YOUR FEEDBACK, YOUR DEVICE
Privacy policy.
Effective October 8, 2026
Your feedback, screenshots, and recordings stay on your device. Pagepaint’s operators do not receive them unless you explicitly share them. Pagepaint has no feedback database, analytics, advertising, or automatic synchronization.
What stays local
Messages, drafts, settings, annotations, screenshots, and recordings are
saved in your browser’s IndexedDB. If you choose a repository folder,
the browser writes ordinary files into its
.annotations/ directory. ZIP exports download to your
device. Each website origin keeps its own CDN-widget data; the browser
extension has separate local storage.
Feedback deliberately includes full URLs and query parameters, page titles, viewport and scroll details, visible page content, and timestamps. Annotation shapes retain the drawing coordinates you choose. Your feedback messages and optional author name remain local unless you export or choose to share them. We cannot recover local feedback after browser data is cleared.
Browser extension permissions
Pagepaint handles the website content you choose to capture, your comments, and the URLs of pages you activate. This local processing is part of its visual feedback feature; it does not monitor your browsing in the background. The extension uses activeTab and scripting to open the toolbar on the tab you activate, storage for local project preferences, and tabCapture and offscreen for a recording you start. It has no blanket host permission, remote executable code, data sales, or unrelated use of your feedback.
Optional GitHub sign-in
GitHub sign-in uses a small Cloudflare Worker to exchange an authorization code for an access token. The client secret is held in Worker secrets. Your access token is encrypted in an HttpOnly cookie, expires within eight hours, and is available only to Pagepaint’s trusted GitHub connection window. It is not saved in the embedded app’s preferences or exports. There is no server session database.
GitHub OAuth asks for repository and Project access, including private repositories. Signing in alone does not share feedback. The account name and repository names you choose to return to the widget are used to configure your project locally. This non-secret metadata is saved in project preferences so it survives refresh; access tokens stay in the trusted connection window.
Sharing an issue
When you review and create a GitHub issue, the connection window sends
the chosen thread and page context directly to GitHub. If you enable
attachments, screenshots, editable annotation metadata, and recordings
are committed to .pagepaint/ on a
pagepaint-feedback branch in the selected repository.
Public repository uploads are public. Private repository permissions
govern private uploads. GitHub stores these issues and commits under its
own policies; signing out of Pagepaint does not delete them.
Hosting and necessary cookies
Cloudflare delivers this website and CDN script and processes ordinary request and connection information, such as IP addresses and request metadata, for delivery and security. GitHub receives authentication requests and any issues or attachments you explicitly publish. We do not use this information for advertising or run analytics scripts. Pagepaint uses local preferences and necessary authentication cookies; it has no advertising or tracking cookies.
Read Cloudflare’s privacy policy and GitHub’s privacy statement for their processing and retention practices.
Your controls
You can clear site data or remove the extension to delete its browser copies, remove the selected local annotation files, and delete downloaded ZIPs. Sign out to clear the Pagepaint authentication cookie. Revoke Pagepaint in GitHub’s authorized-app settings to withdraw its GitHub access. Manage published issues and attachment commits in GitHub separately.
Changes and contact
Pagepaint is maintained by DevPlant. Changes to these practices will be reflected here with an updated effective date. Contact the maintainers through the GitHub link on the Pagepaint homepage.