Privacy Policy
Last updated: 13 August 2026
RefKit runs on your machine. It has no accounts, no analytics, no telemetry, and no server that receives your data. The short version: nothing leaves your computer unless you explicitly send it somewhere you control.
Who is responsible
RefKit is an independent developer tool. Questions about this policy can be sent through the support page.
What the extension reads, and when
Nothing is read until you click. RefKit declares no content scripts and runs nothing on page load, so it cannot work in the background or inspect a tab you have not pointed it at. A fresh install holds no host permission at all. When you press Capture this page, it uses either the temporary access Chrome grants for that one tab, or access to the exact origin if you granted it from the button in the panel. Another origin needs its own decision — and in both cases RefKit collects:
- computed CSS values — colours, fonts, sizes, spacing, radii, shadows, transitions;
- the size and position of elements, used to weight which colours dominate the page;
- how much text an element renders, and a SHA-256 digest of it — never the words. Length is what tells a heading from body copy and weights contrast; the words were never used for anything;
- style rules for hover, focus, active and disabled states, when the page’s stylesheets are readable;
- author-declared CSS custom properties (design tokens), breakpoint widths from media queries, the page URL, page title, viewport size and colour scheme.
What it never reads
- Cookies,
localStorage,sessionStorageor any session data. - Your browsing history, other tabs, or any page you did not capture.
- Raw page HTML. Only the bounded set of properties listed above is collected.
- Passwords or the contents of form fields.
What a capture still contains
Two things survive in the clear, and they are worth knowing about rather than discovering: the page URL path and the page title. A capture nobody can identify is a capture nobody can use, so both are kept — and on a page like /patients/1234titled with a person’s name, that is the part that matters.
The query string and fragment are removed by default, along with any credentials embedded in the URL. You can keep the query for a single capture with a checkbox in the panel; it does not persist to the next one.
Before anything is sent anywhere, the side panel shows you the exact payload — the same bytes the extension would transmit, not a summary of them. Reviewing it is the control that covers what redaction cannot.
What is stored, and where
| Data | Where it lives | Why |
|---|---|---|
| Panel preferences | Local browser storage | Remembering your settings between sessions. |
| Bridge pairing (port and token) | Local browser storage | Reaching the RefKit server you started on your own machine. The token is only ever sent to 127.0.0.1. |
| Captures and design profiles | Your own repository, under .refkit/ | So the design contract survives the chat, travels with the branch, and is reviewable in a diff. |
Data we transmit
None to us. RefKit operates no backend. There is no endpoint that receives captures, usage statistics, error reports or identifiers, because no such service exists.
The extension can send a capture to one place, and only if you set it up: a RefKit server running on your own computer at 127.0.0.1. That connection requires an optional permission you grant during pairing and can revoke at any time in Chrome’s extension settings, plus a token generated for your project. The server refuses requests that come from web-page origins.
Third parties
In the product, there are none. No analytics provider, no error tracker, no advertising network, no AI service. Nothing about your captures is sold, shared or used to train anything.
This website counts its visitors, and it would be dishonest not to say so on the page where you came to read what we do not do.refkit.dev uses Vercel Web Analytics: it counts page views and which site or search sent you, sets no cookie, writes nothing to your browser, and builds no profile that follows you anywhere. Its script is served from this domain rather than someone else’s, which is why the site’s Content-Security-Policy still permits no external script at all.
None of this touches the extension or the server. They remain what the paragraphs above describe: no counter, no identifier, no request that leaves your machine.
Retention and deletion
Because storage is local, you control deletion entirely. Removing the extension clears its browser storage; deleting the .refkit/ directory in a project removes its captures and profile. There is nothing held elsewhere for us to delete on request.
Children
RefKit is a developer tool and is not directed at children under 13, and it does not knowingly collect information from them.
Changes
If this policy changes in a way that affects what is collected or where it goes, the change will be published here with a new date before a release that depends on it. The permissions the extension requests are enforced by an automated contract test, so a quiet expansion of access cannot ship unnoticed.
Chrome Web Store disclosures
RefKit’s single purpose is to capture the visual design of a page you choose and make it available to your coding tools. Handling of user data complies with the Chrome Web Store Developer Program Policies, including the Limited Use requirements: data is used only for that single purpose, is never sold or transferred for advertising or creditworthiness, and is not transferred to any third party.