Privacy Policy
Last updated 7 September 2026
1. Does my source code leave my machine? No.
That is the question that matters most, so it goes first. Inspectro inspects your app entirely on your own computer. Your source code, file contents, file paths, component names, prop values, network payloads and console output are never sent to us or to anyone else. There is no upload step and no cloud analysis — we could not look at your project even if we wanted to.
- The extension reads files from your open workspace to build the component tree and to jump to source. What it reads stays inside your editor.
- A small server on your own machine sits between your browser and your dev server, and adds the Inspectro agent to the pages your dev server already serves. Your pages and your app's requests never pass through any server of ours.
- The agent runs inside your own application, in your own browser tab. It reports what it finds back to your editor over a connection that never leaves your machine.
- The DevTools panel you open is served from that same local server. It is a page on your machine talking to your machine.
- If you use the environment sign-in helper, the extension calls the token endpoint you configured yourself. That is your infrastructure, and we never see it.
2. What we collect, and why
Six things: usage events from the extension, page views and reading activity on this website, claps you leave on an article, error reports when something breaks, whatever you type into the website, and the website's own server logs. We do not sell data, we do not use it for advertising, and we set no advertising or cross-site tracking cookies.
- Usage events from the extension, so we can see which features get used and which ones fail. Feature and command names, tab switches, counts such as how many accessibility issues or network requests a session had, and fixed option values such as the framework we detected. We do not send file paths, component names, prop values, URLs, request or response bodies, console text or source code. The extension allows only numbers, true/false values and short pre-set words off your machine, and replaces anything longer or free-form before it is sent.
- What identifies a usage event: the random per-machine identifier your editor already generates, plus a random identifier for that editing session. Not your name and not your email. As with any request over the internet, PostHog sees the IP address it arrives from — so these events are pseudonymous rather than truly anonymous, and we would rather say that than claim more than we can deliver.
- Attached to every usage event: the Inspectro version, your editor version, your operating system and processor architecture, and whether the build is a development or a production one.
- Page views and reading activity on this website, so we can tell how many people actually read what we publish. Which page was viewed, where the visit came from, and on an article: how far down it you scrolled, whether you pressed play on the narration, and whether you pressed share — we record that you pressed it, not where anything went. Not your name and not your email.
- What identifies website activity: a random identifier kept in your browser's own storage, so a second page view is not counted as a second person. No cookie is set for it, and clearing your browser data resets it. If your browser sends a Do Not Track signal we collect no analytics from your visit at all — though our server still writes the ordinary request log described below, as any web server does. As with any request over the internet, PostHog sees the IP address it arrives from.
- Claps you leave on an article. We store the article, how many claps you left, and when — against a one-way hash of your IP address mixed with a secret only our server knows. That is there to stop one person clapping a thousand times, not to recognise you: we cannot turn the stored value back into your address, and it is not linked to anything else about you.
- Error reports, when Inspectro itself breaks. Section 3 sets out exactly what one contains and what is stripped out of it.
- Whatever you type on the website. If you join the waitlist we store your email address, plus your name and interest if you give them, and the optional role, team size, framework and free-text answers on the thank-you screen — all optional, and asked only after your signup is already saved. If you use the contact form we store your name, email and message so we can reply.
- Ordinary web server request logs for the website, which include IP addresses.
3. Error reports, and what we take out of them
When Inspectro breaks — the extension, the DevTools panel or this website — an error report goes to Sentry, in its European Union region, so we can fix it. Errors only: no performance tracing, no profiling, no session replay, no logs. Nothing is sent while things are working. Every report is stripped before it leaves, and here is what that actually means.
- Removed from every report: all cookies, all request headers including authorisation headers, the request body, the server's hostname, and the user identity Sentry would otherwise attach. No user ID, no email address and no IP address is put into a report.
- No source code goes out — not yours, and not ours. The setting that would attach the lines of code surrounding a crash is switched off, so a report carries only a file name, a function name and a line number.
- Stack traces keep function names, line and column numbers, but the values of variables at the moment of the crash are deleted, and file paths are rewritten to be relative — no directory tree and no account username leaves your machine.
- Web addresses keep their path and their parameter names, but every parameter value is replaced. A link carrying an email address arrives with the email replaced by a placeholder.
- Whatever text is left is then scanned for anything shaped like an email address, a token, a password or a long secret, and those are replaced too.
- The agent that runs inside your own application has no error reporting in it at all. That is deliberate: a stack trace from inside your app could carry your source, your props and your internal hostnames, so it is never instrumented.
- Sentry's servers see the IP address a report arrives from, as any server does. We do not put it in the report, and we have switched on Sentry's setting that discards incoming IP addresses. What Sentry does on its own systems is governed by Sentry, not by us.
4. Who else can see it
We do not sell this data and we do not use it for advertising. A short list of service providers processes it on our behalf, and we send each one only the part it needs to do its job. Each runs on its own terms and its own privacy policy, which we do not control.
- PostHog, European Union region — extension usage events, and this website's page views and reading activity. Its requests are routed through our own domain, so a content blocker does not silently drop some readers and leave us with numbers we cannot trust.
- Sentry, European Union region — error reports.
- Google Cloud Run, Singapore — hosts this website and keeps its request logs.
- Neon, Singapore — the database that holds waitlist entries and contact messages, and account records once accounts exist.
- Zoho Mail — our mailbox, so anything you email us lives there. ZeptoMail would send transactional email, and is not switched on yet.
- Razorpay would be added if and when paid plans launch. Nothing is charged today: Inspectro is free in early access, billing is not live, and we hold no payment details of any kind.
- This site measures page views and reading activity, as section 2 describes. It loads no advertising scripts, records no sessions, captures nothing you type, and sets no tracking cookies — the identifier it uses lives in your browser's own storage. Our fonts are copied onto our own servers when we build the site, so a page load here does not fetch anything from Google's font servers. The site itself runs on Google Cloud Run, which is how Google sees the request logs described above.
5. How long we keep it
Where we control the clock, here it is. Where a third party stores the data, we say so rather than quote a number we have not checked.
- Waitlist entries: until we launch, or until you ask us to remove yours, whichever comes first.
- Contact form messages: while we still need them to deal with what you wrote to us. Ask and we will delete yours sooner.
- Website request logs: our host keeps these for roughly 30 days by default, then they age out.
- Usage events and error reports: these are stored by PostHog and by Sentry under the retention period set on our projects with them. Email us and we will tell you what that currently is.
- Anything on your own machine — settings, caches, sign-in tokens — stays on your machine. We never receive a copy, so there is nothing on our side to delete.
6. How to turn it off, and how to get it deleted
Telemetry is a setting you control, and it is a real switch: turning it off stops collection completely, with no 'essential' channel quietly carrying on. Deletion is an email to a human — Inspectro is one person, so there is no self-service export button, and we are not going to pretend otherwise.
- In your editor's settings, turn off inspectro.telemetry.enabled. It is on by default. Turning it off stops usage events and error reports immediately.
- If your editor's own global telemetry setting is off, Inspectro sends nothing regardless of its own setting. Both have to be on before any telemetry leaves your machine.
- For this website, switch on Do Not Track in your browser and our analytics collect nothing from your visit — the site checks the signal before it measures anything. Server request logs are not covered by that signal, because they are written before any of our code runs. Clearing your browser data also clears the random identifier described in section 2.
- To ask for a copy of what we hold, to have it corrected, or to have it deleted, email hello@inspectro.dev. One person reads that mailbox and will deal with it. We would rather not quote a turnaround time we cannot guarantee, so we have not.
- Waitlist entries and contact messages are easy to find and delete. Usage events are not linked to your identity, so we generally cannot isolate 'your' events — switching telemetry off is what stops any further collection.
7. Accounts, sign-in and payments
Accounts are switched off in production today. There is no sign-in, and there is no account data. This section describes what will happen when accounts are turned on, so it is on the record before anything starts.
- You will sign in with GitHub, GitLab or Bitbucket. We would receive your name, email address and avatar from the provider, plus the tokens needed to keep the session alive. We would not see your provider password, and we would not ask for access to your repositories.
- Stored in our database: your name, email, avatar, the provider link, session records including the IP address and browser of the session, and your plan.
- Connecting an editor sends a device label so you can recognise the grant later — your editor name plus your computer's hostname.
- Tokens are held in your editor's encrypted credential store, on your machine. One-time codes and refresh tokens are kept only as hashes on our side.
- You will be able to revoke a connected editor from your account page, which invalidates that device's tokens.
- Paid plans do not exist yet. If they launch, payments would be handled by Razorpay under its own terms, and this page will describe what that means before anything is charged. Today nothing is charged and we hold no payment details.
8. Age
Inspectro is a tool for professional software developers and we do not direct it at children. Under India's Digital Personal Data Protection Act, 2023, anyone under 18 is a child, and handling a child's personal data lawfully needs verifiable consent from a parent or guardian. We have no way to obtain or check that consent, so we do not knowingly collect personal data from anyone under 18.
- Please do not join the waitlist, use the contact form or create an account if you are under 18.
- If you are a parent or guardian and believe a child's data has reached us, email hello@inspectro.dev and we will delete it.
- This is a data-protection obligation about consent, not a judgement about who is allowed to write code.
9. Your rights, and the law that applies
You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. One email does all three — see section 6 for how, and what we can and cannot isolate.
- Our legal basis is your consent for the waitlist and for anything we send you, and our legitimate interest in replying when you write to us through the contact form.
- If you are in India, you can raise a complaint with the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.
- If you are in the EU or the UK, the GDPR may apply to you as a visitor to this site. We are based in India and have not appointed an EU or UK representative, so email us first and we will do our best to resolve it directly.
- This policy is governed by the laws of India.
10. Who we are, and changes to this policy
Inspectro is operated by Hema Sai Charan Kothamasu, trading as Inspectro — one individual, a sole proprietor based in Hyderabad, India, not a registered company. If you write to us, that is who reads it.
- Email hello@inspectro.dev for anything, privacy requests included. A postal address is available on request.
- Changes to this policy are posted on this page, and the date at the top changes with them. If a change materially affects what we collect, we will say so rather than quietly edit.
- Effective 7 September 2026.
