Legal

Privacy policy

Effective

The short version: we collect what the product needs to pin a comment to a page and show it to your team, we send it only to the services you connect, and we do not sell it or advertise with it. The long version follows.

1.Who we are

Corsight (“we”, “us”) provides a browser extension and web application that lets teams pin comments to elements on live websites and sync those threads with Linear and Slack, together with this website at corsight.app (the “Service”).

We are the controller of the personal data described in this policy. You can reach us about anything in it at hello@corsight.app. A person reads that inbox.

2.What this policy covers

This policy covers the Corsight website, the Corsight browser extension, and the accounts and workspaces behind them. It does not cover the websites you comment on with the extension, or the third-party services you choose to connect (Linear, Slack) — those have their own policies, linked in section 7.

3.Information we collect

Information you give us.

  • Waitlist: if you join the waitlist, we store your email address, which form on the page you used, and when you signed up. Nothing else.
  • Account: when you create an account, we store your email address and, if you provide them, a display name, an avatar, a job title and a timezone, along with preferences such as theme and whether notifications are on.
  • Content: the comments and replies you write, and the projects and organizations you create or join. Each comment also records where it lives: the URL and title of the page it was placed on, and a description of the element it is pinned to (its position and how to find it again). This is the product — a comment without its place on the page is not one.

Information collected automatically.

  • Timestamps on the things you do — when a comment was written, when a profile was last edited, when the panel was last opened.
  • Standard server logs when your browser or the extension calls our servers: IP address, user agent, and the request made. We use these to operate and secure the Service, not to profile you.

Information from services you connect. If you connect Linear or Slack, we receive and store the credentials those services grant us (see section 7), identifiers for the workspaces, teams and channels you choose, and the replies written there on threads that Corsight syncs.

4.What we do not collect

The extension can draw its overlay on any page you open — that is what it is for — but the overlay is drawn locally, in your browser. The extension does not record your browsing history, does not capture pages you merely visit, and sends nothing to our servers until you place a comment.

When you place one, what leaves your browser is the comment and its anchor — the page URL, the page title, and the description of the element it is pinned to — and, depending on your team’s screenshot setting, a picture of the page. See section 5. We never capture the page itself: no HTML, no page source, and nothing from a page you did not comment on.

We do not sell personal data, and we do not show ads.

5.Screenshots

A comment can keep a picture of the page it was left on, so that whoever reads it later can see what was being talked about. How much of the page that picture contains is your team’s decision, set by an owner or admin in Settings, and a project can be set differently from the rest of the team. There are two choices:

  • Full screenshot — a picture of the visible page, as it looked when the comment was made. This is the default. Only the visible part of the page is ever captured, and only at the moment a comment is written.
  • Layout only — a wireframe: the position and size of the boxes, buttons and fields on screen, and placeholder words wherever a line of text was. Those words are ours, not yours — the same Latin every mockup uses. Your text is never read, so nothing it says can reach the picture, and no image, video or embedded frame is looked at either. This is not a screenshot with the words hidden — nothing is photographed at all, so there is no picture of your page for the words to be hidden in.

There is no third choice that switches capture off, because the layout mode is already the off switch for page content: it photographs nothing, so there is nothing of your page to withhold.

Pictures are stored in Cloudflare R2, in a private bucket that is not readable from the internet. Reading one goes through our servers, which check that you are on the project the comment belongs to. A picture is deleted when its comment is deleted, and when a project or an organization is deleted along with everything in it.

Changing the setting applies to comments made from then on. It does not alter or delete pictures that were already stored.

6.How we use information

  • To provide the Service: showing comments to the people allowed to see them, syncing threads with the integrations you connected, and keeping your preferences.
  • To operate and secure it: authenticating you, enforcing access rules, preventing abuse, and debugging with server logs.
  • To contact you: replying when you write to us, and — if you are on the waitlist — telling you when you can get in. Waitlist emails are used for that and nothing else.
  • To improve the Service, using aggregate, de-identified usage rather than the content of your comments.

7.Integrations: Linear and Slack

Integrations are off until someone in your organization connects them, and each one only reaches what you point it at.

  • Linear: when a thread is pushed to Linear, we send the comment text and its page context to create the issue in the team you chose. Replies written on the issue in Linear come back to the thread in Corsight. We store the OAuth credentials Linear grants us, server-side only.
  • Slack: when a thread is shared to Slack, we send it as a message to the channel you chose, and replies in that Slack thread come back to Corsight. We store the bot credentials Slack grants us, server-side only.

What happens to data inside those services is governed by their policies: Linear’s privacy policy and Slack’s privacy policy. Disconnecting an integration stops the syncing; content already created in Linear or Slack stays there, under your control in those tools.

8.AI features

When a thread becomes a Linear issue, we may send the text of that thread to Google’s Gemini API to draft the issue’s title and description. That is the only AI feature in the product, and the only content sent is the thread being pushed — never your whole workspace. If the drafting service is unavailable, the issue is created from the comment’s own words instead.

We do not use your content to train AI models.

9.Who we share information with

We share personal data only with:

  • Service providers that host and run the Service for us — our database and authentication provider (Supabase), our screenshot storage provider (Cloudflare R2) and our application hosting provider — under contracts that limit what they may do with it.
  • The services you connect (Linear, Slack) and, for issue drafting, Google’s Gemini API, as described above.
  • Your own organization: comments belong to a project inside an organization. A public project is visible to everyone in that organization; a private one only to the people invited to it. That rule is enforced by the database on every read.
  • Authorities, if the law requires it, and successors in a merger or acquisition — in which case this policy continues to apply to data collected under it.

11.How long we keep it

  • Account and content: for as long as your account exists. When you delete your account, your profile and the data attached to it are deleted; comments you wrote inside a team’s projects may remain, attributed to a deleted user, because they are part of that team’s record.
  • Waitlist: until you get access, or until you ask us to remove you — whichever comes first.
  • Screenshots: for as long as the comment they belong to. Deleting a comment deletes its picture, and so does deleting the project or the organization it lived in.
  • Integration credentials: until the integration is disconnected, at which point they are deleted.
  • Server logs: for a short operational window, then deleted or de-identified.

12.Security

Data moves over TLS and is stored encrypted at rest by our providers. Access rules are enforced in the database itself, on every read — not just in the interface. Integration credentials are held server-side only and never reach the browser or the extension. No system is perfectly secure; if a breach affects your personal data, we will notify you as the law requires.

13.Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of them, email hello@corsight.app — we will respond within the time the law allows. You can also edit your profile and preferences in the app, leave the waitlist by asking, and disconnect an integration at any time. If you are in the EEA or UK, you may also lodge a complaint with your data protection authority.

14.International transfers

Our providers may store and process data outside your country, including in the United States. Where data leaves the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.

15.Cookies and local storage

This website sets no advertising or third-party analytics cookies. We use browser storage for two things: remembering your theme choice (light or dark), and — in the app and extension — keeping you signed in. Both are strictly functional.

16.Children

The Service is for work and is not directed at children. Do not use it if you are under 16. If you believe a child has given us personal data, contact us and we will delete it.

17.Changes to this policy

When we change this policy, we change the date at the top of it. If a change is material — new categories of data, new purposes, new recipients — we will tell account holders by email or in the app before it takes effect.

18.Contact

Questions, requests, complaints: hello@corsight.app.