What Tintstep sends, and what it does not.

Tintstep reads computed style on the page after you click the icon, use the shortcut, or start a scan. Those values stay in the browser's extension storage for that session. A finished scan is cleared when the tab navigates or closes.

The extension does not include a network call for inspect or scan. Connecting a paid license is a separate request. That request sends a pairing code or a device credential. It does not send the page URL, the CSS, or the copied color.

The website stores your email, the state of your subscription, and support messages you write. Stripe handles payments. Bird sends mail. Vercel hosts the site. Supabase holds the database. Cloudflare is DNS. Datadog receives logs without your email and without page content. The role of each company is on Subprocessors.

Wren Foundry does not sell personal information, does not use it for advertising, and does not use it to determine creditworthiness. The extension's purpose is to inspect computed styles on a page you choose. Those styles stay on the device.

Account passwords are stored by Supabase Auth as a hash. Tintstep does not keep a copy of the password. Card numbers are entered on Stripe's page. They are not stored in the Tintstep database.

To report a security problem, write to security@wrenfoundry.com. You can also use the contact form.

Privacy policy