Privacy Policy

Last updated 12 September 2026

This describes what the Caveat browser extension sends, stores, and never does. It's written to match what the code actually does, not as boilerplate — if this ever drifts from the extension's real behaviour, that's a bug in this page, not a change we made silently.

What Caveat sends

What Caveat never does

How the trust score works

The free-tier score is produced by a rule-based analysis of rating distribution and review language running on our server — no AI, no third-party model. The Pro-tier deep analysis sends the same public review data to Anthropic's Claude API to produce it. In both cases, only the public data listed above is sent — nothing about you as a person.

The score is our automated opinion about a pattern in publicly visible reviews. It is not a finding of fact about any seller or product, and it can be wrong. If you're a seller and believe an analysis is inaccurate, see our dispute process.

What's stored, and where

On your device

Your own Anthropic API key if you've set one (BYO key), and ExtPay's own subscription-state storage (from ExtensionPay, our billing provider). Both clearable any time from the extension's settings page.

On our server

A cache of past analyses, keyed by product listing (not by you) — refreshed every 30 days on the free tier, 14 days on Pro. If you start a trial or subscribe, ExtensionPay (our payment processor) holds your billing details; we never see or store your card number.

No tracking

No user analytics, no ad tracking, no third-party trackers of any kind.

Deleting your data

Open the extension's settings page and use "Delete local data" to clear your BYO API key and ExtPay state from your device. To close a subscription or request server-side data deletion, email [email protected].

Changes to this policy

If this changes materially, the "Last updated" date above will change, and we'll note what changed here.

Contact

[email protected]