Privacy Policy
Effective September 3, 2026
Product Pass is published by DOTDEV. This policy explains how the Product Pass browser extension handles information.
Summary
Product Pass has no advertising, analytics, tracking, or publisher-operated backend. Review data, screenshots, and screen recordings are stored locally. Data leaves the browser only when you explicitly use a configured AI provider, authenticate with a provider, or publish to GitHub.
Information handled locally
- Review sessions, note text, page titles and URLs, selected-element labels and selectors, annotation geometry, and issue drafts.
- Cropped annotation screenshots and no-audio WebM screen recordings stored in extension IndexedDB. Media is not sent to AI providers and is sent to GitHub only when you explicitly enable media upload for a draft and confirm publication.
- Settings and credentials—including API keys, GitHub tokens, and Codex OAuth/identity tokens—stored in extension
storage.local. Opaque identity tokens may encode provider account identifiers. Browser extension storage is not a hardware-backed vault.
User-directed transfers
AI organization
When you confirm “Organize notes,” Product Pass may send note text, page title, sanitized URL without credentials/query/fragment, annotation type, and element label to your selected AI provider. It does not send screenshot or recording blobs, page DOM, CSS selectors, URL query strings, URL fragments, or credentials in the prompt. If no provider is configured, organization happens locally.
GitHub publishing
When you accept and confirm publication, Product Pass sends the edited issue title and body, including its source-evidence text and an invisible reconciliation marker, to the GitHub repository you configured. Source evidence may contain page URLs, titles, labels, and CSS selectors. GitHub authentication and accessible-repository lookup requests are sent directly to GitHub. If you explicitly enable media upload for that draft, Product Pass also sends the source JPEG/WebM bytes directly to GitHub's experimental, undocumented attachment endpoint and inserts returned URLs into the issue. Media upload is off by default.
Authentication
If you choose ChatGPT/Codex subscription authentication, authentication data is exchanged directly with OpenAI. If you choose GitHub OAuth Device Flow, authentication data is exchanged directly with GitHub using the repository scope you select. Product Pass does not forward tokens to DOTDEV.
Permissions
- Site access: requested per site so you can select page elements, draw boundaries, restore overlays, and capture the visible selected area.
- Tabs, active tab, and scripting: identify the active page, capture its visible area after you invoke Product Pass, and run annotation tools only on sites you enable.
- Storage: retain sessions, screenshots, recordings, settings, and credentials.
- Alarms: safely resume time-limited device authentication flows.
- Side panel/sidebar: display the Product Pass workspace.
Retention and deletion
Local data remains until you delete a session, clear credentials, remove extension data, or uninstall Product Pass. “Finish” preserves a session; “Delete session” permanently removes its local notes, drafts, screenshots, and recordings. Deleting local data cannot delete media previously uploaded to GitHub. Third-party providers apply their own retention policies to information you direct Product Pass to send.
Sharing and sale
DOTDEV does not receive, sell, rent, or use Product Pass data for advertising, credit, or unrelated purposes. User-directed transfers to configured providers are required to perform the requested feature.
Children
Product Pass is a professional productivity tool and is not directed to children.
Changes and contact
Material changes will be published here with a revised effective date. Questions or privacy requests: product-pass@moejay.dev.