What this policy covers
This policy describes how PikSpec handles information in PikSpec — Website Inspector, previously named PikSpec Studio, and the connected PikSpec website and private workspace. The extension’s purpose is to help you inspect and document the visual design of a webpage you choose, then save or export that design reference. Inspection begins when you choose to analyse a page; opening the panel or changing tabs does not by itself authorise a new inspection.
Information PikSpec handles
PikSpec handles account and profile information, its own authentication credentials, inspected page addresses and titles, website content, and interactions needed for inspection. The connected service also handles feature-use and allowance records, subscription and billing information, and network information such as IP addresses. The sections below explain what stays on your device, what is sent to our services, and your choices.
PikSpec is a website-design tool and does not have a dedicated feature for collecting medical records or private messages. However, text, screenshots and clone archives can contain health information, personal communications, financial information or other sensitive content when you choose a page that contains it. There is no blanket filter that removes all such information. Review the source page and the proposed capture before saving or sharing, and avoid capturing information you do not intend to include.
What stays in your browser
During inspection, PikSpec processes the selected page’s rendered structure, computed styles, colours, typography, spacing, media references and the elements you select. Local state can include the page address, inspected text, component previews, generated tokens and export progress. Extension storage retains some of this information so you can reopen the panel or retry an interrupted action.
Element selection, highlighting and the colour picker process pointer position and selection actions while you use those tools. These interactions serve the inspection you requested; PikSpec does not run a general keystroke logger or use them to build an advertising profile. The URLs and titles in saved captures form your PikSpec capture history, not a copy of Chrome’s browsing-history database.
PikSpec does not use browser APIs to read the inspected site’s cookies, browser history database or local/session storage. It does not intentionally extract that site’s sign-in credentials. Structured evidence excludes form values and applies privacy filters, but these filters do not guarantee that every piece of personal information or secret embedded in page content is removed. Review pages and exports before saving or sharing them, especially on signed-in sites.
Inspect, Tokens, Clone and screenshots
Inspect reads the element you choose, its styles, text and layout. An element screenshot or the colour picker can read pixels from the visible tab. Font verification may briefly use Chrome’s debugging API to identify the fonts actually rendered in the selected element. PikSpec does not continuously record your screen or inspect unrelated tabs in the background.
Tokens turns measured colours, typography, spacing and other supported style values into reusable design tokens. Local export and copy actions do not automatically send those files to PikSpec’s workspace or to an AI provider. Workspace saves upload the evidence or token output described in the save review.
Clone prepares a static page reference, not the original website’s backend. Its archive can contain page text, HTML including hidden markup, CSS, media, links and preserved inactive scripts. Clone omits values from recognised password and credential controls, including supported embedded-frame snapshots. This is targeted protection: clone archives are not automatically redacted of all personal information. Other text, markup or screenshots can still contain secrets or private information, including content that is not visible on screen. Source asset requests can use your browser’s existing site session; this does not require PikSpec to read the cookie values. Capture only content you are entitled to use.
While preparing a clone, PikSpec may scroll the page and open supported menus or disclosures to record their visible states. It avoids recognised account and navigation actions, but a site’s own event handlers can still make network requests or have side effects. Only run this feature on pages where you are comfortable allowing those interactions.
Why the extension asks for permissions
activeTab and scripting let PikSpec identify the current page after you invoke it and run the inspection and capture code included in the extension package. sidePanel displays the tools beside your page. storage retains preferences, PikSpec session credentials and local capture or export state. downloads saves exports and media you request; PikSpec does not use it to collect your existing download history. identity supports the sign-in handoff to your PikSpec account.
debugger is used briefly to identify fonts actually rendered in a selected element and to capture responsive viewport screenshots when you include them in a save. Chrome may display a debugging notice. PikSpec clears its viewport overrides and detaches after the operation; it does not use this permission to extract cookies, credentials or network request bodies.
Access to www.pikspec.com supports sign-in, account and allowance checks, confirmed workspace uploads and communication with the PikSpec website. Optional access to all websites is requested through Grant access & analyse so you can inspect pages you choose and use visible-pixel tools after navigation. Granting access does not authorise automatic analysis of every page: a new page requires your explicit analysis action. You can revoke site access in Chrome’s extension settings.
What is sent when you save
Saving to your workspace sends the source page address and title, measured design evidence, selected component information and previews, and any generated token set included in the save review to PikSpec’s backend. Structured source addresses are normalised to remove query strings and fragments; URLs inside clone files or page content may still retain them. Cancelling the save review does not upload that capture.
Responsive desktop, tablet and mobile screenshots are an additional choice in the save review. The checkbox is initially selected for a new capture; you can clear it before confirming Save. These are screenshots of the visible viewport at each size, not a complete scrolling-page recording. They can include visible personal information and are not automatically anonymised. Chrome’s debugging API temporarily changes the viewport for this feature and then restores it.
When you choose to save a static clone to your workspace, the archive and its metadata are uploaded too. Saved evidence is associated with your account and is not published as a public gallery. Local downloads stay on your device unless you subsequently upload or share them. Opening media references, previews that load external assets, or original-file downloads makes requests to the sites hosting those files; those sites receive ordinary network information such as your IP address and may apply their own policies.
Account, billing and service information
We process your account email, profile information and sign-in provider to operate your account. Device and session records include extension version, browser label, timestamps and hashed installation identifiers. Server-side session credentials are protected separately from capture data. The extension stores an opaque refresh credential to keep you signed in.
We record plan entitlements, allowance usage, payment and subscription identifiers, and account/security events to provide paid features, prevent duplicate charges and investigate failures. These essential service records can be linked to your account and are separate from optional browser analytics. Dodo Payments collects payment details and handles checkout and receipts. PikSpec may display billing addresses and masked payment details returned by Dodo; it does not collect full card numbers or CVCs. If you contact support, we also process the information you provide to answer your request.
Some local generation and download actions contact PikSpec to check or record your allowance, even if you do not save page content to the workspace. These requests include the feature, quantity, operation or reservation identifiers, and, for reconstruction outputs, opaque inspection identifiers linked to your account. These service records are distinct from uploading a capture or sending a prompt to an AI provider. Cancelling a save stops that capture upload; it does not undo sign-in, allowance or security records already created.
Our servers process IP addresses to limit abusive request rates. Our hosting and security providers also receive ordinary request and browser information to deliver and protect the service. Application-error diagnostics include a generalised PikSpec page path and an error identifier; the diagnostic payload does not include captured page content, passwords or session tokens. PikSpec does not request GPS or precise device-location access. IP addresses are nevertheless network information covered by this policy.
With your permission and when enabled, first-party product analytics record events on PikSpec, generalised page paths, a per-tab session identifier and allow-listed event properties. Browser analytics are not attached to your account identifier. The web client honours Global Privacy Control and Do Not Track for this optional telemetry. Infrastructure providers also process operational request information for delivery, security and troubleshooting. This is separate from reading your browsing history.
Why we use information and who processes it
We use information to provide inspection and workspace features, authenticate you, fulfil requested exports, manage allowances and subscriptions, send account/service messages, and secure and maintain PikSpec. Hosting and application delivery use Vercel; authentication, database and private capture storage use Supabase; transactional email uses Resend; billing uses Dodo Payments. Signing in with Google also involves Google. When enabled, Cloudflare Turnstile provides authentication abuse checks. These providers process information needed for their respective services and may operate outside your country. Applicable contractual and legal safeguards govern those transfers.
Exporting a prompt or token file does not itself send it to an external AI tool. If you paste, upload or share that file with another service, that service’s policies apply. We do not sell extension user data, use it for personalised advertising, or transfer it to data brokers. Information may also be disclosed when necessary to comply with applicable legal obligations or protect users and the service.
We do not use or transfer user data to determine creditworthiness or for lending. Transfers to service providers are limited to the purposes described here and permitted by the Chrome Web Store User Data Policy; using a provider does not authorise unrelated advertising or sale of extension user data.
PikSpec’s use and transfer of extension user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension user data is used only for the user-facing inspection and workspace features described here, except for the limited purposes permitted by that policy.
We do not use extension user data to train general-purpose AI models. Human access to extension user data is limited to specific data you have affirmatively agreed we may access, security investigations, legal requirements, or aggregated and anonymised data used for internal operations as permitted by Chrome’s Limited Use rules. Support staff do not have permission to browse your captures for unrelated purposes.
How information is protected
PikSpec uses HTTPS for production service requests, account-scoped access checks for workspace content, private clone storage and time-limited access links. Backend service credentials are not shipped in the extension. These safeguards reduce risk but cannot guarantee that a service, browser or downloaded file is completely secure. Keep your account secure and avoid sharing access links, exported private content or authentication credentials.
Retention and your controls
Saved workspace content remains associated with your account until you delete it. Moving a capture to Trash is not permanent deletion; use permanent deletion or Account → Data and privacy → Delete capture data to remove saved evidence. Account settings also let you download an account-data summary, manage extension sessions and request account deletion. The summary currently includes up to 100 capture-index entries and is not a complete archive of every captured file; export individual captures separately if you want to keep them, or contact support for help with a broader access request.
Permanent capture deletion removes stored evidence and clone files, including unfinished uploads associated with that capture. Storage and database failures are reported so deletion can be retried. An upload already in progress can finish after deletion: a minimal cleanup record containing account/capture identifiers and a cleanup time is retained for a later storage sweep, then removed after successful cleanup. It does not contain page content. Previously issued upload links can remain valid for up to two hours; delayed cleanup runs through scheduled maintenance after that window and can take longer if a service is unavailable.
An expired upload or sign-in token means that token can no longer complete its action; it does not by itself mean every related record or local recovery file has been deleted. Unfinished capture evidence can remain until account/capture-data deletion, and local recovery data can remain in extension storage. Scheduled maintenance removes product-event records older than 90 days. Other account, subscription and security records are kept for their service purpose and applicable retention obligations.
Deleting an account removes its live account and capture records through the deletion workflow. Billing-provider records and information needed for legal obligations, dispute resolution or security may be retained separately. Provider backups may persist until their normal expiry. A failed deletion is reported as a failure, not as completed. Contact us if you need help exercising access, correction or deletion rights.
Uninstalling the extension clears its local extension storage but does not delete your cloud account or files you downloaded. You can revoke site access in Chrome’s extension settings and revoke signed-in extension sessions in PikSpec account settings. Essential sign-in cookies and local application storage keep the service working; they are not advertising cookies.
Depending on where you live, you may have rights to access, correct, delete, receive a copy of, restrict or object to processing of your information, and to withdraw optional consent or complain to a relevant privacy authority. Contact PikSpec using the address below; we may need to verify account ownership before acting. Withdrawing optional analytics consent does not disable essential account and billing processing or delete earlier service records.
Updates and contact
We update this policy when the product or its data handling changes. The version date appears above. Use the contact below for privacy questions, requests or reports of content you believe should be removed. Include only the information needed to locate the issue; never send passwords, session tokens or payment-card details.
Contact PikSpec
Email support@pikspec.com for support, privacy requests or content reports.