CometWeb Lens extension privacy policy
Last updated: 7 October 2026
Data controller
Data controller: Maciej Zmitrukiewicz (CometWeb). Privacy contact: hello@cometweb.io
Supervisory authority (Poland): UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl
Website access and the context-menu helper
The extension declares a small content script for all web pages so the right-click Inspect element feature can work. Your browser may show a broad site-access permission. The script listens for the context-menu event; only then does it compute a CSS selector for the selected element and pass that selector and the current page URL to temporary extension storage. It does not send page text, form values or network requests. Insight requests start only after you choose an Insight feature.
Cloud reports and scans
When you connect your Insight account, the extension sends your API key to app.cometweb.io to authenticate requests. Opening a report sends the inspected page URL to look up existing results. Starting a cloud scan sends that URL and the selected scan level; the backend then audits the public page. Task and mute actions send the selected finding, page URL and text you provide. Routine lookups remove query parameters and fragments; a scan keeps non-sensitive query parameters but removes credentials and secret-like parameters.
Current tab audit
On request, Lens checks six accessibility rules in the current browser tab, including pages behind a login. The page content and full URL stay in your browser. Results stay in extension memory for up to ten minutes. To save a result in Insight, you must choose a project and agree to each export. The export contains the site origin, keyed fingerprints of the page, named state, role and affected elements, rule outcomes, browser and viewport details, language and capture time. Insight also records the project, workspace and account that sent it and removes the observation after 30 days. This is a user-reported observation, not a cloud score or proof of WCAG compliance.
Optional metrics
Browser metrics are optional. On first launch you can allow them or use the extension without sending them. Declining does not block reports, the side panel, inspector, or fix snippets.
You can change this later in extension settings. After metrics are turned off, the extension does not send further browser measurement data.
What data may be sent?
When metrics are enabled, the extension collects technical data about the audited page:
- Page performance metrics (LCP, INP, CLS, FCP and TTFB)
- Counts of JavaScript-accessible cookies by category
- Third-party request counts and transfer size, when available, by resource category
- Cookie names and third-party resource addresses are used locally for categorization; they are not sent
- Audited page URL without query parameters, fragment, or credentials
- Date and time of the measurement
Optional browser measurements do not include cookie names or values, page form contents, or values typed into the inspected page's input fields. Account authentication and task text are described separately above.
Purpose of processing
Data is used to enrich the page quality audit with measurements from a real browser and to associate those measurements with the user's CometWeb project.
Where does the data go?
Metrics are sent over an encrypted connection only to the CometWeb backend. The production address is https://app.cometweb.io. The API key is kept in extension-origin storage and is never sent to the audited page.
Preview security
HTML fix previews are sanitized. Scripts, forms, event handlers, inline styles, and attributes that could fetch external resources — such as src, srcset, and href — are removed.
Local data and removal
Page tools inspect the current DOM locally. The extension does not upload the whole DOM or your local HTML/CSS previews. Your API key stays in extension-origin IndexedDB; settings stay in local extension storage and report cache entries expire after five minutes. Removing the key clears cached results and scan polling. Uninstalling removes local extension data; cloud reports belong to your Insight account and must be managed there. Private browsing is not supported.
Use of data
Data is used to provide reports, cloud scans, task actions and optional page measurements. CometWeb Lens does not sell browsing data, use it for advertising, or transmit it to a separate analytics service. Its use of data is limited to the stated features. Account data and server-side retention are covered by the full CometWeb privacy policy.
Your rights
For access, rectification, or deletion requests, use app.cometweb.io/profile or email hello@cometweb.io.
Full privacy policy
The full privacy policy is available at cometweb.io/legal/privacy.