Legal
Privacy policy
Effective
The short version: we collect what the product needs to pin a comment to a page and show it to your team, we send it only to the services you connect, and we do not sell it or advertise with it. The long version follows.
1.Who we are
Corsight (“we”, “us”) provides a browser extension and web application that lets teams pin comments to elements on live websites and sync those threads with Linear and Slack, together with this website at corsight.app (the “Service”).
We are the controller of the personal data described in this policy. You can reach us about anything in it at hello@corsight.app. A person reads that inbox.
2.What this policy covers
This policy covers the Corsight website, the Corsight browser extension, and the accounts and workspaces behind them. It does not cover the websites you comment on with the extension, or the third-party services you choose to connect (Linear, Slack) — those have their own policies, linked in section 7.
3.Information we collect
Information you give us.
- Waitlist: if you join the waitlist, we store your email address, which form on the page you used, and when you signed up. Nothing else.
- Account: when you create an account, we store your email address and, if you provide them, a display name, an avatar, a job title and a timezone, along with preferences such as theme and whether notifications are on.
- Content: the comments and replies you write, and the projects and organizations you create or join. Each comment also records where it lives: the URL and title of the page it was placed on, and a description of the element it is pinned to (its position and how to find it again). This is the product — a comment without its place on the page is not one.
Information collected automatically.
- Timestamps on the things you do — when a comment was written, when a profile was last edited, when the panel was last opened.
- Standard server logs when your browser or the extension calls our servers: IP address, user agent, and the request made. We use these to operate and secure the Service, not to profile you.
Information from services you connect. If you connect Linear or Slack, we receive and store the credentials those services grant us (see section 7), identifiers for the workspaces, teams and channels you choose, and the replies written there on threads that Corsight syncs.
4.What we do not collect
The extension can draw its overlay on any page you open — that is what it is for — but the overlay is drawn locally, in your browser. The extension does not record your browsing history, does not capture pages you merely visit, and sends nothing to our servers until you place a comment.
When you place one, what leaves your browser is the comment and its anchor — the page URL, the page title, and the description of the element it is pinned to — and, depending on your team’s screenshot setting, a picture of the page. See section 5. We never capture the page itself: no HTML, no page source, and nothing from a page you did not comment on.
We do not sell personal data, and we do not show ads.
5.Screenshots
A comment can keep a picture of the page it was left on, so that whoever reads it later can see what was being talked about. How much of the page that picture contains is your team’s decision, set by an owner or admin in Settings, and a project can be set differently from the rest of the team. There are two choices:
- Full screenshot — a picture of the visible page, as it looked when the comment was made. This is the default. Only the visible part of the page is ever captured, and only at the moment a comment is written.
- Layout only — a wireframe: the position and size of the boxes, buttons and fields on screen, and placeholder words wherever a line of text was. Those words are ours, not yours — the same Latin every mockup uses. Your text is never read, so nothing it says can reach the picture, and no image, video or embedded frame is looked at either. This is not a screenshot with the words hidden — nothing is photographed at all, so there is no picture of your page for the words to be hidden in.
There is no third choice that switches capture off, because the layout mode is already the off switch for page content: it photographs nothing, so there is nothing of your page to withhold.
Pictures are stored in Cloudflare R2, in a private bucket that is not readable from the internet. Reading one goes through our servers, which check that you are on the project the comment belongs to. A picture is deleted when its comment is deleted, and when a project or an organization is deleted along with everything in it.
Changing the setting applies to comments made from then on. It does not alter or delete pictures that were already stored.
6.How we use information
- To provide the Service: showing comments to the people allowed to see them, syncing threads with the integrations you connected, and keeping your preferences.
- To operate and secure it: authenticating you, enforcing access rules, preventing abuse, and debugging with server logs.
- To contact you: replying when you write to us, and — if you are on the waitlist — telling you when you can get in. Waitlist emails are used for that and nothing else.
- To improve the Service, using aggregate, de-identified usage rather than the content of your comments.
7.Integrations: Linear and Slack
Integrations are off until someone in your organization connects them, and each one only reaches what you point it at.
- Linear: when a thread is pushed to Linear, we send the comment text and its page context to create the issue in the team you chose. Replies written on the issue in Linear come back to the thread in Corsight. We store the OAuth credentials Linear grants us, server-side only.
- Slack: when a thread is shared to Slack, we send it as a message to the channel you chose, and replies in that Slack thread come back to Corsight. We store the bot credentials Slack grants us, server-side only.
What happens to data inside those services is governed by their policies: Linear’s privacy policy and Slack’s privacy policy. Disconnecting an integration stops the syncing; content already created in Linear or Slack stays there, under your control in those tools.
8.AI features
When a thread becomes a Linear issue, we may send the text of that thread to Google’s Gemini API to draft the issue’s title and description. That is the only AI feature in the product, and the only content sent is the thread being pushed — never your whole workspace. If the drafting service is unavailable, the issue is created from the comment’s own words instead.
We do not use your content to train AI models.
10.Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — providing the Service you signed up for, including syncing with the integrations you connected.
- Legitimate interests — securing the Service, preventing abuse, and improving it with aggregate usage.
- Consent — the waitlist, and anything else you opt into. You can withdraw consent at any time.
- Legal obligation — where we must keep or disclose data by law.
11.How long we keep it
- Account and content: for as long as your account exists. When you delete your account, your profile and the data attached to it are deleted; comments you wrote inside a team’s projects may remain, attributed to a deleted user, because they are part of that team’s record.
- Waitlist: until you get access, or until you ask us to remove you — whichever comes first.
- Screenshots: for as long as the comment they belong to. Deleting a comment deletes its picture, and so does deleting the project or the organization it lived in.
- Integration credentials: until the integration is disconnected, at which point they are deleted.
- Server logs: for a short operational window, then deleted or de-identified.
12.Security
Data moves over TLS and is stored encrypted at rest by our providers. Access rules are enforced in the database itself, on every read — not just in the interface. Integration credentials are held server-side only and never reach the browser or the extension. No system is perfectly secure; if a breach affects your personal data, we will notify you as the law requires.
13.Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of them, email hello@corsight.app — we will respond within the time the law allows. You can also edit your profile and preferences in the app, leave the waitlist by asking, and disconnect an integration at any time. If you are in the EEA or UK, you may also lodge a complaint with your data protection authority.
14.International transfers
Our providers may store and process data outside your country, including in the United States. Where data leaves the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
16.Children
The Service is for work and is not directed at children. Do not use it if you are under 16. If you believe a child has given us personal data, contact us and we will delete it.
17.Changes to this policy
When we change this policy, we change the date at the top of it. If a change is material — new categories of data, new purposes, new recipients — we will tell account holders by email or in the app before it takes effect.
18.Contact
Questions, requests, complaints: hello@corsight.app.