Privacy Policy
Effective date: September 16, 2026
ReviewSieve is a Chrome extension that reduces review noise on GitHub pull requests. This policy explains the data ReviewSieve handles, why it is handled, where it is stored, and which service providers receive it.
1. GitHub pull-request content
When you view a GitHub pull request, ReviewSieve reads the rendered review comments needed to classify, filter, deduplicate, and compare review findings.
Raw GitHub review text is processed locally in your browser. ReviewSieve does not send raw GitHub review text to ReviewSieve servers, Supabase, Stripe, Resend, or an AI model.
For cross-visit Review Delta, ReviewSieve stores privacy-preserving hashes/signatures and limited review metadata locally in Chrome storage instead of storing raw review text. It also stores a hashed identifier for the pull request so the same PR can be recognized on a later visit.
2. Local usage metrics
ReviewSieve may store local-only product metrics such as comments processed, comments avoided, duplicates collapsed, and PRs cleaned. These values and their deduplication hashes remain in Chrome local storage and are not transmitted for analytics or advertising.
3. Account and authentication data
If you sign in, ReviewSieve uses your email address for passwordless authentication through Supabase Auth. One-time sign-in emails are delivered through Resend.
Authentication access credentials are kept in the extension's session cache. The refresh credential used to restore your session is stored in extension-origin IndexedDB. Raw authentication tokens are not sent to GitHub content scripts.
4. Subscription and billing data
If you purchase ReviewSieve Pro, ReviewSieve uses Supabase Edge Functions to start Stripe Checkout and Stripe Customer Portal sessions. Stripe processes payment-card details on Stripe-hosted pages. ReviewSieve does not receive or store card numbers or CVC values.
ReviewSieve's backend stores subscription-related identifiers and status needed to determine whether your account has Pro access, such as the Stripe customer identifier, subscription identifier, price identifier, subscription status, and renewal/cancellation timestamps.
5. Service providers
- Supabase — authentication, entitlement records, and server-side billing functions.
- Resend — delivery of passwordless one-time sign-in emails through SMTP.
- Stripe — paid subscription checkout, customer portal, billing, invoices, and subscription events.
- GitHub — the website on which ReviewSieve's local review-cleaning functionality operates.
6. Advertising, sale, and profiling
ReviewSieve does not sell user data. ReviewSieve does not use GitHub review content, account data, or browsing information for personalized advertising, retargeting, credit scoring, or data-broker purposes.
7. Data retention and deletion
Local ReviewSieve data is stored in the Chrome profile in which the extension is installed. Uninstalling the extension removes extension-local browser storage according to Chrome's extension storage behavior.
Signing out removes the locally stored authentication session/refresh credential. Subscription records may remain on ReviewSieve's backend for billing, fraud prevention, accounting, dispute handling, and legal compliance where required.
For an account-data deletion request, use the publisher support contact shown on the ReviewSieve Chrome Web Store listing.
8. Security
ReviewSieve limits extension permissions to the functionality it needs, uses HTTPS for remote service communication, does not execute remotely hosted JavaScript, and keeps privileged Stripe, Supabase, and Resend secrets on server-side systems rather than in the extension package.
9. Chrome Web Store Limited Use
10. Changes
If ReviewSieve changes how it handles user data, this policy and the Chrome Web Store privacy disclosures will be updated before or alongside the relevant product change.
11. Contact
For privacy questions, use the publisher support contact listed on the ReviewSieve Chrome Web Store page.