ReproKit Privacy Policy
ReproKit is a browser extension that assembles bug reports from on-page technical context. This policy explains, plainly, what it captures, where that capture stays, and what — if anything — ever leaves your machine.
In short
- Everything ReproKit captures is stored locally in your browser. Nothing is uploaded to us or to any third party.
- ReproKit has no backend server. It cannot see your data, because there is nowhere for that data to go.
- A capture only leaves your device when you personally click Copy, Download, or Export.
- Password fields are never captured — not redacted afterward, never read in the first place.
- You can delete any or all saved reports at any time from the extension's history view.
1. Scope
This policy covers the ReproKit browser extension only — its popup, side panel, options page, background service worker, and content scripts. It does not cover any third-party website you use ReproKit on, or any issue tracker (Jira, Linear, GitHub, Slack, etc.) you choose to paste an exported report into.
2. What ReproKit captures
ReproKit only captures data while you have started a recording session — never in the background otherwise. During a session, on the tab you're testing, it may record:
All of the above is generated by code running inside your own browser, reading only the page you're actively testing. None of it is transmitted anywhere by ReproKit itself.
3. Where your data lives
Captured sessions and settings are written to your browser's local extension storage (chrome.storage), on your device. ReproKit does not operate a server, does not sync your data to any cloud account, and has no analytics or telemetry pipeline of any kind. There is no infrastructure on our side that ever receives what you capture.
A report leaves local storage only when you take an explicit action: clicking Copy (to your clipboard), or Download / Export (to a file on disk). What you then do with that file or clipboard content — paste it into a ticket, email it, post it in Slack — is outside ReproKit's control and this policy.
4. Automatic redaction
Before anything is shown in a report, ReproKit strips certain patterns automatically and always: bearer tokens, JWTs, AWS access keys, PEM-encoded key blocks, and query-string parameters that look like secrets. You can additionally turn on redaction of email addresses and card-like numbers in Settings.
You can remove or edit any step, console line, or network entry from a report prior to copying it.
5. Browser permissions
ReproKit requests broad-looking permissions because a bug can occur on any site you're debugging. Each one is used only for local capture — not for tracking, advertising, or data collection:
None of these permissions are used to collect data for us — only to let the extension do its job inside your own browser.
7. Retention & deletion
Saved reports remain in local browser storage until you delete them, up to the free-tier history limit (the oldest report is dropped once that limit is reached). You can delete a single report, or clear your entire history with confirmation, from the extension's history view at any time. Uninstalling the extension removes all locally stored ReproKit data along with it.
8. Children's privacy
ReproKit is a developer tool not directed at children, and is not knowingly used to collect information from anyone under 13.
9. Changes to this policy
If this policy changes, the effective date at the top of this page will be updated and, for material changes, noted in the extension's release notes. Continued use of ReproKit after a change constitutes acceptance of the revised policy.
10. Contact
Questions about this policy or how ReproKit handles data: