PrivacyPolicy隐私政策

Privacy for a review tool that touches real pages.面向真实页面审稿工具的隐私政策。

This policy explains how Visual Feedback Studio handles information across the website, Web Studio, Chrome companion, local receiver, and Team Preview.本政策说明 Visual Feedback Studio 如何处理官网、Web Studio、Chrome companion、本地 receiver 与 Team Preview 中的信息。

UpdatedJuly 6, 20262026 年 7 月 6 日
01Overview概览

Local by default. Shared only when you choose shared workflows.默认本地,仅在你选择共享流程时共享。

Visual Feedback Studio is built to capture visual review intent on implemented interfaces. In the local workflow, feedback is saved to your machine. In hosted or Team Preview workflows, selected review context is stored so reviewers can decide, hand off, and verify together.Visual Feedback Studio 用于在已实现界面上捕捉视觉审稿意图。在本地工作流中,反馈保存在你的机器上。在 hosted 或 Team Preview 工作流中,被选择的审稿上下文会被保存,以便多人共同裁决、交接和验证。

Beta note:Beta 说明: This policy describes the current public beta surfaces. Formal company details, paid-plan terms, and enterprise addenda may be added later.本政策描述当前公开 Beta 产品表面。正式公司主体、付费计划条款和企业补充协议可能在后续加入。
02Services covered适用范围

This policy covers every VFS surface.本政策覆盖所有 VFS 表面。

This policy applies to visualfeedbackstudio.com, app.visualfeedbackstudio.com, the Visual Feedback Studio Chrome companion, the local receiver, local workflow scripts, and Team Preview API or workspace features.本政策适用于 visualfeedbackstudio.com、app.visualfeedbackstudio.com、Visual Feedback Studio Chrome companion、本地 receiver、本地工作流脚本,以及 Team Preview API 或工作台功能。

It does not control third-party products you use with VFS, including your coding agent, browser, hosting provider, repository host, or the pages you choose to review.本政策不控制你与 VFS 一起使用的第三方产品,包括你的 coding agent、浏览器、托管服务、代码仓库服务,或你选择审查的页面。

03Information we collect我们收集的信息

Review data is different from source code.审稿数据不等于源码。

Account
When you use hosted or Team Preview features, we may process identity from GitHub OAuth or device flow, including provider user id, display name, and email when provided.当你使用 hosted 或 Team Preview 功能时,我们可能处理来自 GitHub OAuth 或 device flow 的身份信息,包括 provider user id、显示名称,以及可用时的邮箱。
Workspace
We may store workspace, project, member, invite, role, access, and project metadata needed to run shared review rounds.我们可能保存运行共享审稿轮次所需的 workspace、project、member、invite、role、access 与项目元数据。
Rounds
Review rounds may include labels, goals, preview URLs, viewport sets, base ref metadata, status, deadlines, exports, and timestamps.审稿轮次可能包含名称、目标、预览 URL、viewport 集合、base ref 元数据、状态、截止时间、导出记录和时间戳。
Feedback
Feedback items may include reviewer display name and role, selected target, DOM or selector clues, source hints, notes, copy, style, measurement payloads, page URL, title, and source URL.反馈项可能包含审稿人显示名称和角色、被选目标、DOM 或 selector 线索、源码提示、备注、文案、样式、测量 payload、页面 URL、标题和 source URL。
Decisions
We may store decisions, conflict groups, finalized actions, verification summaries, report metadata, audit timestamps, and related review trail data.我们可能保存裁决、冲突分组、最终动作、验证摘要、报告元数据、审计时间戳和相关审稿轨迹数据。
Site usage
The public website may use Vercel Analytics to understand basic page usage and site health without selling or advertising against that data.公开官网可能使用 Vercel Analytics 了解基础页面使用情况和站点健康状态,但不会出售这些数据或用于广告投放。
04Chrome extension and local receiverChrome 插件与本地 receiver

The companion works only when you start review.Companion 只在你开始审稿时工作。

The Chrome companion uses the required permissions activeTab, scripting, and storage. Site access for http, https, and file pages is requested as optional host permission, site by site, when you start review on a page.Chrome companion 使用必需权限 activeTab、scripting 和 storage。针对 http、https 与 file 页面的站点访问作为 optional host permission,在你对某个页面开始审稿时按站点请求。

The extension is not a browsing-history collector. It injects the review workspace only on pages you click or authorize, and access can be revoked through browser controls.插件不是浏览历史采集器。它只在你点击或授权的页面上注入审稿工作台,访问权限可通过浏览器控制撤销。

chrome.storage.local and page localStorage may store language, theme, temporary agent preference, and local receiver token. Local feedback saves to 127.0.0.1 by default. Hosted or Team Preview data is created only when you sign in and actively sync or save into that workflow.chrome.storage.local 和页面 localStorage 可能保存语言、主题、临时 agent 偏好和本地 receiver token。本地反馈默认保存到 127.0.0.1。Hosted 或 Team Preview 数据只会在你登录并主动同步或保存到该工作流时产生。

Limited Use: Information handled by the extension is used only to provide or improve visual review features and is handled consistently with the Chrome Web Store User Data Policy Limited Use requirements.插件处理的信息仅用于提供或改进视觉审稿功能,并按照 Chrome Web Store User Data Policy 的 Limited Use 要求处理。
05Hosted Studio and Team PreviewHosted Studio 与 Team Preview

Shared rounds need shared review context.共享轮次需要共享审稿上下文。

When you use hosted or Team Preview features, Visual Feedback Studio stores the review objects needed for the workspace: accounts, memberships, projects, rounds, feedback, conflicts, decisions, finalized actions, verification summaries, and reports.当你使用 hosted 或 Team Preview 功能时,Visual Feedback Studio 会保存工作台所需的审稿对象:账号、成员关系、项目、轮次、反馈、冲突、裁决、最终动作、验证摘要和报告。

Source code, receiver tokens, local file paths, environment variables, and local rollback snapshots are not intentionally synced to hosted services. If you include sensitive information inside notes or page content, that information may become part of the review data you choose to sync.源码、receiver token、本地文件路径、环境变量和本地 rollback snapshot 不会被有意同步到 hosted 服务。如果你在备注或页面内容中包含敏感信息,该信息可能成为你选择同步的审稿数据的一部分。

06How we use information信息用途

We use data to run the review loop.我们用数据运行审稿闭环。

We use information to provide the service, authenticate users, run review rounds, save feedback, group conflicts, record decisions, generate handoff context, verify outcomes, secure the product, debug issues, and communicate about the service.我们使用信息来提供服务、验证用户身份、运行审稿轮次、保存反馈、分组冲突、记录裁决、生成交接上下文、验证结果、保护产品安全、调试问题,并就服务与你沟通。

07What we do not do我们不会做什么

No ads. No resale. No cross-site profiling.不做广告,不出售,不做跨站画像。

We do not sell personal information. We do not use extension data for advertising, credit, insurance, employment, or unrelated profiling. We do not ask the agent to edit source code merely because the browser observed a page.我们不会出售个人信息。我们不会将插件数据用于广告、信贷、保险、就业或无关画像。浏览器看到页面,并不意味着我们会要求 agent 修改源码。

08Sharing and subprocessors共享与服务提供方

VFS uses infrastructure, not ad networks.VFS 使用基础设施,而不是广告网络。

We may share information with service providers that help operate VFS: Vercel for static site hosting and analytics, Cloudflare Workers and D1 for Team Preview API and data storage when enabled, GitHub OAuth as the Team Preview identity provider, and browser or Chrome platform APIs for extension operation.我们可能与帮助 VFS 运行的服务提供方共享信息:Vercel 用于静态站点托管与分析;启用时 Cloudflare Workers 和 D1 用于 Team Preview API 与数据存储;GitHub OAuth 用作 Team Preview 身份提供方;浏览器或 Chrome 平台 API 用于插件运行。

We may also disclose information if required by law, to protect rights and safety, or as part of a business transfer, subject to appropriate safeguards.在法律要求、保护权利与安全,或业务转让场景中,我们也可能在适当保护措施下披露信息。

09Retention, export, and deletion保留、导出与删除

You should be able to take review data with you.你应该可以带走审稿数据。

Local workflow files remain under your control on your machine. Hosted review data is retained while needed to provide the service, maintain review history, comply with obligations, resolve disputes, and protect security.本地工作流文件由你在自己的机器上控制。Hosted 审稿数据会在提供服务、维护审稿历史、履行义务、解决争议和保护安全所需期间保留。

Team Preview supports export-oriented workflows, and some records may use soft deletion or append-only decision logs to preserve review integrity. You may contact us to request access, correction, export, or deletion where applicable.Team Preview 支持面向导出的工作流,部分记录可能使用软删除或 append-only 裁决日志,以保持审稿完整性。在适用范围内,你可以联系我们请求访问、更正、导出或删除。

10Security安全

Tokens and origins define the first boundary.Token 与 origin 是第一道边界。

The local receiver uses origin checks and receiver tokens when configured. Team Preview stores session and invite tokens as hashes where supported by the service design. Access is role-based, and guest invite tokens are scoped to the intended review round.本地 receiver 在配置时使用 origin 检查和 receiver token。Team Preview 在服务设计支持的地方以 hash 形式保存 session 与 invite token。访问控制基于角色,guest invite token 限定在目标审稿轮次内。

No method of transmission or storage is perfectly secure. Use VFS only on pages and projects you are authorized to review, and avoid placing secrets in review notes.没有任何传输或存储方式能保证绝对安全。请仅在你有权审查的页面和项目中使用 VFS,并避免把密钥写进审稿备注。

11Your choices and rights你的选择与权利

You control the mode you use.你控制使用哪种模式。

You can use the local workflow without a team account, revoke Chrome site access, remove local files, sign out of hosted features, export review data where available, and request deletion or correction by contacting us.你可以在没有团队账号的情况下使用本地工作流,撤销 Chrome 站点访问,删除本地文件,退出 hosted 功能,在可用时导出审稿数据,并通过联系我们请求删除或更正。

12Children未成年人

VFS is for professional review workflows.VFS 面向专业审稿工作流。

Visual Feedback Studio is not directed to children. Do not use the service if you are not old enough to consent to these terms in your location or to use professional developer tools.Visual Feedback Studio 不面向儿童。如果你未达到所在地同意本政策或使用专业开发者工具的年龄,请不要使用本服务。

13International use跨境使用

Your tools may operate across borders.你的工具可能跨境运行。

Depending on where you and our service providers are located, information may be processed in countries other than your own. We use service providers and safeguards appropriate to the beta service.根据你和服务提供方所在位置,信息可能在你所在国家或地区之外被处理。我们会为 Beta 服务使用相应的服务提供方和保护措施。

14Changes变更

Policy changes will be visible here.政策变更会在这里可见。

We may update this policy as the product changes. Material changes will be reflected by updating the date above and, when appropriate, by providing additional notice in the product or on the site.我们可能随着产品变化更新本政策。重大变更会通过更新上方日期,并在适当时通过产品内或官网的额外通知体现。

15Contact联系

Questions go to one place.问题集中发到一个地方。

For privacy questions, requests, or concerns, contact Visual Feedback Studio at hello@visualfeedbackstudio.com.如有隐私问题、请求或疑虑,请通过 hello@visualfeedbackstudio.com 联系 Visual Feedback Studio。