Privacy policy
Last updated: September 27, 2026
Summary
The extension does not collect, store on a server or transmit any of your data, and it talks to no server. No analytics, no telemetry and no user account. Nothing you inspect leaves your machine. The license and restore pages on this site do talk to the site's own API, described under "Network requests" below.
What the extension does
UIFoxy stays inert until you click its icon in the Chrome toolbar. That click grants the activeTab permission for that tab only and injects two scripts into it: one that reads the page's component tree and one that draws the selection interface. When you click an element, the extension builds a Markdown text with the file path and the matching line and puts it on your clipboard.
Data accessed, and why
- Structure of the open page (DOM and component tree). Purpose: Finding out which component is under the cursor. Where it stays: Tab memory. Discarded when the tab closes.
- Sourcemaps (.map) of the open page. Purpose: Translating a position in the served file into the file in your project. Where it stays: Service worker memory. Discarded when Chrome shuts the worker down.
- Tab title and URL. Purpose: Building the header of the generated prompt. Where it stays: Inside the text that goes to your clipboard, and in the prompt histories: the tab’s, in session storage, and the Pro plan’s, in local storage.
- The comment you write. Purpose: It is the content of the prompt. Where it stays: Browser session storage, so it survives a reload. Cleared when the tab or the browser closes.
- Last 10 prompts copied in the tab. Purpose: Copying them again. Where it stays: Browser session storage. Cleared when the tab or the browser closes.
- Daily prompt counter (date and number). Purpose: The Free plan limit. Where it stays: Extension local storage, in your browser only.
- Pro license key. Purpose: Unlocking Pro. Where it stays: Extension local storage.
- Last 100 copied prompts, on Pro (including page titles and URLs). Purpose: History across browser sessions. Where it stays: Extension local storage. Removed when you uninstall the extension.
Network requests
The only request the extension makes fetches the sourcemap file from the same origin as the page you are inspecting, the same server that already delivered the site or app. No request is made to UIFoxy servers or to third parties.
The license and restore pages on this site talk to the site's own API, which looks up your purchase on Stripe and, to restore a license, emails you the link through Cloudflare. That happens on the site, not in the extension.
Remote code execution
None. All code that runs comes from the installed package. Fetched sourcemaps are read as data (JSON) and never evaluated as code.
Declared permissions
activeTab. Grants access only to the tab where you clicked the icon, and only for as long as that session lasts. It replaces a request for access to every site.scripting. Injects the package's two scripts into the tab, on demand.storage. Keeps, locally, your selection session (until the tab closes), the Free plan counter, the license key and, on Pro, your prompt history. Nothing is synced.
The extension declares no host_permissions, so it has no permanent access to any site.
Plans and payment
The Pro plan is purchased through Stripe, which processes billing data under its own privacy policy. The extension only stores the license key in your browser to unlock unlimited use. No payment data passes through the extension.
To restore a license, you type the email you used at checkout. It is used only to look up the purchase and send you the link, and it is not stored. Cloudflare sends the email and runs Turnstile, a bot check, on that page.
Changes
If this policy changes, the date at the top of this page is updated. Changes that expand the data accessed require a new version of the extension, reviewed by the Chrome Web Store.
Contact
Questions or requests about privacy: write to us.
