Privacy Policy

Last updated: September 23, 2026

1. Introduction

This Privacy Policy explains how Bunny Inspector ("we", "our", or "us") collects, uses, and protects your information when you use our browser extension and website at inspector.bunnytech.app.

Key Principle: We do not capture, collect, or store any data from inside the browser extension. Your annotations and all captured data stay entirely on your device. We have no access to any content you create or inspect using the extension.

2. Information We Collect

Account Information

When you sign up using Google or GitHub, we receive:

  • Your email address
  • Your name (as provided by the OAuth provider)
  • Your profile picture URL

Subscription & Payment Information

When you subscribe to a paid plan, we store the following in our database:

  • Your subscription plan (monthly or yearly)
  • Subscription status (active, cancelled, past due, etc.)
  • Billing period dates
  • Stripe customer ID and subscription ID (for subscription management)
  • The date and time your license was last verified ("last used"), so we can tell active licenses from dormant ones

Your payment card details, billing address, and full transaction history are collected and stored directly by Stripe and never pass through or are stored on our servers.

What We Do NOT Collect

We do not collect, transmit, or have access to any data from inside the browser extension. This includes:

  • Your annotations or their content
  • Screenshots you capture
  • Websites you visit or browse
  • Console logs or network requests you record
  • CSS selectors, HTML content, or source locations
  • Any page content or DOM data
  • Your browsing history or behavior

The only communication the extension makes with our servers is to verify that your license is valid.

3. Chrome Extension Permissions

Our browser extension requests the following permissions:

  • activeTab: To inspect and annotate elements on the current page you're viewing
  • storage: To save your annotations and settings locally in your browser
  • downloads: To export your annotations as a file when you choose to download
  • sidePanel: To display the extension interface in Chrome's side panel
  • webRequest: To capture network request details when you enable network recording for debugging
  • contextMenus: To provide right-click menu options for quick annotation actions
  • Host permissions (<all_urls>): To enable inspection on any website you visit. All captured data stays local in your browser.

Important: All data captured using these permissions is stored locally in your browser using IndexedDB. None of this data is transmitted to our servers. The extension only contacts our servers to verify your license status. You control when and how to export your data.

4. Cookies, Analytics and Advertising

Your Choice: When you first visit, a cookie banner asks whether we may use Analytics (PostHog) and Advertising (OpenAI) cookies. Neither is set until you accept. Essential storage (your sign-in session and your cookie choice) is always on. You can change your choice at any time under "Cookie settings" in the footer.

Website Only: Our website at inspector.bunnytech.app uses Cloudflare Web Analytics, which uses cookies for privacy-friendly, anonymous traffic analysis. These cookies do not track you across websites and do not collect personal information.

Product Analytics (PostHog): Our website also uses PostHog to understand how visitors use the site so we can improve it. It records the pages you visit on our site and key actions (signing in, buying a license, clicking "Add to Chrome"). If you accept Analytics, PostHog also stores a randomly generated, anonymous device identifier in your browser and may record a session replay of your visit, with everything you type into forms masked. If you don't, PostHog stores nothing on your device and only counts visits using an anonymous hash computed on its servers. We do not collect any personal information from anonymous visitors.

If you are signed in and accepted Analytics, we additionally attach the following to your PostHog profile so we can measure activation and support your account: your account ID, email, name, subscription plan and status, whether your license is currently valid, whether you are a paying customer, and the date your license was last verified. We use PostHog's EU cloud, and it acts as a data processor on our behalf. This applies to the website only.

Advertising Measurement (OpenAI): We advertise in ChatGPT and use the OpenAI Ads Measurement Pixel on our website to learn which ads lead to sign-ups, installs, and purchases. It only runs if you accept Advertising. The pixel then stores the ad click ID in a first-party cookie (__oppref, 30 days), along with a random browser ID (__obref, 1 year). Turning Advertising off deletes both cookies.

With Advertising on, we report three events to OpenAI: when you sign in, when you buy a license (plan and price), and when you click "Add to Chrome". Each report includes your email address and account ID, hashed with SHA-256 before they leave your browser or our server, so OpenAI does not receive them in readable form. OpenAI also receives the page URL, your IP address, and your browser's user agent. The pixel may detect an email address you type into a form on our site and send it in the same hashed form. The website works the same whether you accept or not.

Extension: The browser extension does not use cookies, tracking pixels, or any analytics. It does not track your browsing activity or behavior.

5. How We Use Your Information

We use the information we collect to:

  • Authenticate you and manage your account
  • Process subscription payments
  • Verify your license when using the extension
  • Understand how our website is used and improve the product (via privacy-friendly analytics)
  • Measure which of our ads lead to sign-ups, installs, and purchases
  • Respond to support requests
  • Send important service updates (optional)

6. Third-Party Services

We use the following third-party services:

Stripe (Payment Processor)

We use Stripe to process all subscription payments and manage billing. When you subscribe to a paid plan, Stripe directly collects and processes the following information:

  • Payment card details (card number, expiration date, CVC)
  • Billing name and address
  • Email address
  • Transaction history and payment amounts

Important: We never see or store your full card details. Stripe handles all payment information directly on their PCI-compliant servers. We only receive and store your Stripe customer ID and subscription status to manage your account.

Stripe may use your data in accordance with their own privacy policy. See Stripe's Privacy Policy.

Cloudflare Web Analytics

We use Cloudflare Web Analytics on our website for anonymous traffic analysis. It is privacy-friendly and does not use personally identifiable information. See Cloudflare's Privacy Policy.

PostHog (Product Analytics)

We use PostHog on our website to analyze usage and improve the product. PostHog processes the pages you visit and, if you accept Analytics, an anonymous device identifier, session replays, and — for signed-in users — your account ID, email, name, subscription plan and status, license validity, and last license-check date. Data is processed on PostHog's EU cloud. See PostHog's Privacy Policy.

OpenAI (Advertising Measurement)

If you accept Advertising, we use the OpenAI Ads Measurement Pixel and Conversions API to measure our ads in ChatGPT. OpenAI receives the ad click ID, a browser ID, the page URL, your IP address and user agent, and your hashed (SHA-256) email address and account ID when you sign in, buy a license, or click "Add to Chrome" (see ). See OpenAI's Privacy Policy.

Google OAuth

If you sign in with Google, Google shares your basic profile information with us. See Google's Privacy Policy.

GitHub OAuth

If you sign in with GitHub, GitHub shares your basic profile information with us. See GitHub's Privacy Statement.

Turso (Database)

We use Turso to store account and subscription data. Data is stored in the EU (Ireland). See Turso's Privacy Policy.

7. Data Storage and Security

Extension Data: All annotation data captured by the browser extension is stored locally in your browser using IndexedDB. This data never leaves your device unless you explicitly export it.

Account Data: Your account and subscription information is stored in our database hosted in the European Union (EU).

We implement appropriate security measures including encryption in transit (HTTPS), secure authentication tokens, and regular security reviews. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

8. Data Retention

  • Account data: Retained while your account is active, deleted upon request
  • Subscription data: Retained for legal/accounting purposes as required by law
  • Extension data: Stored locally on your device, entirely controlled by you
  • Ad measurement cookies: __oppref expires after 30 days, __obref after 1 year

9. Your Rights

You have the right to:

  • Access: Request a copy of the data we hold about you
  • Rectification: Request correction of inaccurate data
  • Deletion: Request deletion of your account and data
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain data processing

To exercise these rights, contact us at privacy@bunnytech.app

10. GDPR Compliance (EU Users)

For users in the European Union, we process your data under the following legal bases:

  • Contract: To provide the service you subscribed to
  • Consent: For analytics (PostHog) and advertising (OpenAI) cookies, given in our cookie banner. You can withdraw it at any time under "Cookie settings" in the footer
  • Legitimate Interest: To prevent fraud and improve our service
  • Legal Obligation: To comply with legal requirements

11. CCPA Compliance (California Users)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of the sale of personal information

We do not sell your personal information.

If you accept Advertising, we share hashed identifiers with OpenAI only to measure our own ads (see Third-Party Services). To opt out, turn off Advertising under "Cookie settings" in the footer, or contact us at privacy@bunnytech.app.

12. Children's Privacy

Bunny Inspector is not intended for users under 16 years of age. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

14. Contact Us

If you have questions about this Privacy Policy, please contact us at privacy@bunnytech.app