Skip to content
Tintstep
ProductPricingHelpSign inView installation status

Privacy Policy

Effective date: 27 September 2026

Wren Foundry operates Tintstep, the Chrome extension and the website at tinstep.wrenfoundry.com. This policy states what stays on your computer and what the website stores. Tintstep is a product of Wren Foundry.

1. Who we are

Wren Foundry decides why account, billing, support, and site-log information is used. Stripe decides the purposes for which it handles a card number entered on Stripe's own pages. Stripe also processes the subscription records Wren Foundry sends it.

Write to privacy@wrenfoundry.com. Mailed notices go to [postal address].

2. The extension and your pages

When you click the Tintstep icon, use its shortcut, or start a page scan, the extension reads computed styles on that page. The read can include colors, fonts, spacing, selectors, contrast figures, asset URLs already on the page, inline SVG markup, and the page URL.

Those values stay in the browser. Wren Foundry does not receive them. Wren Foundry does not use them for advertising. Chrome clears session storage when the browser session ends. The extension clears the current page's values when you leave the page, close the tab, or clear the selection. A license token, if you connect one, and your display preferences stay on the device until you remove them or remove the extension.

The extension asks Chrome for access to the page when you invoke it. It does not request a standing permission to read every site. Its network permission is limited to the Tintstep site and is used to connect a license. That request sends a pairing code or a device credential. It does not send the page URL, the CSS, or the copied color.

The extension does not load analytics.

3. Information the website collects

You provide, or the service creates, these categories when you use the website:

  • Identifiers: email address, an optional display name, an account identifier, and a device label.
  • Credentials: a password, stored as a hash by the authentication provider. Wren Foundry does not keep the password itself. A device refresh token is stored as a hash.
  • Commercial information: subscription status, period end, price identifier, invoice amount, currency, invoice status, and a hosted invoice link. Card numbers and the CVC are entered on Stripe's pages. Wren Foundry does not store them.
  • Customer content: support messages you send, including the subject and the body.
  • Consent records: whether you asked for product notes, and whether you allowed website analytics. The analytics record uses an opaque visitor key, not your email.
  • Internet and device activity on this site: request time, path, status, duration, and IP address in the host log. If you turn analytics on, Datadog records page views of tinstep.wrenfoundry.com, including the path and the referrer host.

Wren Foundry collects this information from you, from your browser, from Stripe when a subscription or invoice changes, and from the companies that host and deliver the site. Wren Foundry does not collect browsing history as a log, the text of pages you inspect, your contacts, precise location, advertising identifiers, photos of you, or biometric data. Wren Foundry does not build a profile of the websites you inspect.

4. Why information is used

PurposeCategoriesBasis, where GDPR or UK GDPR applies
Provide the extension on your devicePage styles, which Wren Foundry does not receiveNot Wren Foundry's processing. The reading happens on your device.
Create and secure the accountIdentifiers, credentialsContract
Take payment and keep a license in forceCommercial information, identifiersContract
Send verification, receipts, payment failures, and deletion mailIdentifiers, commercial informationContract
Answer supportCustomer content, identifiersContract, or legitimate interest in answering a person who writes before creating an account
Send product notesIdentifiersConsent. You can withdraw it on the Email page or through the unsubscribe link.
Secure the site, prevent abuse, and keep logsInternet activityLegitimate interest in running a safe site
Analytics you opt intoInternet activity on this siteConsent
Keep invoicesCommercial informationLegal obligation to keep tax records
Answer a privacy requestThe categories the request coversLegal obligation

Wren Foundry does not use personal information for a purpose that is incompatible with this table. A legitimate interest named in the table can be opposed. Write to privacy@wrenfoundry.com. Wren Foundry will stop that processing unless the law requires it or the interest overrides the objection.

5. Cookies and analytics

The Cookie Policy names the cookies. The session cookie is required to stay signed in. The consent cookie remembers the analytics choice. Analytics stay off until you choose Turn analytics on. The banner also offers Keep analytics off.

6. Who receives information

The companies on the subprocessors page process personal information for Wren Foundry:

  • Vercel hosts the website and the API and holds request logs.
  • Supabase stores the database and authentication hashes.
  • Stripe processes payments. Stripe holds the card data entered on its pages.
  • Bird delivers email and receives the recipient, the subject, and the body of the message being sent. The delivery log Wren Foundry stores does not keep the HTML body.
  • Datadog stores operational logs and, only after you consent, site analytics. Those logs exclude email addresses, tokens, and message bodies.
  • Cloudflare provides DNS. A DNS query is not the contents of an account.

Staff with a support or owner role can see account and support records to do that job. They cannot see page styles, because Wren Foundry does not have them.

Wren Foundry may disclose information if the law requires it, or to a buyer of the business, under a duty to use it only for the purposes in this policy. Wren Foundry will email account holders if a new owner will handle their information, unless the law forbids that notice.

7. Sale, sharing, and advertising

Wren Foundry does not sell personal information. Wren Foundry does not share it for cross-context behavioral advertising. Wren Foundry does not allow a third party to use it for targeted advertising. Wren Foundry does not use it to determine creditworthiness.

8. Retention

InformationHow long
Page styles on your deviceUntil you navigate away, close the tab, clear the selection, end the browser session, or remove the extension
Account, including email and display nameUntil you delete the account
Device row and hashed refresh tokenUntil you remove the browser or delete the account
Pairing code hash10 minutes, then purged within a day
Support messages24 months after the ticket closes, or sooner if you delete the account
Email delivery log, without the message body90 days
Privacy-request record24 months
Staff access log that names an account24 months
Server logs30 days
Consent cookie365 days
Consent record12 months
Invoice records7 years after the invoice date

Deleting an account does not delete invoice records. A deleted account can remain in a backup until that backup expires. Wren Foundry does not restore a deleted account from a backup except to recover the service from an incident.

9. Security

Wren Foundry uses TLS for the website, hashed passwords, hashed device tokens, row-level access control on customer tables, and signature checks on payment notifications before a payload is trusted. Logs exclude email addresses, tokens, and message bodies. No method of storage is perfect. Page styles are only as protected as the computer they sit on.

To report a security problem, write to security@wrenfoundry.com.

10. International transfers

Vercel, Supabase, Stripe, Bird, Datadog, and Cloudflare may process the information they receive in the United States. Page styles are not part of that processing, because Wren Foundry does not receive them.

If you are in the EEA, the United Kingdom, or Switzerland, you may complain to the supervisory authority where you live.

11. Children

The website is not directed to children under 16. An account is for a person who is at least 18. The extension does not ask for an age, because it does not create an account. If Wren Foundry learns that an account belongs to a child, Wren Foundry will delete it.

12. Your rights

Depending on where you live, you can ask to access, correct, delete, or export personal information, to object to or restrict certain processing, to withdraw consent, and to appeal a refusal. You can complain to a supervisory authority.

A signed-in person can download account data from Export and delete the account from Delete. You may also write to privacy@wrenfoundry.com or use the contact form. Wren Foundry verifies a request by matching the email on the account, or by asking for information an impostor would not have. Wren Foundry completes the request within 30 days after verification.

You may appeal a refusal by emailing privacy@wrenfoundry.com with the subject Appeal within 45 days after the refusal. Wren Foundry answers the appeal within 45 days.

Wren Foundry will not discriminate against you for making a request. Wren Foundry may refuse a request the law allows it to refuse, and it will say why. Wren Foundry does not offer a financial incentive for personal information.

An authorized agent may submit a request with proof of authority, where the law requires Wren Foundry to accept an agent. Wren Foundry may still ask you to confirm the request.

California residents: Wren Foundry does not sell or share personal information as those terms are used in the CCPA. Wren Foundry does not use sensitive personal information to infer characteristics. You may use Export, Delete, or email to request access, correction, or deletion.

Residents of other US states that grant a privacy right may use the same tools and the same email address.

13. Automated processing

Tintstep has no AI feature. Wren Foundry does not use personal information to train an AI model. Applying the subscription status you purchased is a rules-based check on payment. It is not a decision that produces a legal or similarly significant effect beyond whether the two Pro files are available.

14. Changes

Wren Foundry will post a change on this page and change the effective date. If a change materially expands how account information is used, Wren Foundry will email the account before the change applies. When the extension's data practices change, Wren Foundry updates this policy and the Chrome Web Store privacy disclosure together.

15. Contact

Wren Foundry

[postal address]

privacy@wrenfoundry.com

wrenfoundry.com

Tintstep

Tintstep is made by Wren Foundry.

On this site

  • How it works
  • Install
  • Releases
  • About
  • Privacy
  • Terms
  • Subscription terms
  • Acceptable use
  • Cookies
  • License
  • Subprocessors
  • Data processing
  • Security
  • Contact