Privacy Policy
Publisher and operator: Bonita
Privacy contact: cumeseg958@gmail.com
Website: designreviewsexten.com
This policy describes how Pixel Fixer: Design Review handles information when you compare designs with web pages, inspect layouts, save review notes, diagnose resource loading, or request an AI review.
Information stored on your device
The extension stores project and page names, selected page addresses, imported design images, layer settings, measurements, comments, screenshots, interface preferences, and resource-loading facts you attach to notes. Project metadata is stored in Chrome extension storage; images are stored in the extension’s IndexedDB database. Temporary review and diagnostic state is kept in session storage or memory.
Page addresses may include query parameters or fragments if you explicitly enable them for page identification. Ordinary local comparison does not automatically upload your projects, screenshots, or designs to our AI service. The extension does not require a personal account. Clipboard image access occurs when you use an image-paste action.
Resource diagnostics and simulations
When you start diagnostics for a selected tab, the extension records image, font, and stylesheet resource types, reduced resource addresses, event times, HTTP status codes, and loading errors. It does not request network request bodies, cookies, or authorization headers for this feature. User information, query strings, and fragments are removed from displayed diagnostic URLs; URL paths may still contain private information.
A resource-failure simulation temporarily blocks selected resources in a separate test tab. Exact resource addresses may be held temporarily to match a blocking rule. Ending the test clears its temporary diagnostic log and rules. Facts you explicitly attach to notes remain in the project.
Image imports and exports
Importing an image by URL contacts the server at the address you provide and may follow redirects. That server can see your IP address. The import request omits browser credentials and the Referer header. The image is validated and saved locally.
Exports and backups are generated at your request. They contain the review material selected for that export; project backups include original design images, which may contain embedded metadata. Downloaded copies remain under your control.
Optional AI review
Local screenshot previews and basic checks do not send the screenshot to an AI model. Starting AI review or refreshing the allowance contacts our service to check the usage limit. The service issues a random installation token, which the extension stores locally and uses to authenticate requests. The server stores a hash of this token and processes your IP address, including hashed IP records, to limit abuse and enforce the allowance of 15 attempts per installation in a rolling 24-hour period.
When you explicitly submit a full AI review, the extension sends a screenshot of the visible page, your selected design image if any, the page title, a page address stripped of username, password, query, and fragment, viewport and scroll measurements, and geometry and computed CSS styles of visible elements. Form fields and selected regions are masked before submission. Other visible personal information, messages, or confidential content may remain in the screenshot or design. Inspect the preview and avoid submitting material you do not want processed externally.
Our service runs on a virtual private server and sends the screenshot, optional design, page title, and a compact selection of layout and style information directly to OpenAI. The model request does not include the separate page URL field, although our service receives it and an image may show an address. A SQLite database on our server stores installation-token hashes, enrollment IP hashes, submission-rate records, and request receipts, including a hash of the request payload. Source screenshots, design images, full request payloads, and AI results are not written to this database. AI results and the associated review request are temporarily held in server memory so the extension can retrieve the report.
Our hosting provider processes server infrastructure data, and OpenAI processes the review content required to return AI feedback. Infrastructure and model processing may take place outside your country. Hosting logs, security records, and backups can have retention periods separate from those described for our application. OpenAI requests use store: false; this setting does not guarantee immediate deletion of every provider record. See OpenAI API data controls for the provider’s data handling information.
How information is used and shared
Information is used to provide the design-review functions you select, preserve your work, deliver requested AI feedback, enforce usage limits, and protect the service. We do not sell user data, use it for personalized advertising, or use it to determine creditworthiness or for lending.
Transfers are limited to providing these functions, security needs, legal requirements, or other cases permitted by the Chrome Web Store User Data Policy. Human access is limited to cases permitted by that policy, such as your specific consent for support, security investigations, or legal obligations. The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
If you contact us by email, we receive your address and the information you choose to include so we can respond. Do not send passwords or your installation authentication token by email.
Retention and deletion
Local projects and images have no automatic expiry. Moving a project or page to the catalog trash retains its underlying data. Settings provide tools to remove unused files and clear the extension’s local data. Clearing local data does not delete downloaded exports or server-side records.
AI reports, including their review requests and results, are held temporarily in server memory and are eligible for removal one hour after completion; a cleanup task runs approximately every 30 seconds. Results may be removed earlier when memory limits are reached or the service restarts. Submission-rate IP records are removed after they are at least one minute old during a later database transaction. Installation identifiers, token hashes, enrollment IP hashes, and request receipts currently have no automatic expiration and remain until removed. These periods do not define the retention of hosting-provider logs, backups, or OpenAI records.
For questions or requests to access, correct, or delete information held by Bonita, contact cumeseg958@gmail.com. Because the service does not associate installations with an email account, we may need additional non-secret information to locate the relevant records and verify your request. We cannot access project data stored only on your device.
Security and changes
AI-service communications use HTTPS. The operator’s AI credentials remain on the server rather than in the extension. No storage or transmission system can guarantee absolute security.
Updates to this policy will be published on this page with a revised date. Changes requiring additional disclosure or consent will be presented in the extension before the changed data handling begins.