you ask forPerforming our agreement with you
Showing your GitHub handle on a commentYour consent, which you can withdraw in Settings
Signup and confirmation emailTaking the steps you ask for before using critter
Sending an invite a teammate requestedLegitimate interests: letting teams invite their members
Rate limits, abuse prevention and securityLegitimate interests: protecting users and the service
Keeping an account record of who signs inLegitimate interests: supporting users and securing accounts
Bot checks with reCAPTCHA Enterprise on the Get started pageLegitimate interests: keeping fake companies and automated abuse out
Cookieless website analyticsLegitimate interests: understanding overall site traffic
Running critter in a Firebase project shared with the Township appLegitimate interests: operating shared infrastructure
Answering your messages and privacy requestsLegitimate interests: supporting users; legal obligation for rights requests
Answering legal requests and keeping required recordsLegal obligation

Providing personal data. No law requires you to give us personal data. You can use public comments without an account. An email address (or a Google, GitHub or X account) is needed to create an account, and an account is needed to join a company or show your GitHub handle. An email address is needed to sign up for downloads. If you don’t provide these, only those features are unavailable.

We do not:

critter makes no automated decisions that have legal or similarly significant effects on you. Rate limits are automatic, and AI replies are suggestions for you to review.

9. Who we share it with

We share data only as needed to run critter, to comply with the law, to protect against malware, spam, phishing, fraud or abuse, or, with your explicit prior consent, as part of a merger, acquisition or sale of assets.

Service providers
ProviderWhat it does for critter
Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and Cloud Scheduler, Firebase Hosting, Cloud Logging)Sign-in, account and comment storage, comment images, our online services and scheduled clean-up, the sign-in page and service logs
Google reCAPTCHA EnterpriseBot checks on the company setup page
VercelWebsite hosting, signup and invite services, request logs and cookieless analytics
ResendSignup contacts, confirmation emails and invite emails
GitHubSign-in, the repository features you use, confirming your handle for named comments (our server sends GitHub your GitHub account ID), and a static copy of the website on GitHub Pages
Google and XSign-in, if you choose them
AnthropicAI requests you send with your own key
nodejs.orgNode.js download for the Mac helper install script

Others who may see your data: anyone with critter, for public comments, images and handles you choose to show; members of your company; collaborators on GitHub repositories you write to; administrators of the shared Firebase project, which also runs the Township app (see section 4); and authorities, when the law requires it.

The websites you comment on, and Google, GitHub, X, Anthropic and the other services above, handle data under their own privacy policies. We are not responsible for their practices.

10. Where data is processed

critter’s online services run in the United States: our databases are stored in Google Cloud’s United States multi-region (nam5), and our functions run in Google Cloud’s us-central1 region. Our other providers may process data in the United States and other countries. When we transfer personal data from the EEA, the UK or Switzerland, we rely on the safeguards our providers offer, such as the EU–US Data Privacy Framework and its UK and Swiss extensions, or the European Commission’s Standard Contractual Clauses (with the UK Addendum for UK data). Write to us for details.

11. How long we keep data

Our databases have no backups or point-in-time recovery switched on. Google keeps earlier versions of changed or deleted records for up to one hour for recovery, after which they are gone. Deleted images may stay in Google Cloud Storage’s recovery storage for a short time (7 days by default), and copies in our providers’ logs and systems follow their own retention.

12. Your choices and rights

Things you can do yourself

Requests to us

Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, restrict how we use it, and withdraw consent at any time (this does not affect what we did before). To make a request, email hello@critloop.ai. Requests are free. We may ask you to confirm you control the account or email address involved. We reply within one month, or within 45 days for California requests, and tell you if we need more time. For California requests to know, delete or correct, we confirm receipt within 10 business days. Because critter operates only online and you have a direct relationship with us, email is the way to make a request. You can use an authorised agent; we may ask for proof that the agent acts for you. We delete or update data we received from X or GitHub promptly when you ask.

Your right to object. Where we rely on legitimate interests, you can object to that use of your data at any time, and we will stop unless we have compelling grounds to continue. You can always object to direct marketing, and we will stop.

Complaints. Please tell us first, so we can try to put it right: we acknowledge complaints within 30 days and look into them without undue delay. You can also complain to a data protection authority. In the EU, that is the authority where you live or work, or where the issue happened (see the list of EU authorities). In the UK, it is the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). In Switzerland, it is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).

California and other US states

In the past 12 months we have collected these categories of personal information, from you, your browser, your sign-in provider and your teammates, for the purposes in this policy: identifiers (such as email address, account IDs, IP address in our providers’ logs, and hashed browser and network IDs); customer records (such as your name); professional information (the company you join, your membership and who invited you); internet activity (addresses of pages you comment on or look up comments for, and site usage including approximate country); visual content (screenshots you choose to post); and account login details (your email and password, which go only to Firebase Authentication and are used only to sign you in and secure your account). We draw no inferences about you. Retention is described in section 11.

In the past 12 months we disclosed these categories for business purposes to the service providers in section 9: Google, Vercel and Resend for identifiers, customer records, professional information and internet activity; Google for visual content and account login details. We also disclosed public comments, images and handles you chose to show to other critter users, and company data to members of your company.

We do not sell or “share” personal information for cross-context behavioural advertising, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing information about anyone under 16. Because we don’t sell or share data or use sensitive data beyond what is permitted, we don’t need “Do Not Sell or Share” or “Limit the Use” links. You have the right to know, delete and correct your data, and we won’t treat you differently for using your rights. Residents of other US states with privacy laws have similar rights; if we decline your request, you can appeal by replying to our decision, and we will answer within the time your state’s law sets.

Do Not Track and Global Privacy Control. critter does no cross-site tracking, and no third party collects information about your activity across other websites through critter, so these signals don’t change anything we do.

13. Children

critter is not directed to children. You must be at least 13 to use critter, or 16 if you live in the European Economic Area. Google, GitHub and X set their own minimum ages for their accounts. We don’t knowingly collect personal information from children under these ages. If you believe a child has given us personal information, write to us and we will delete it.

14. Security

All data critter sends travels over encrypted connections (HTTPS/TLS), and Google Cloud encrypts stored data. Browsers never read or write our databases directly: every request goes through our server code, which checks it first. critter never stores passwords and keeps GitHub tokens in session storage. Our databases store network addresses and browser IDs only as hashes; raw IP addresses appear only in our providers’ short-lived request logs (see section 11). Access to our systems is limited to the people who run critter and the administrators of the shared Firebase project (see section 4). No system is perfectly secure; if a breach affects your data, we will notify you where the law requires.

15. Chrome Web Store and Google API Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. critter’s use of information collected through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

critter’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

16. Changes to this policy

When we change this policy, we update the date at the top. For significant changes, we will also tell you in the extension or on this site before they take effect. Before using your data in a new way, we will update the notice in the extension and ask for your agreement where needed. We review this policy at least once a year.

Questions? Write to hello@critloop.ai.