Privacy Policy for Cratis Lens

August 4, 2026 ยท View on GitHub

Last Updated: August 4, 2026

Introduction

Cratis Lens ("Extension," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how the Cratis Lens Chrome extension collects, uses, discloses, and safeguards your information when you use our extension.

1. Information We Collect

1.1 Automatically Collected Information

  • Local Storage: The Extension stores user settings, preferences, and configuration data locally on your device using Chrome storage APIs. This data is device-local and is not transmitted to our servers unless explicitly configured.
  • Extension Runtime Information: The Extension may read non-personal technical information such as extension version, Chrome version, and browser settings to provide functionality and maintain compatibility. This information is not transmitted to Cratis unless you explicitly configure a feature that sends data to a Cratis Arc backend.

1.2 Information You Provide

  • Configuration and Preferences: When you configure the Extension, such as connecting to a Cratis Arc backend or setting preferences, this information is stored locally on your device.
  • Authentication Credentials: If the Extension requires connection to a Cratis Arc backend service, any authentication tokens or credentials you provide are handled according to the privacy policy of your Cratis Arc service provider.

1.3 Information from Web Pages

  • Web Content Interaction: The Extension may access content from web pages you visit to provide developer productivity tools and insights. This access is limited to the functionality you explicitly request and is not transmitted to external servers unless required for features you enable.
  • Page Metadata: The Extension may collect metadata about pages you visit (such as URLs, page titles) solely for providing extension features and enabling developer tools within the context of the page.
  • Cratis Arc Identity Cookies: The Extension may access and remove the Cratis Arc .cratis-identity cookie on configured Cratis Arc application or backend origins when you change the active Lens user or tenant. Cookie values are not stored, transmitted, analyzed, or shared by the Extension.

2. How We Use Your Information

We use the information collected to:

  • Provide and improve the functionality of the Cratis Lens Extension
  • Store your preferences and settings to enhance your user experience
  • Enable communication with your Cratis Arc backend services (if configured)
  • Troubleshoot technical issues and improve extension compatibility
  • Comply with legal obligations

3. Data Storage and Security

3.1 Local Storage

  • Your data is stored locally on your device using Chrome's storage APIs
  • We implement industry-standard security practices to protect stored data
  • You maintain full control over your local data and can clear it at any time through Chrome's settings

3.2 Data Transmission

  • Data is only transmitted to external services when you explicitly configure the Extension to connect to a Cratis Arc backend
  • All communication with external services should occur over secure (HTTPS) connections
  • We do not sell, trade, or rent your personal information to third parties
  • The Extension does not transmit cookie values to Cratis or any third party

3.3 Cratis Arc Backend Communication

  • If you configure the Extension to connect to a Cratis Arc service, that service's privacy policy will govern the handling of data transmitted to it
  • You are responsible for reviewing the privacy policy of your Cratis Arc service provider

4. Third-Party Services

The Extension may communicate with:

  • Your configured Cratis Arc backend service (if applicable)
  • Chrome APIs for storage and browser integration

We do not intentionally share your information with unaffiliated third parties.

5. Your Privacy Rights and Controls

5.1 Data Access and Control

  • You have full control over what data the Extension can access on your device
  • All data stored by the Extension is stored locally and can be deleted at any time by:
    • Clearing the Extension's data through Chrome's Site Settings
    • Uninstalling the Extension
    • Using Chrome's "Clear browsing data" feature

5.2 Permissions

  • The Extension requests specific Chrome permissions to function. You can review these in the Chrome Extension Details page
  • Revoking any permissions will limit the Extension's functionality accordingly

5.3 Chrome Sync

  • The Extension stores Lens settings in Chrome's local extension storage and does not use Chrome sync for Lens settings

6. Children's Privacy

The Extension is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will delete such information promptly.

7. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify users of any material changes by updating the "Last Updated" date of this Privacy Policy. Your continued use of the Extension following notification of changes constitutes your acceptance of the updated Privacy Policy.

8. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your privacy rights, please contact us:

Email: support@cratis.io

9. Additional Information

9.1 Permissions Explanation

The Extension requests the following Chrome permissions:

  • storage: To store your Extension settings and preferences locally on your device, using chrome.storage.local only. The Extension does not use Chrome sync for its settings.
  • scripting: To inject a read-only detection script into the page you are inspecting, in order to determine whether it is a Cratis Arc application and to read its Arc configuration and observable-query diagnostics. The script runs only while the Lens popup is open, only against the tab you are viewing, and never modifies the page.
  • cookies: To remove the Cratis Arc .cratis-identity cookie from configured Cratis Arc origins when the active Lens user or tenant changes, preventing stale development identity from being reused. The Extension reads only that cookie's name and scope in order to remove it; it does not read, store, transmit, analyze, or share cookie values.
  • declarativeNetRequest & declarativeNetRequestWithHostAccess: To add the Cratis Arc identity and tenancy headers to matching requests. Rules are scoped to the detected Arc page origin or the configured Arc backend host; when neither is configured, the Extension installs no rules at all and adds no headers to any request.
  • Host Permissions (<all_urls>): To support developer-configured local or remote Cratis Arc application origins. This breadth is required because the Arc application under development can live on any origin the developer chooses; it is not used to observe general browsing.

9.2 Data Retention

  • Local data is retained as long as you use the Extension or until you manually delete it
  • Data transmitted to Cratis Arc services is retained according to that service's data retention policies

9.3 Compliance

  • This Extension complies with the Chrome Web Store policies regarding privacy and data collection
  • We are committed to maintaining the highest standards of privacy and data protection

By using the Cratis Lens Extension, you agree to the terms of this Privacy Policy.