Privacy Policy
What COR Lens collects, what it doesn’t, and the choices you have.
TL;DR: COR Lens generates test-automation locators. We collect product-usage analytics and diagnostics to improve the product. We do not collect full page contents, screenshots, or your general browsing history. When you save a locator, we store the selected element metadata needed to make that locator useful, such as tag, selected attributes, locator strategies, and limited text context. If you use AI search with your own API key, your query and sanitized element context go directly to your chosen AI provider, never through us.
1. Overview
COR Lens (“the Extension”) is a Chrome extension that helps QA engineers and developers generate element locators for test automation. This policy explains what data the Extension collects, how it is used and shared, and your choices. It is provided by COR Labs (“we”, “us”).
2. Data We Collect
2.1 Product analytics
To understand how COR Lens is used and to improve it, the Extension sends usage and diagnostic events to PostHog, our analytics provider and data processor. These events include:
- Lifecycle events (install, update, sign-in, sign-out)
- Feature-usage events (element inspected, locator generated/copied/saved, search run, page scanned, target framework changed, onboarding progress)
- Non-identifying properties about those actions (e.g. locator count, quality score, selected framework, query length, match counts)
- Error and diagnostic reports used to fix crashes and bugs
- Approximate location (country, region, city) derived by our analytics provider from your IP address — never precise location, and the Extension never asks for location permission
Before you sign in, these events are associated with a random device identifier stored in your browser — not with you personally. When you sign in, that identifier is linked to your account so we can understand product usage per user. We do not include the content of the pages you inspect in these events.
2.2 Account and cloud data (only when signed in)
Signing in is optional. If you create an account and sign in, the following is stored on COR Labs servers:
- Account details from your COR Labs profile (such as name, email, and organization)
- Locators, pages, and projects you choose to save to the cloud, including selected element metadata needed to generate and review those locators
If you never sign in, no account or cloud data is created and locators you capture stay in your browser’s local history.
2.3 Data stored locally in your browser
- Settings: your preferences (theme, framework, AI configuration, etc.)
- AI API key: if you provide your own key, it is stored in Chrome storage on your device and is not sent to us
- Local locator history: locators you capture without signing in, including page URL/title and selected element metadata for saved local entries
- Session/auth tokens and a local buffer of recent analytics and error entries used for diagnostics
2.4 Website and app analytics
Our website and COR web app may also use PostHog to understand traffic, onboarding, and product usage. This can include page views, clicks on calls to action, referral parameters such as ?ref=extension, device and browser information, and account-level product events after you sign in. Website analytics may use cookies or local storage. We use this information to improve COR, measure reliability, and understand which product flows are working.
2.5 What we do NOT collect
- Full page contents or screenshots of the pages you browse or inspect
- Your general browsing history for advertising, profiling, or resale
- Advertising identifiers; we do not sell your data or use it for advertising
3. Permissions Explained
The Extension requests the following permissions:
- activeTab — inspect elements on the tab you are actively using
- storage — save your settings, local history, and session on your device
- scripting — inject the inspection script and evaluate locators against the live page
- tabs — route inspection results to the correct tab, read the active page URL/title for saved locator context, and match the current URL to a saved project page
- clipboardWrite — copy generated locators to your clipboard
- debugger — use the Chrome DevTools Protocol to power native element picking across shadow DOM and iframes. It attaches only while you are actively inspecting and detaches immediately afterward; Chrome shows a banner while it is attached.
- host access (all sites) — the app you are testing can live on any domain, so inspection and navigation detection must run wherever you point COR Lens. Page scripts support user-facing locator features; page content is not transmitted to COR Labs except when you explicitly save locator data or sign in and sync it.
- webNavigation (optional) — enumerate frames for cross-frame AI search; requested only if you use that feature.
4. AI Features
If you enable AI-powered search:
- Your search query and a sanitized list of visible page elements are sent to your chosen AI provider (OpenAI or Google Gemini) so the provider can identify likely locator matches
- Sanitized element context may include tag names, selected attributes, role/label-style accessibility information, match counts, and limited text snippets needed to distinguish elements
- You provide your own API key, which is stored locally on your device and is not sent to COR Labs
- These AI requests go directly from your browser to the provider; they do not pass through COR Labs servers, and we do not receive your key, your queries, or the element context sent to the provider
- Please review the privacy policies of OpenAI and Google
5. How We Share Data
We do not sell your data. We share it only with service providers who process it on our behalf to run the product — principally PostHog and our own hosting infrastructure — and where required by law. AI requests go directly to the provider you configure, as described above.
6. Chrome Web Store Limited Use
COR Lens uses extension user data only to provide, maintain, secure, and improve its locator-generation and locator-management features. We do not sell extension user data, use it for personalized advertising, transfer it for unrelated purposes, or use it to determine creditworthiness or lending eligibility. Human access to user data is limited to cases where you ask for support, where access is necessary for security or legal compliance, or where data has been aggregated and anonymized for internal operations.
7. Data Security & Retention
- Local data is stored using Chrome’s storage APIs on your device
- Data in transit is protected with HTTPS/TLS
- We retain account, cloud, and analytics data for as long as needed to provide and improve the product, or until you delete your account or request deletion
8. Your Rights & Choices
- Use the Extension without signing in (no account or cloud data is created)
- Use it without AI features (no requests to AI providers)
- Clear local data by removing the extension via Chrome
- Request access to or deletion of your account and associated data by contacting us. Depending on your location, you may have additional rights under laws such as the GDPR or CCPA.
9. Children’s Privacy
The Extension is intended for professional use and is not directed to children under 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this policy from time to time. Changes are reflected in the “Last updated” date above, and significant changes will be noted in the extension’s update notes.
11. Contact
Questions about this policy or our data practices? Email [email protected].