Privacy Policy — Teifi Portal Snapshot
Teifi Portal Snapshot is a test-and-feedback browser extension. It captures bug evidence only when you explicitly act (start a session, take a screenshot, record, or file a finding). It does no passive tracking, analytics, or advertising.
What we collect
Only content you deliberately capture during a test session:
- Screenshots and screen/tab recordings you take.
- Annotations and reproduction steps you record.
- Console logs and network request metadata from the tab under test (to help reproduce a bug).
- Environment details: page URL, browser, OS, app version, window size.
- Your name and organization from Linear, used to attribute reports.
Secrets are redacted before storage: authorization headers, bearer tokens, JWTs, and sensitive URL query parameters are stripped; recording inputs are masked.
What we do not collect
- No browsing history, no passive page monitoring, no keystroke logging outside a captured step.
- No data is collected from pages when no session is active.
- We never sell your data or use it for advertising.
How it is used and stored
- Media (screenshots, recordings) are uploaded to Cloudflare R2 (cdn.teifi.work).
- Report data (findings, logs, steps, environment) is stored in a Postgres database (report.teifi.work).
- When you choose to file a finding, its media and description are sent to your own Linear workspace via your Linear account.
- Creating a report requires your Linear account. Viewing one requires the secret share link the extension gives you: anyone you send that link to can view the report, including people outside your organization, until the report is deleted. Do not share it more widely than you intend.
- The API and the MCP integration for AI agents are restricted to your Linear organization or to a token you create yourself.
- Media files (screenshots, recordings) are served from a public CDN URL that is unguessable but unauthenticated.
Authentication
The extension holds no secrets. Uploads and report creation authenticate with your own Linear OAuth token, validated server-side against your Linear organization. The token is stored locally in the browser's extension storage and is never shared with third parties.
Permissions
Broad host access (<all_urls>) exists so you can capture on any site you are testing. Other permissions map directly to features: screenshots and recording, injecting the capture toolbar, Linear sign-in, and saving a recording locally when upload is unavailable.
Retention and deletion
Reports persist until deleted by a member of your organization. To request deletion of a report or your data, contact us.
Contact
Questions or data requests: privacy@teifi.work.