Privacy policy for SiteTweak - Edit Any Site with AI
SiteTweak - Edit Any Site with AI by Pavel
Privacy policy for SiteTweak - Edit Any Site with AI
This Privacy Policy ("Policy") explains how SiteTweak ("we," "us," and "our") collects, uses, and shares information when you use our browser extension and related services ("Services").
By installing or using SiteTweak, you acknowledge that your information will be handled as described below. If you do not agree with this Policy, please do not use the Services.
For privacy-related questions or to exercise your rights under applicable data protection law, contact us at u4342113639@gmail.com.
We aim to collect the minimum information needed to operate and improve SiteTweak.
There are two ways SiteTweak can generate a customization, and they differ in where your data goes:
- With your own OpenRouter key. Your browser sends the request straight to the model provider. Nothing about the page reaches SiteTweak's servers.
- With free generation. Your request goes through SiteTweak's servers to the model provider. The page content passes through our servers; we do not store it.
Separately from either mode, an optional telemetry setting sends usage data to help improve the extension. Where data is sent to our servers under that setting, we apply automated PII redaction before transmission to reduce what we receive.
The following information is stored locally in your browser's extension storage and is never transmitted to our servers:
- Your OpenRouter API key
- Theme, language, and model preferences
- Telemetry opt-in/opt-out preference
- Saved scripts and customizations (a tweak you explicitly publish with Share is the exception — see "Shared tweaks" below)
Saved scripts and generated code from past sessions are stored locally. If telemetry sharing is enabled, generated code may also be sent to SiteTweak telemetry as described below.
SiteTweak can generate customizations without an OpenRouter key of your own. In that mode your request goes through SiteTweak's servers to the model provider, and the answer comes back the same way. Each request carries:
- Your prompt and the recent conversation for that customization
- The structure and relevant content of the page you are customizing, after local cleaning
- The customization currently applied to that page, where it is relevant to your request
- The results of any page inspection the model requests while working on your request
- A random device identifier, created on your device and stored locally, used to count how many free generations you have used, to limit abuse, and — if you publish a shared tweak — to recognize your device as the one allowed to update or delete it
- The domain you are on, which reaches our records only as an irreversible hash
What we keep. Free generation passes through; it is not recorded. We do not store the page content, your prompt, the conversation, or the generated code from this path. Our records for it hold counters only: the hashed domain, the number of model calls, token counts, the cost, and whether the generation completed. The optional telemetry described below is a separate setting with its own data and its own retention.
How to avoid it entirely. If you configure your own OpenRouter API key, free generation is not used, and none of the above reaches SiteTweak's servers.
SiteTweak lets you publish a tweak as a public link. When you press Share, the tweak's name, description, site pattern, and code are uploaded to our servers and become visible to anyone who has the link, along with the version history of your later updates. Your device identifier is stored with the share so that your device — and no other — can update or delete it; it is never shown publicly. If you ask SiteTweak to draft the description for you, the tweak's name, site pattern, and code go to the model provider the same way as a free generation; we do not store that request or its answer beyond the description you choose to publish.
A shared tweak stays published until you delete it — with the Delete control in the extension or on its share page — or ask us to remove it, or until it is blocked following abuse reports. Deleting removes the tweak, its version history, and its reports from our database; copies that other people already installed remain in their browsers.
When you contact us for support, report a bug, request a feature, or exercise your data rights, we receive the email address you write from and the contents of your message. We use this only to respond to you.
The extension includes a "Share anonymous usage data" setting to help improve SiteTweak. This setting may be enabled when you first install the extension, and you can turn it off at any time in the extension settings. When telemetry sharing is enabled, we collect the following when you submit a prompt:
- The text of your prompt, after automated PII redaction is applied locally on your device
- The generated CSS and JavaScript returned by the model, after the same redaction is applied
- Metadata about the request: model name used, response length, response format, timestamp
- The website domain (e.g.
example.com, not the full URL or page contents) where the customization was applied - Lifecycle events: when you regenerate, save, delete, or toggle a customization
- Language and timezone, for compatibility analysis
About PII redaction. Before prompt text or generated code is sent to SiteTweak telemetry, it is processed locally through an automated redaction step. Detected identifiers — including email addresses, phone numbers, IP addresses, payment card numbers, IBAN and bank account numbers, government identifiers, postal addresses, and common API keys and tokens — are replaced with type tokens such as
[EMAIL] or [PHONE]. The redacted text is what reaches our servers. No automated system catches every possible identifier; you should not paste highly sensitive information into prompts.You can disable telemetry at any time in the extension settings. Disabling stops all future collection but does not retroactively delete previously collected data; for that, see "Your Rights" below.
When your browser communicates with our servers — for free generation, for the customization gallery, for shared tweaks, or for telemetry if you have it enabled — our infrastructure receives standard request metadata, including your IP address and user agent. IP addresses are used for security, abuse prevention, and rate limiting, including a daily cap on free generations per address; they are retained in access logs for up to 30 days and are not joined to telemetry records.
We use the information described above to:
- Operate, maintain, and improve SiteTweak
- Deliver free generations, count them against your free allowance, and keep the cost of that allowance within its budget
- Analyze how the extension is used so we can develop new features and fix bugs
- Evaluate and improve our prompts, model selection, and generation quality (using redacted prompt and response data)
- Diagnose technical issues
- Detect and prevent abuse, fraud, and security threats
- Respond to your support requests and legal obligations
The commitments in this section apply to SiteTweak wherever you installed it from.
SiteTweak's use and transfer of information received from Chrome Web Store APIs to any other app will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
We do not use telemetry data for advertising, ad targeting, ad measurement, or sale to third parties. We do not allow humans to read individual user prompts except (a) when required for security investigations or to comply with legal obligations, (b) when you explicitly share content with us through a support request, or (c) on a small sample of fully redacted records reviewed internally to evaluate redaction quality and improve generation. Reviewers in case (c) see only post-redaction text.
We share information only in these situations:
- Service providers we rely on to run SiteTweak, such as hosting and infrastructure providers. They process data on our behalf under contractual confidentiality obligations and may not use it for their own purposes.
- OpenRouter. Generating a customization requires sending your request to a language model through OpenRouter. In either mode this may include your prompt, the model used, relevant page structure and content from the page you are customizing, recent conversation context, and any currently applied customization relevant to the request.
- If you use your own API key, this goes directly from your browser to OpenRouter and does not pass through SiteTweak servers.
- If you use free generation, it passes through SiteTweak's servers and is then handled by OpenRouter in the same way.
OpenRouter's handling of your data is governed by their privacy policy at https://openrouter.ai/privacy.
- Anyone with the link, if you publish a tweak. Sharing a tweak is deliberate publication: its name, description, site pattern, and code become readable by anyone who opens the link. See "Shared tweaks" above for what is stored and how to take it down.
- Legal compliance and safety. We may disclose information if we believe in good faith that disclosure is required by law, legal process, or to protect the rights, property, or safety of SiteTweak, our users, or others.
- Business transfers. If SiteTweak is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction. We will notify users and provide choices where required by applicable law.
We do not sell your information. We do not share telemetry with advertisers or data brokers.
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Consent (Art. 6(1)(a)) for telemetry collection. You may withdraw consent at any time by disabling telemetry sharing in the extension settings.
- Performance of a contract (Art. 6(1)(b)) for delivering the core extension functionality you requested, including delivering a free generation you asked for, counting it against your free allowance, and publishing, updating, or deleting a tweak you chose to share.
- Legitimate interests (Art. 6(1)(f)) for security, abuse prevention, server log retention, and responding to support requests. Our interests are balanced against your rights and freedoms; you have the right to object.
- Legal obligation (Art. 6(1)(c)) where we must comply with applicable law.
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. You may also lodge a complaint with your local data protection authority. To exercise any of these rights, email u4342113639@gmail.com; we will respond within the timeframe required by applicable law.
- Local data on your device persists until you uninstall the extension or clear it through extension settings.
- Telemetry records are retained for up to 12 months and then automatically deleted.
- Free generation leaves no record of page content, prompts, or generated code. The counters it does produce — hashed domain, model calls, token counts, cost, outcome — are retained for up to 12 months.
- Shared tweaks stay published until you delete them, ask us to remove them, or they are blocked; deleting removes the share, its version history, and its reports from our database immediately.
- Server access logs are retained for up to 30 days.
- Support correspondence is retained for as long as needed to handle your request and meet record-keeping obligations.
- Backups may persist for a short additional period beyond the primary retention windows above and are overwritten on a rolling basis.
To request earlier deletion, email u4342113639@gmail.com.
We use HTTPS for all communication between the extension and our servers. Telemetry is stored in an access-controlled database. We apply technical and organizational measures appropriate to the sensitivity of the data, but no system is perfectly secure and we cannot guarantee absolute protection.
SiteTweak is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided information to us, contact u4342113639@gmail.com and we will delete it.
We may update this Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. For material changes, we will provide notice through the extension or by updating this page in advance of the change taking effect.
For privacy questions, requests, or complaints: u4342113639@gmail.com.