Privacy policy
Last updated 7 September 2026
Flupes is a Chrome extension and companion website for reviewing live web pages. You pin a comment to an element on a page, your team replies in a thread on that same element, and you can send the thread to Linear. This policy describes exactly what that involves collecting, and what happens to it.
When Flupes is doing anything at all
The extension is installed with every site switched off. Nothing runs on a page until you turn Flupes on for that site from the extension‘s popup, or until someone on your team creates a project for it — and your own choice to switch a site off always wins over your team‘s. On a site that is switched off, the extension shows no interface and contacts no server.
Chrome asks you to grant access to all sites when you install, because the extension cannot know in advance which sites you will want to review. That grant is what makes it possible to switch a site on later without reinstalling anything. It is not a description of what the extension does with it.
What we collect
Only when you are signed in and working on a site you have turned on.
Your account
- Your name, email address and profile picture, from the Google account you sign in with.
- The organisation you belong to and the projects you can see.
- A random identifier generated once per browser installation, used to match your browser to your integration connections. It is not derived from anything about you or your device.
The comments you write
- The text of your comment and your replies.
- The address and title of the page you commented on.
- How to find the element you pointed at again on a later visit: a CSS selector, an XPath, the element‘s visible text, its ARIA role and label, and its `data-` attributes.
- A short excerpt of that element‘s HTML — at most 500 characters — and thirteen of its computed CSS properties, so a developer reading the comment can see what you were looking at.
- A screenshot of the area around the element. Your browser captures the visible tab, then crops it to that area before anything leaves your computer; only the crop is stored or sent.
- Your browser and operating system name, your window size, your screen size and your display scale factor, so a layout problem can be reproduced.
Your integration settings
- Which sites you have turned Flupes on or off for.
- If you connect Linear, an authorisation held on your behalf so we can post on your behalf. We never see your Linear password.
- If you choose to paste a Linear personal API key instead of connecting an account, that key.
What we never collect
- Your browsing history, your open tabs, or the addresses of pages you did not comment on.
- Page content beyond the element you deliberately pointed at.
- Cookies, passwords, form entries, or anything stored by the sites you visit.
- Anything at all on a site you have not turned Flupes on for. On those sites the extension loads no interface and makes no network requests.
What we use it for
To show your comments to the people you are reviewing with, to put a comment back on the right element when you return to a page, to send a thread to Linear when you ask us to, and to email your team when there is something new to read.
That is the whole list. We do not sell your data, we do not share it with advertisers, we do not use it to build a profile of you, and we do not use it to train models. Flupes contains no analytics, tracking or advertising code of any kind.
Who else sees it
The services we rely on to run Flupes, and nobody else:
- Supabase
- Hosts our database and the private storage bucket that holds screenshots. Located in the United States.
- Cloudflare
- Runs the small service that talks to Linear and our email provider on your behalf.
- Pipedream Connect
- Holds the Linear authorisation of accounts connected before we ran our own Linear app, so we do not have to. Only reached when such an account sends a comment onward.
- Linear
- Receives a comment — its text, the page address, the technical details listed above and the screenshot — only when you press send.
- Loops
- Sends notification and invitation emails. Receives your email address and the notification text, nothing else.
- Stripe
- Processes payments as merchant of record; receives billing name, email and address. Card details never reach us.
We will also disclose data if the law requires it, or to investigate abuse or a security problem. If Flupes is ever acquired, data moves with it, and we will say so here before that happens.
Where it is stored, and how
Comments and account data live in our database. Screenshots live in a private storage bucket that is not readable from the open internet; when the app needs to show you one, it mints a link that expires within the hour. Everything travels over HTTPS.
Some settings are kept in your browser‘s own extension storage rather than on our servers — which sites you have turned on, your sign-in session, and your unsent drafts. Removing the extension removes those.
How long we keep it
Comments and their screenshots stay until you or a teammate delete them, or until the project is deleted. Delete a project and its comments and screenshots go with it.
To delete your account and everything attached to it, write to us at the address below and we will remove it within 30 days. Anything already sent onward to Linear lives in Linear under its own retention rules and has to be deleted there.
Children
Flupes is a tool for professional teams. It is not directed at children, and we do not knowingly collect data from anyone under 13.
Changes to this policy
If what we collect changes, this page changes with it and the date at the top moves. A change that widens what we collect will also ask for your agreement inside the extension before it takes effect.
Contact
Questions, or a deletion request: hi@flupes.app.