LEGAL
Privacy Policy
Effective October 4, 2026 · Last updated October 4, 2026
This policy explains what the critter Chrome extension, the critter.design website and the services behind them collect, why we collect it, who else handles it, how long we keep it, and the choices you have. This policy describes critter 0.6 and later.
In short
- Most of what critter does stays in your browser: settings, drafts, screenshots, saved work and any API key you add.
- Public page comments carry no name or email unless you choose to show your GitHub handle. Anyone who opens the same page with critter can read them. Comments on local and intranet pages never leave your browser.
- While the Comments or Chat view is open, critter sends the address of the page you are on, with tracking and secret-looking query parameters removed, to load that page’s comments. Our database keeps no record of which pages you look up. Google Cloud, which runs our services, keeps standard request logs (time, IP address and browser type, but not the page address) for about 30 days.
- Signing in is optional. If you sign in, your account is held by Firebase Authentication, a Google service, and we keep a basic record of it. critter never stores your password.
- Your Anthropic API key stays in your browser and is sent only to Anthropic. Your GitHub token is kept in your browser and used with GitHub; during sign-in it is also passed to Firebase Authentication (Google) to verify your account.
- The extension has no analytics, ads or trackers. The website uses cookieless Vercel Web Analytics and one first-party cookie that remembers your signup for downloads. The Get started page also loads Google reCAPTCHA Enterprise and Firebase sign-in, which may set Google cookies and local storage.
- We don’t sell your data or use it for advertising. Write to hello@critloop.ai to see, correct or delete it.
1. Who we are and how to contact us
critter (“critter”, “we”, “us”) is the product offered at critter.design. This policy covers:
- the critter Chrome extension, including its side panel, its on-page tools and its sign-in window;
- the critter.design website (also reachable at critloop.ai), including early-access signup, account and company setup, teammate invites, downloads and the helper install script;
- critter’s hosted pages on Firebase Hosting, such as the sign-in page;
- critter’s online services: public page comments, accounts and companies; and
- the optional critter helper for macOS.
It does not cover the websites you visit or comment on, or the services of Google, GitHub, X, Anthropic and other providers. Their own privacy policies apply to them.
For any privacy question or request, including requests about data we received from Google, GitHub or X and requests to remove a public comment, write to hello@critloop.ai.
2. What the extension keeps on your device
The extension stores the following in Chrome’s extension storage, the extension’s local storage and IndexedDB on your computer. We don’t receive it unless a later section says so.
- Settings: theme, screenshot name prefix, which tools are shown, and whether to show your GitHub handle on public comments (off by default).
- Your sign-in session: the Firebase session that keeps you signed in, until you sign out.
- Your remembered account: sign-in method, name, email, account ID and photo address, used to offer a quick “continue as” option on the sign-in screen. It holds no password or token. It stays after you sign out, until you remove the extension or clear its data.
- Your local profile: a name and picture you set in Settings. These are shown only in your browser and are never uploaded.
- Your GitHub token (if you sign in with GitHub or paste a token), kept in session storage. It is cleared when you sign out, switch accounts, close the browser, or when GitHub rejects it.
- Your Anthropic API key (if you add one) and your chosen model. The key is stored unencrypted in the extension’s local storage.
- Your work: screenshots, annotations, reference images, private conversations, drafts, notes and saved work. Unsaved draft screenshots are deleted the next time critter tidies its storage after 24 hours.
- Comments on local addresses: comments you write on localhost, private-network and intranet pages, with their images.
- Feed read state: which comments you have seen on which pages, for the unread badge. It is never sent anywhere.
- Company and repository details: your company token and company name if you join a company; the repository you connect, scan results and drafts; recent local projects with their folder paths; and a handle to a folder you pick. critter reads the folder’s git remote, branch and package manager, but does not copy its files.
- A random browser ID that lets your browser recognise and delete its own public comments (see Comments).
To remove this data, sign out and then remove the extension or clear its data in Chrome. The extension does not yet have a single “delete everything” control.
What the extension reads from web pages
- While the side panel is open, it reads the address and title of the active tab. The title is never sent anywhere. It does not read your browsing history, cookies or other tabs.
- Its page tools run only when you choose Point, Drag or Show pins. Point and Drag ask Chrome for access to all sites. On any site you have granted, critter shows a page’s comment pins by itself while the side panel is open. The tools read the element or area you select: tag, id, classes, position, up to 200 characters of its text, and, on React sites, component names.
- A screenshot is taken only when you capture a selection, and covers the visible area you select plus a small margin.
Requests to other servers
- Some screens load icons and pictures from other servers: website icons on the Projects home (for example from nike.com, nytimes.com, figma.com and linear.app), and profile pictures from Google, GitHub or X. Those servers see your IP address and browser type, as with any image on the web.
- The Firebase software that handles sign-in sends Google a small usage header (dates and software version) with sign-in requests.
- On critter.design and critloop.ai, the extension adds its version number to the page so the site can detect it and hand your company token to the side panel.
3. Comments you post
You can comment on any public web page without an account. When you post a public comment, our comment service stores:
- the comment text (up to 2,000 characters) and which comment it replies to;
- the page address, cleaned in your browser and again on our server: we keep the site, path and identifying query, and remove the part after “#”, any username or password in the address, tracking parameters (such as
utm_*,fbclidandgclid) and query parameters whose names look like secrets (such as tokens, keys, codes and session IDs). The path itself is kept as it is, so avoid commenting on pages whose address contains a private link or code; - where the comment sits on the page: the element’s tag, id, classes, CSS path and position, any area you drew, and the pin position, together with your window size and the page’s size when you placed it. We do not store the element’s text, page text or page title;
- when it was posted;
- a one-way hash of your random browser ID, so that only your browser can delete the comment; and
- if you turn on Show my GitHub handle and have linked GitHub: your GitHub handle and your critter account ID. The handle is shown with the comment; the account ID is not. Our server confirms your handle with GitHub using your GitHub account ID, and keeps a small record of your critter account ID, GitHub account ID and handle, and when it last checked, so it doesn’t have to ask GitHub each time. That record is refreshed at most every 30 days and kept until you ask us to delete your account.
Images. Where image attachments are available, you can attach a screenshot or image to a public comment. We store the image with any annotations drawn into it, a thumbnail, its title (and, for an image you imported, its file name), when it was captured, where on the page it was taken, its size, and its page address. Images show whatever was on your screen, and nothing in them is blurred or removed, so check them before posting.
Who can see public comments. Anyone who opens the same page address with critter can read its comments, images and any GitHub handles shown. Please don’t post personal information about yourself or others.
Loading comments. While the Comments or Chat view is open, the side panel sends the cleaned address of the current page, together with your random browser ID, to our comment service to load that page’s comments, and repeats this every minute for the Feed badge. The address includes the page’s path and any query parameters we don’t recognise as tracking or secret, such as search terms or IDs. Parameters are matched by name, so a secret in the path or under an unusual name may still be sent. Close the Comments and Chat views, or the side panel, on pages whose address you don’t want looked up. Looking up comments writes nothing to our comment database. Google Cloud’s standard request logs record the time, your IP address and browser type for each request, without the page address, and keep them for about 30 days (see section 11). Addresses of local and intranet pages (localhost, private IP ranges and intranet host names) are never sent: comments on those pages stay in your browser.
Abuse limits. To stop spam, we count posts and image uploads per browser and per network. For the network count we store a keyed hash of your IP address. The key changes every day, but past keys are kept in the same database, so these records are pseudonymous rather than anonymous. Nothing deletes them automatically yet: they stay until we remove them. Our comment database never stores your raw IP address, and these records are not shown with your comments.
Deleting comments. You can delete a comment from the browser that posted it, or while signed in to the same account if it shows your GitHub handle. Deleting a comment also deletes its replies. If you remove the extension or clear its data, your browser can no longer delete its earlier anonymous comments: write to us and we will help. Anyone can ask us to remove a comment that is about them. We may also remove comments that are unlawful or abusive.
Comments inside a company are covered in section 5.
4. Your account
An account is optional. You need one to join a company, use repository features or show your GitHub handle on comments.
Sign-in methods. You can sign in with Google, GitHub, X, or an email address and password. Sign-in is handled by Firebase Authentication, a Google service. Google, GitHub and X sign-in run through critter’s sign-in page on Firebase Hosting, which keeps no session of its own.
What Firebase Authentication stores: your email address, your password in hashed form (for email sign-in), the sign-in methods you have linked with each provider’s account ID, your name and profile photo address, and when the account was created and last used. Firebase sends verification and password-reset emails for us, and keeps its own security logs, including IP addresses, under Google’s terms.
Your password goes from the side panel straight to Firebase Authentication. critter never stores it.
Our account record. When you sign in from the extension, our server copies these details from Firebase into a record of your account: account ID, email and whether it is verified, name, photo address, linked sign-in methods and each provider’s account ID, your last sign-in method, and creation, last sign-in and update times. We use it to know who uses critter, to support you and to keep the service secure. Only our server can read or write it; other users can’t see it. It is refreshed when you sign in, and at most every 6 hours while you stay signed in.
Provider tokens. During sign-in, the token from Google, GitHub or X is passed to Firebase Authentication to verify your account. critter then discards the Google and X tokens and keeps only the GitHub token, in your browser (see section 2). If your email already has an account with another sign-in method, the new sign-in is held in memory for up to 10 minutes so you can link the two.
What we get from each sign-in provider
- Google: your Google account ID, email address and whether it is verified, name and profile photo. critter asks only for basic sign-in access and uses no other Google APIs. See Google user data below.
- GitHub: your GitHub account ID, username, name, email and profile photo. Sign-in from the extension also asks GitHub for repository access: either the “repo” permission, which gives full read and write access to all public and private repositories your GitHub account can access (including organisation repositories), or, for the critter GitHub App, only the repositories you select. critter binds the token to the one repository you connect and uses it only from your browser. You can revoke it at any time in GitHub under Settings → Applications.
- X: your X account ID, name and profile photo, and your email address if X provides it. critter uses this only to sign you in and match your account. It never posts to X, reads your timeline, or sends X anything beyond the sign-in request. We don’t use the email address we receive from X for marketing. If you ask us, or X asks us, we promptly delete or update the X data we hold.
Shared infrastructure. critter’s Firebase and Google Cloud project, including its sign-in accounts, is also used by another app, Township. People who administer that project can access the data stored in it. Google’s, GitHub’s and X’s sign-in screens may show the name “township” or the address township-9ec0d.firebaseapp.com, because critter’s sign-in runs in that shared project. You are still signing in to critter, and this policy applies to the data critter receives.
Google user data
If you sign in with Google, we receive your Google account ID, email address and whether it is verified, name and profile photo address. We use them only to create and identify your critter account, to show who is signed in, and to link your sign-in methods. They are stored in Firebase Authentication, in our account record, and in your browser’s remembered account. If you join a company, your name (and your photo on company comments) is shown to its members, and your email is stored with your membership. If you invite a teammate, your name appears in the invite email, sent through Resend. We don’t share them with anyone else except Google, which runs Firebase for us. We don’t keep your Google access token, send Google data to AI model providers, use it to train AI models, or use it for advertising.
5. Companies, repositories and the Mac helper
These features are optional and are for teams who review web projects together.
- Company: its name, owner, plan, seat limit, members and company token. Anyone with the token can see the company’s name.
- Membership: your account ID, a display name (your sign-in name or the part of your email before “@”), your email, when you joined and when you were last active (a seat counts as active if used in the last 30 days), and recent activity counts used for rate limits. Other members see your display name and these dates, but not your email.
- Invites: when a member invites you, we store your email address, the company and who invited you, and send you an email through Resend with the company name, the inviter’s name, the company token and setup steps. If you received an invite, we got your email address from that teammate.
- Company comments: the text, page route, element details (which can include the element’s visible text), repository name, commit and branch, status, and the author’s name and photo. All members of the company can see them. They stay until the author or the company owner deletes them, including after the author leaves.
- Repository work: using your GitHub token from your browser, the extension reads the repository you connect, lists pull requests, and creates draft branches, commits, pull requests and issues, and uploads images to GitHub when you ask it to. That content lives on GitHub under GitHub’s terms and is visible to people with access to the repository. Apart from the Firebase Authentication sign-in exchange, our servers never receive your GitHub token, and downloaded source code is kept only in memory.
The Feed (a shared repository wall) appears in the extension but isn’t switched on yet, and shared screenshots for company comments aren’t available: their online services are not running. We will update this policy before they launch.
The Mac helper. The optional helper is installed by a script that downloads Node.js from nodejs.org and the helper from critter.design into ~/.critloop on your Mac. It talks only to the extension in your browser. It opens and clones projects, runs your package manager and development server, applies edits you approve, and keeps undo records with before-and-after file contents on your Mac. It uses git with your own credentials to fetch from and push to GitHub. It sends nothing to critter’s servers and has no telemetry.
6. AI features
With your own Anthropic API key. When you send an Edit or Review request in Chat, the extension sends it straight from your browser to Anthropic. A request can include your message, the notes and elements you selected (including their visible text and page addresses), up to five screenshots, the conversation so far, a summary of the connected repository (its routes, file and component names, and sample source code), and the repository files the assistant reads. Refreshing the model list sends only your key. These requests don’t pass through our servers and we don’t store them. Anthropic handles them under your agreement with Anthropic and its privacy policy.
Managed AI (not yet available). We are building an optional AI service that would work without your own key, run requests through our servers and AI providers such as Anthropic, OpenAI and TypeSafe, and offer paid credits through Stripe. It is not part of the current release. Before it launches, we will update this policy and ask for your agreement in the extension. No payment information is collected today.
AI output can be wrong. Review proposed changes before you use them.
7. The website
- Signup email: when you sign up for early access, we save your email address as a contact with Resend, our email provider, and may send you a confirmation email. Signing up unlocks the downloads. We use your signup email only to confirm your signup and to send messages about your access to critter. We don’t send marketing emails. We don’t verify the address, so if you get an email you didn’t sign up for, write to us and we’ll remove it.
- Download cookie: after signup, we set one first-party cookie,
critloop_download_access, that lets you download critter and see the install instructions. It contains an expiry time, a random value and a signature. It does not contain your email or any ID linked to you. It lasts 30 days, page scripts can’t read it, and signing out on the site removes it. It is strictly necessary for downloads. - Analytics: our main pages use Vercel Web Analytics to count visits. It records the page viewed (which can include its query string), the referring page, and the browser, operating system, device type and country derived from your request. It sets no cookies and doesn’t identify you across days. We look only at totals.
- Server logs: Vercel, which hosts the site, keeps request logs (such as IP address, browser, page and status) for its standard period. Our own code doesn’t log email addresses or tokens. To limit abuse, the signup and invite services keep your IP address, and for invites your account ID, in server memory to count recent requests. The counts reset after a minute (a day for invites per account) and are discarded when the server instance restarts. They are never written to disk.
- Theme: your appearance choice is saved in your browser’s local storage and never sent anywhere.
- Account and company setup: the Get started page offers GitHub sign-in through Firebase Authentication, without repository permissions. Your session is kept in your browser until you sign out. If you check a private repository, a GitHub App token is kept only in page memory, and a GitHub token you paste is sent only to GitHub and discarded after two requests. This page loads Google reCAPTCHA Enterprise when it opens, through Firebase App Check, to confirm requests come from a real browser; Google receives browser and device signals and may set cookies for this under its own terms. Firebase sign-in on this page also keeps its own data in your browser.
- Email to us: if you write to us, we keep the message and your address to answer you.
8. How we use information
We use information only to provide and improve critter’s single purpose, commenting on web pages and turning that feedback into code changes, and the features described above. That includes keeping the service working, secure and reliable.
| Purpose | Legal basis |
|---|---|
| Running comments, accounts, companies, invites and repository features you ask for | Performing our agreement with you |
| Showing your GitHub handle on a comment | Your consent, which you can withdraw in Settings |
| Signup and confirmation email | Taking the steps you ask for before using critter |
| Sending an invite a teammate requested | Legitimate interests: letting teams invite their members |
| Rate limits, abuse prevention and security | Legitimate interests: protecting users and the service |
| Keeping an account record of who signs in | Legitimate interests: supporting users and securing accounts |
| Bot checks with reCAPTCHA Enterprise on the Get started page | Legitimate interests: keeping fake companies and automated abuse out |
| Cookieless website analytics | Legitimate interests: understanding overall site traffic |
| Running critter in a Firebase project shared with the Township app | Legitimate interests: operating shared infrastructure |
| Answering your messages and privacy requests | Legitimate interests: supporting users; legal obligation for rights requests |
| Answering legal requests and keeping required records | Legal obligation |
Providing personal data. No law requires you to give us personal data. You can use public comments without an account. An email address (or a Google, GitHub or X account) is needed to create an account, and an account is needed to join a company or show your GitHub handle. An email address is needed to sign up for downloads. If you don’t provide these, only those features are unavailable.
We do not:
- sell your data;
- use or transfer it for personalised, retargeted or interest-based advertising;
- transfer or sell it to advertising platforms, data brokers or other information resellers;
- use or transfer it to decide creditworthiness or for lending; or
- let people read your data, unless you agree, it is needed for security (such as investigating abuse), the law requires it, or it is aggregated and anonymised for internal operations.
critter makes no automated decisions that have legal or similarly significant effects on you. Rate limits are automatic, and AI replies are suggestions for you to review.
9. Who we share it with
We share data only as needed to run critter, to comply with the law, to protect against malware, spam, phishing, fraud or abuse, or, with your explicit prior consent, as part of a merger, acquisition or sale of assets.
| Provider | What it does for critter |
|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and Cloud Scheduler, Firebase Hosting, Cloud Logging) | Sign-in, account and comment storage, comment images, our online services and scheduled clean-up, the sign-in page and service logs |
| Google reCAPTCHA Enterprise | Bot checks on the company setup page |
| Vercel | Website hosting, signup and invite services, request logs and cookieless analytics |
| Resend | Signup contacts, confirmation emails and invite emails |
| GitHub | Sign-in, the repository features you use, confirming your handle for named comments (our server sends GitHub your GitHub account ID), and a static copy of the website on GitHub Pages |
| Google and X | Sign-in, if you choose them |
| Anthropic | AI requests you send with your own key |
| nodejs.org | Node.js download for the Mac helper install script |
Others who may see your data: anyone with critter, for public comments, images and handles you choose to show; members of your company; collaborators on GitHub repositories you write to; administrators of the shared Firebase project, which also runs the Township app (see section 4); and authorities, when the law requires it.
The websites you comment on, and Google, GitHub, X, Anthropic and the other services above, handle data under their own privacy policies. We are not responsible for their practices.
10. Where data is processed
critter’s online services run in the United States: our databases are stored in Google Cloud’s United States multi-region (nam5), and our functions run in Google Cloud’s us-central1 region. Our other providers may process data in the United States and other countries. When we transfer personal data from the EEA, the UK or Switzerland, we rely on the safeguards our providers offer, such as the EU–US Data Privacy Framework and its UK and Swiss extensions, or the European Commission’s Standard Contractual Clauses (with the UK Addendum for UK data). Write to us for details.
11. How long we keep data
- Data in your browser: until you delete it, remove the extension or clear its data. Draft screenshots that are never saved are deleted the next time critter tidies its storage after 24 hours.
- Public comments and their images: until the author deletes them, or until we remove them on request. A page’s address stays in our records after its comments are deleted. Images uploaded but never posted are removed about a day after upload.
- Rate-limit records and daily keys: the records count the last hour of activity and contain no raw IP address. They are pseudonymous, not anonymous, because the daily keys are kept (see section 3). Nothing deletes the records or the keys automatically yet, so they stay in our database until we remove them.
- Your account, account record and GitHub handle record: until you ask us to delete them. There is no in-app delete button yet; write to us and we will delete them. When we delete your account we also remove your memberships and the account link on your named comments.
- Company records: memberships until you leave or the owner removes you; company comments until the author or owner deletes them; companies and invites until you ask us to delete them.
- Signup contacts: until you ask us to remove you.
- Download cookie: 30 days, or until you sign out on the site.
- Logs and analytics: for the standard retention periods of Google Cloud (about 30 days for request logs), Firebase and Vercel.
Our databases have no backups or point-in-time recovery switched on. Google keeps earlier versions of changed or deleted records for up to one hour for recovery, after which they are gone. Deleted images may stay in Google Cloud Storage’s recovery storage for a short time (7 days by default), and copies in our providers’ logs and systems follow their own retention.
12. Your choices and rights
Things you can do yourself
- Use critter without an account, or sign out at any time.
- Turn Show my GitHub handle off in Settings, and delete comments you posted.
- Remove your Anthropic key, leave a company, or remove the extension to clear its data.
- Revoke critter’s access in your Google, GitHub or X account settings, and turn off site access for critter in Chrome’s extension settings.
Requests to us
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, restrict how we use it, and withdraw consent at any time (this does not affect what we did before). To make a request, email hello@critloop.ai. Requests are free. We may ask you to confirm you control the account or email address involved. We reply within one month, or within 45 days for California requests, and tell you if we need more time. For California requests to know, delete or correct, we confirm receipt within 10 business days. Because critter operates only online and you have a direct relationship with us, email is the way to make a request. You can use an authorised agent; we may ask for proof that the agent acts for you. We delete or update data we received from X or GitHub promptly when you ask.
Your right to object. Where we rely on legitimate interests, you can object to that use of your data at any time, and we will stop unless we have compelling grounds to continue. You can always object to direct marketing, and we will stop.
Complaints. Please tell us first, so we can try to put it right: we acknowledge complaints within 30 days and look into them without undue delay. You can also complain to a data protection authority. In the EU, that is the authority where you live or work, or where the issue happened (see the list of EU authorities). In the UK, it is the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). In Switzerland, it is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
California and other US states
In the past 12 months we have collected these categories of personal information, from you, your browser, your sign-in provider and your teammates, for the purposes in this policy: identifiers (such as email address, account IDs, IP address in our providers’ logs, and hashed browser and network IDs); customer records (such as your name); professional information (the company you join, your membership and who invited you); internet activity (addresses of pages you comment on or look up comments for, and site usage including approximate country); visual content (screenshots you choose to post); and account login details (your email and password, which go only to Firebase Authentication and are used only to sign you in and secure your account). We draw no inferences about you. Retention is described in section 11.
In the past 12 months we disclosed these categories for business purposes to the service providers in section 9: Google, Vercel and Resend for identifiers, customer records, professional information and internet activity; Google for visual content and account login details. We also disclosed public comments, images and handles you chose to show to other critter users, and company data to members of your company.
We do not sell or “share” personal information for cross-context behavioural advertising, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing information about anyone under 16. Because we don’t sell or share data or use sensitive data beyond what is permitted, we don’t need “Do Not Sell or Share” or “Limit the Use” links. You have the right to know, delete and correct your data, and we won’t treat you differently for using your rights. Residents of other US states with privacy laws have similar rights; if we decline your request, you can appeal by replying to our decision, and we will answer within the time your state’s law sets.
Do Not Track and Global Privacy Control. critter does no cross-site tracking, and no third party collects information about your activity across other websites through critter, so these signals don’t change anything we do.
13. Children
critter is not directed to children. You must be at least 13 to use critter, or 16 if you live in the European Economic Area. Google, GitHub and X set their own minimum ages for their accounts. We don’t knowingly collect personal information from children under these ages. If you believe a child has given us personal information, write to us and we will delete it.
14. Security
All data critter sends travels over encrypted connections (HTTPS/TLS), and Google Cloud encrypts stored data. Browsers never read or write our databases directly: every request goes through our server code, which checks it first. critter never stores passwords and keeps GitHub tokens in session storage. Our databases store network addresses and browser IDs only as hashes; raw IP addresses appear only in our providers’ short-lived request logs (see section 11). Access to our systems is limited to the people who run critter and the administrators of the shared Firebase project (see section 4). No system is perfectly secure; if a breach affects your data, we will notify you where the law requires.
15. Chrome Web Store and Google API Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. critter’s use of information collected through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
critter’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
16. Changes to this policy
When we change this policy, we update the date at the top. For significant changes, we will also tell you in the extension or on this site before they take effect. Before using your data in a new way, we will update the notice in the extension and ask for your agreement where needed. We review this policy at least once a year.
Questions? Write to hello@critloop.ai.