Plain-language summary
ReviewFlow does not watch your browsing in the background. It reads the active page only after you choose a capture action. A marked capture stays on your device unless you connect a ReviewFlow workspace and confirm a cloud upload.
- No advertising profiles
- No sale of user data
- No background browsing collection
- No human review of private captures unless you request support or it is required for security or law
Information we handle
When you deliberately capture and save feedback, ReviewFlow may handle:
- the active page URL and title;
- a screenshot of the visible page area and your annotations;
- the selected element's tag, short text excerpt, selector, and screen position;
- viewport size, capture time, and a coarse browser/device description;
- feedback titles, descriptions, scope type, priority, revision round, comments, and approval decisions;
- account email, display name, workspace membership, project information, and authentication session data;
- subscription plan, billing status, Paddle customer and transaction identifiers, and limited billing contact information.
Payment-card details are collected by Paddle during checkout. ReviewFlow does not receive or store your full payment-card number.
How we use it
We use this information only to provide ReviewFlow's single purpose: capturing user-selected website evidence, organizing the requested work, sharing it with the selected project team or invited client, and recording review decisions. We may also use limited operational data to secure the service, prevent abuse, diagnose failures, and maintain reliability.
Local and cloud storage
The extension keeps its project connection and up to 50 recent local recovery records in Chrome local storage. Local records remain on that browser profile until the extension data is cleared or the extension is removed.
Cloud uploads happen only after a workspace is connected and you confirm the first upload disclosure. Cloud records are associated with the selected workspace and use private storage. Guest review images are provided through short-lived signed links.
Service providers
ReviewFlow uses the following processors only where needed to operate the product:
- Supabase
- Authentication, database, and private file storage.
- Vercel
- Application hosting, server functions, and delivery.
- Resend
- Transactional sign-in email delivery.
- Paddle
- Checkout, payment processing, tax handling, subscription management, and buyer support as Merchant of Record.
We do not transfer user data to advertising platforms, data brokers, or information resellers.
Security and retention
User data is transmitted over HTTPS. Access is limited by workspace membership, server-side authorization, private storage policies, expiring guest links, and signed media URLs. We retain cloud information while it is needed to provide the workspace and for limited backup, security, or legal obligations.
Your choices
You can keep captures local by not connecting a cloud workspace. You can clear extension data through Chrome, revoke a guest review link from the workspace where available, or request access, correction, export, or deletion through our support page. Include the email used for your ReviewFlow workspace so the request can be verified.
Chrome Web Store Limited Use
ReviewFlow's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use Chrome-provided data only to provide or improve the user-facing capture and feedback workflow described above.
Changes
If our data practices materially change, we will update this page and present any newly required disclosure or consent inside the product before the new practice begins.
For purchase and cancellation rules, see our Terms of service and Refund policy.