CometWeb Lens extension privacy policy

Last updated: 7 October 2026

Data controller

Data controller: Maciej Zmitrukiewicz (CometWeb). Privacy contact: hello@cometweb.io
Supervisory authority (Poland): UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl

Website access and the context-menu helper

The extension declares a small content script for all web pages so the right-click Inspect element feature can work. Your browser may show a broad site-access permission. The script listens for the context-menu event; only then does it compute a CSS selector for the selected element and pass that selector and the current page URL to temporary extension storage. It does not send page text, form values or network requests. Insight requests start only after you choose an Insight feature.

Cloud reports and scans

When you connect your Insight account, the extension sends your API key to app.cometweb.io to authenticate requests. Opening a report sends the inspected page URL to look up existing results. Starting a cloud scan sends that URL and the selected scan level; the backend then audits the public page. Task and mute actions send the selected finding, page URL and text you provide. Routine lookups remove query parameters and fragments; a scan keeps non-sensitive query parameters but removes credentials and secret-like parameters.

Current tab audit

On request, Lens checks six accessibility rules in the current browser tab, including pages behind a login. The page content and full URL stay in your browser. Results stay in extension memory for up to ten minutes. To save a result in Insight, you must choose a project and agree to each export. The export contains the site origin, keyed fingerprints of the page, named state, role and affected elements, rule outcomes, browser and viewport details, language and capture time. Insight also records the project, workspace and account that sent it and removes the observation after 30 days. This is a user-reported observation, not a cloud score or proof of WCAG compliance.

Optional metrics

Browser metrics are optional. On first launch you can allow them or use the extension without sending them. Declining does not block reports, the side panel, inspector, or fix snippets.

You can change this later in extension settings. After metrics are turned off, the extension does not send further browser measurement data.

What data may be sent?

When metrics are enabled, the extension collects technical data about the audited page:

Optional browser measurements do not include cookie names or values, page form contents, or values typed into the inspected page's input fields. Account authentication and task text are described separately above.

Purpose of processing

Data is used to enrich the page quality audit with measurements from a real browser and to associate those measurements with the user's CometWeb project.

Where does the data go?

Metrics are sent over an encrypted connection only to the CometWeb backend. The production address is https://app.cometweb.io. The API key is kept in extension-origin storage and is never sent to the audited page.

Preview security

HTML fix previews are sanitized. Scripts, forms, event handlers, inline styles, and attributes that could fetch external resources — such as src, srcset, and href — are removed.

Local data and removal

Page tools inspect the current DOM locally. The extension does not upload the whole DOM or your local HTML/CSS previews. Your API key stays in extension-origin IndexedDB; settings stay in local extension storage and report cache entries expire after five minutes. Removing the key clears cached results and scan polling. Uninstalling removes local extension data; cloud reports belong to your Insight account and must be managed there. Private browsing is not supported.

Use of data

Data is used to provide reports, cloud scans, task actions and optional page measurements. CometWeb Lens does not sell browsing data, use it for advertising, or transmit it to a separate analytics service. Its use of data is limited to the stated features. Account data and server-side retention are covered by the full CometWeb privacy policy.

Your rights

For access, rectification, or deletion requests, use app.cometweb.io/profile or email hello@cometweb.io.

Full privacy policy

The full privacy policy is available at cometweb.io/legal/privacy.