Privacy policy
Draft of 1 October 2026
Draft — pending legal review
This is a plain-language draft. It describes how CircleIt works today, but a lawyer has not reviewed it yet and it is not a final policy. Text in grey boxes still needs to be filled in.
CircleIt moves design feedback from a web page to your coding agent. To do that it has to handle screenshots of the pages you mark and details about the elements on them. This page explains exactly what, and what it leaves alone.
1. Who we are
CircleIt (“we”, “us”) runs this website, the dashboard, the Chrome extension and the agent plugin. We are responsible for the personal data described here. CircleIt is a trading name of CHM Capital Ltd, registered in England and Wales (company number 17466915), registered office 59-60 Russell Square, London WC1B 4HP. For anything about your personal data, email [email protected].
2. What we collect
Your account
Your name and email address, your password (stored only as a one-way hash), passkeys and two-factor settings if you turn them on, the teams you belong to and your role in each, and the email addresses of people you invite.
Feedback you send with the extension
Nothing is collected while you browse. When you open the extension on a page and press Send, it collects:
- Screenshots of the regions around your marks, not the whole page or, if you send only a page note, one screenshot of the visible part of the page. A screenshot shows whatever was visible in that part of the page, so avoid capturing areas that show information you should not share.
- The page address (URL) and title, and the size of your window and of the page.
- Your marks (their shape and position), your comments and any page note.
- For each element under a mark: a CSS selector, its tag, id and classes, up to 200 characters of its text, its position, a few attributes (such as alt text, link address, name and test ids), 12 computed styles (such as font, colour and spacing), up to 600 characters of its HTML, and source-file hints if the page exposes them.
- Your browser’s user agent string and the extension’s version number.
The extension never reads what is typed into form fields: values are left out of the text and stripped from the HTML it records, and password fields are never read. It does not collect cookies or your browsing history, and it takes nothing from pages you do not send from. When you send marks, the screenshots cover only the areas around them; a note sent on its own captures the visible part of the page.
The extension’s use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Your agent sessions
When the plugin runs in Claude Code or Codex, it registers the session with us. It sends the agent’s name and version, your computer’s hostname, the working directory, the git branch and remote address, a project key derived from them, the project’s local addresses (the APP_URL in its .env file, .test domains and dev-server ports), and the agent’s session or thread id. It also sends the status messages your agent writes back. It does not upload your code.
Connected browsers and agents
An access token for each browser and agent you connect (stored only as a hash), its name, such as “Chrome on macOS”, and when it was last used.
Payments
Payments are handled by Stripe. We never see or store full card numbers. We keep the Stripe customer id, your team’s plan and its payment status, and the card brand and last four digits that Stripe shares with us.
Technical data
- Server logs record IP addresses, requests and errors so we can keep the service secure and working.
- Cookies are used only to keep you signed in and to protect forms (a session cookie, a security token and, if you tick it, “remember me”). There are no advertising or analytics cookies. We count visits to this website with Fathom Analytics, which uses no cookies and collects no personal data.
- Your light or dark preference is remembered in your browser’s local storage. Fonts are served from our own server.
- The extension keeps your last 10 sends in your browser (chrome.storage.local) to show live receipts: the page address and title, the first comment, the project and agent label, the agent’s working directory, and the agent’s latest status message. It also stores there your CircleIt connection token and the name and email of the account it is connected to, the project and agent you last picked for each site (by the site’s address), and where you last left the toolbar on screen (a position only, with no page address). An in-progress draft of your marks is kept in session storage, which is cleared when the browser closes. Nothing is synced elsewhere. Uninstalling the extension removes it.
3. How we use it
- To run the service: deliver feedback to your team’s agent sessions, show it in your inbox, and show each item’s status to the person who sent it.
- To send account emails: address verification, password resets and team invitations.
- To take payments and count each team’s free changes.
- To keep the service secure, prevent abuse and fix problems.
We do not sell your data, use it for advertising, or use your feedback or screenshots to train AI models. [Legal bases for each purpose, for example contract and legitimate interests, to be confirmed.]
4. Who can see it
- Your team. Feedback is visible to the members of the team it was sent to, including clients the team invited, and is delivered to that team’s agent sessions.
- Your agent’s provider. When your agent opens feedback, the brief and screenshots become part of its conversation, which is processed by that agent’s provider (for example Anthropic for Claude Code or OpenAI for Codex) under your own agreement with them.
- Our service providers. Companies that process data for us: Amazon Web Services (hosting and file storage, United States), Cloudflare (network and security), Mailgun (account emails, United States), Google Workspace (support email), Fathom Analytics (website visit counts) and Stripe (payments).
- When the law requires it. If we receive a valid legal request, or to protect people’s rights and safety.
5. Storage and security
Screenshots are kept in private storage. They are never given public links: they are shown only to signed-in members of the team and to agents connected to it, after checking which team they belong to. Passwords and access tokens are stored as hashes, and you can disconnect any browser or agent from the Setup page at any time. All traffic is encrypted with HTTPS, and our servers are in the United States. [International transfer safeguards to be added.]
6. How long we keep it
- Your account data, for as long as you have an account.
- Feedback and its screenshots, until someone on the team deletes the feedback or its project. Deleting feedback deletes its screenshots too.
- If you delete your account, feedback you sent stays with the team you sent it to, but is no longer linked to you.
- Billing records, for as long as tax law requires.
[Retention for server logs and for data of deleted teams to be confirmed.]
7. Your rights
You can ask to see the personal data we hold about you, correct it, delete it, receive a copy of it, or object to or restrict how we use it. You can change your profile and delete your account yourself in Settings. For anything else, contact us. You can also complain to your data protection authority; in the UK that is the Information Commissioner’s Office.
8. Children
CircleIt is a tool for work and is not meant for children. [Minimum age to be confirmed.]
9. Changes to this policy
When this policy changes we will update it here with a new date. If a change affects how we use your data in a significant way, we will email you before it takes effect.
10. Contact
Questions about privacy or your data: [email protected]