UX Lens Privacy Policy
UX Lens (the “Extension”) is a webpage UI/UX review tool that runs when you choose to start a review. This policy explains what data the Extension processes, why it processes that data, who may receive it, and how you can manage or delete it.
1. Scope
This policy applies to the UX Lens browser extension and the review reports it creates. It does not apply to third-party AI services you choose to connect or to the data practices of websites you review.
2. Data processed
2.1 Local rule reviews
When you start a review, the Extension may read page URLs, titles, excerpts of visible text, links, element selectors, basic document structure, element dimensions, colors, typography, layout, interaction states, and page attributes used for basic usability and accessibility checks.
This information is used to identify issues involving readability, click target sizes, navigation, trust signals, and basic accessibility, and to generate a review report. Local rule analysis runs in your browser. The developer does not receive this page data through a developer-operated server.
The Extension does not continuously monitor your browsing activity, read your complete browsing history, or intentionally read cookies, saved browser passwords, or values entered into password fields.
2.2 Same-site multi-page reviews
The Extension visits additional pages only when you choose the same-site multi-page option and confirm the pages to review. A review is limited to a maximum of five pages from the same site. The Extension does not automatically crawl an entire website.
To check whether identified page links are available, the Extension may send credential-free HTTP HEAD or GET requests to those links. Links that cannot be verified remain marked as unconfirmed in the report.
2.3 Optional AI reviews
AI review is disabled by default. Data is sent to an AI service only when you enable AI, select a provider, supply your own API key, and start or re-run a review. Data sent may include selected page URLs and titles, visible text excerpts, page structure and layout measurements, local rule findings, and prompts used to produce review recommendations.
Screenshot sharing is disabled by default. When you enable it, the Extension also sends a screenshot of the visible page area or an image you provide. Page text, URL query parameters, and screenshots may contain names, account details, order information, or other personal information. The Extension cannot guarantee that all sensitive information will be detected or removed automatically. Enable AI or screenshots only for pages you are authorized and willing to share with the selected service.
Supported AI services may include OpenAI, Anthropic, DeepSeek, Google Gemini, OpenRouter, Moonshot/Kimi, Qwen/DashScope, and an OpenAI-compatible custom endpoint that you configure. The selected recipient and request address are displayed in the Extension. Each third-party service processes, retains, and deletes data under its own privacy policy and your agreement with that service.
3. API keys
API keys you enter are stored by provider in chrome.storage.local and are not stored in browser sync storage. When an AI request is made, the applicable key is sent directly to the provider you selected for authentication.
The developer does not operate a relay server that receives AI requests or API keys. Browser local storage is not a separately encrypted password vault. Protect access to your device and browser profile, and use the Extension’s “Clear local data” control to remove saved keys when they are no longer needed.
4. Local storage and retention
The Extension may store interface and report language, scan scope, AI provider and model settings, API keys, active task progress, and the most recent report and related screenshot locally in your browser. Debug request or response logs may also be stored if you explicitly enable developer mode.
The Extension retains only the most recent report; a new report replaces the previous report. Temporary data needed for an active task is cleared after the task finishes. Exported HTML or JSON files are saved to your Downloads folder and remain under your control.
5. Data sharing and sale
Except for data sent to the service you select when you enable AI, the developer does not sell, rent, or disclose your page data, API keys, or review reports to third parties.
The Extension contains no advertising, behavioral analytics, or telemetry. It does not use data for advertising, credit assessment, or purposes unrelated to its webpage review functionality. Use of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
6. Permissions
- activeTab: Identifies the page you selected when you start a review;
- scripting: Runs review scripts on a selected page and locates issue elements when requested;
- downloads: Creates and downloads HTML or JSON review reports;
- storage: Stores settings, task status, API keys, and the most recent report locally;
- alarms: Maintains or resumes a longer review task that you already started;
- Host permission (
<all_urls>): Supports reviews of ordinary webpages you select and same-site pages you confirm.
Website access does not mean that the Extension automatically reads every website. Pages are processed only when you start a review or use the report’s page-location feature. Browser-internal and other protected pages may not be reviewable.
7. Your choices and controls
- Use local rule reviews without enabling AI;
- Keep screenshot sharing disabled;
- Choose the AI provider and model;
- Restrict or revoke website access in your browser’s extension settings, although doing so may prevent related features from working;
- Select “Clear local data” in the Extension to delete locally stored settings, API keys, reports, screenshots, and task progress;
- Uninstall the Extension to remove the browser’s local extension storage.
Reports already exported to your device must be deleted separately from your Downloads folder. To access or delete data already received by a third-party AI service, follow that provider’s procedures.
8. Data security
The Extension uses Chrome extension permissions and trusted extension contexts to limit access to locally stored data and minimizes the amount of data it retains. No local storage or network transmission method can guarantee absolute security. Do not save API keys on an untrusted device or enable AI or screenshots for sensitive pages you are not authorized to process.
9. Children’s privacy
The Extension is intended for people who independently perform website design, development, or operations work. It is not directed to children, and the developer does not knowingly collect children’s personal information.
10. Changes to this policy
If the Extension’s data practices change, this policy will be updated and the “Last updated” date above will be revised. Material new categories of data sharing will also be explained in the relevant Extension interface.
11. Contact
For questions about this policy or how UX Lens processes data, use the developer contact information shown on the Extension’s Chrome Web Store listing.