Twiddle Privacy Policy
This policy describes how Twiddle handles data today. It is written for Chrome Web Store review and for people who send feedback.
1. What Twiddle is
Twiddle helps a designer or product person inspect visual properties and design tokens on a live page, make temporary visual or structural edits, preview responsive layouts, and copy a handoff. It is not a page saver, it has no account system in this build, and it does not download or execute remote code.
2. What we do not collect
Twiddle does not run analytics, ads, crash telemetry, or account sync in this build. Inspect, edit, token analysis, Adaptive preview, copied handoffs, and element screenshots stay on your machine unless you press Send report.
Turning Twiddle on or opening Adaptive does not send page content to us. Adaptive previews real viewport widths so CSS @media runs. This build does not ask for site access and does not rewrite User-Agent. Device UA is parked; if it returns, this policy will be updated first.
3. What we collect, and only after Send
Collection happens only when you open Leave feedback and press Send report.
- Feedback note (unless you attach a screenshot instead)
- Optional reply email
- Up to four screenshots (maximum 2 MiB each); these may show the page you were reviewing
- Current page URL — always attached by the current code
Purpose: product support, debugging, and a reply if you left an email. We do not sell this data or use it for ads, creditworthiness, or unrelated profiling.
4. Who receives it
- FormSubmit — HTTPS relay that emails the submission to privacy@twiddle.tools. Their policy: formsubmit.co/privacy.pdf.
- The receiving mailbox — privacy@twiddle.tools. Cloudflare Email Routing forwards it to the operator’s mailbox hosted by Google (Gmail). Policy: policies.google.com/privacy.
No other third party is used for feedback in this build. FormSubmit’s response is read as status data only; Twiddle does not execute returned scripts.
5. Local copies
- After Send, the extension stores a copy (last 20 reports, quota permitting) in
chrome.storage.local. The inspected website cannot read it. - Twiddle deletes any leftover page-origin
localStoragekeytwiddle-feedback-inboxand does not write feedback there anymore. - UI preferences stay in the page’s
localStorageundertwiddle-prefs. They are not sent to us. Same-origin scripts on that site can read those preferences. They do not include your feedback note, email, or screenshots.
6. Retention and deletion
Email copies are kept as long as needed to understand and reply, then deleted on request. Extension storage copies last for up to 20 reports or until you remove the extension. To delete a report we hold, email the contact above from the address you used (or describe the report).
7. Security
Feedback is sent over HTTPS to FormSubmit. We do not ask for passwords, cookies, or authentication tokens. Do not attach secrets, and do not send a report from a page you are not allowed to share.
8. Permissions
This build asks for activeTab, scripting, and storage only. The toolbar icon or Alt+Shift+S injects the inspector on the active tab. This build does not ask for site access and does not rewrite User-Agent.
9. Children
Twiddle is not directed at children under 13. We do not knowingly collect their data.
10. Changes
If collection, processors, or purposes change, this policy and the Chrome Web Store privacy-practices form will be updated before that build ships.
11. Contact
Privacy and deletion: privacy@twiddle.tools
Product mail: hello@twiddle.tools