Privacy Policy
Last updated 28 July 2026 · Flora extension 0.1.0
The short version. Flora reads the page you are looking at, only when you ask it to, and turns it into a written specification. To do that, the measurements and screenshots of that page are sent to our service and then to Anthropic, which writes the specification. We also keep your Google account details and a short profile so you have an account and we can count your credits. We do not track your browsing, we run no analytics, and we sell nothing to anyone.
1. Who we are
Flora is published by [LEGAL ENTITY — name, form, registration number], [REGISTERED ADDRESS]. For anything in this document, including requests about your data, write to stevenkuti20@gmail.com.
For the purposes of the GDPR we are the data controller for the data described below.
2. What Flora does, in order
Understanding the data means understanding the sequence, so here it is:
- You open the side panel and click a capture mode.
- The extension reads the structure and styles of the active tab only, and takes one or more screenshots of it.
- Those measurements are assembled into a text document. Nothing has left your browser at this point.
- If you ask for a written specification, that document and its screenshots are sent to the Flora service, which forwards them to Anthropic’s API. The result comes back and is copied to your clipboard.
Step 4 is the only step that sends anything anywhere, and it only happens in the paid modes. The free Simple component mode never contacts our service or Anthropic.
3. What we collect, and why
3.1 Data you give us
| Data | Why | Where it is stored | Kept for |
|---|---|---|---|
Google account identifier (sub), email address, first and last name | To sign you in, and to recognise the same person if the address changes | In your browser (chrome.storage.local); the email, names and trade in our sign-up database | Until you uninstall, or until you ask us to delete the record |
| Your trade — one of developer, agency, freelancer, solo founder | To know who the product is being built for. A closed list, not a free text field | Same as above | Same as above |
| Payment details | We never see them. Payments are handled entirely by Whop | Never stored by us | — |
We request three Google scopes and no more: openid for the stable account identifier, email for a verified address, and profile for your name. Nothing else is read from your Google account — no contacts, no files, no calendar.
3.2 Data the extension generates
| Data | Why | Where it is stored | Kept for |
|---|---|---|---|
| An installation identifier, generated at random in your browser | To count credits against an installation. It is not derived from anything about you or your machine | In your browser, and on our service next to your credit balance | Until you uninstall or clear the extension’s storage |
| Credit balance, and a record of checkouts you opened | To know what you have paid for | In your browser, and authoritatively on our service | As long as the balance exists |
| Your settings — output target, automatic mode, motion preference | So the extension behaves the way you left it | In your browser only. Never sent anywhere | Until you uninstall |
3.3 Content of the pages you capture
This is the part that matters, so it is stated plainly. When you run a capture, Flora reads the DOM and the stylesheets of the active tab and takes screenshots of it. If the page you are capturing contains personal data — a customer name in a CRM, an address in a webmail, an amount in a banking page — that data is in the measurements, and in the paid modes it is sent to our service and to Anthropic.
Flora cannot tell a public marketing page from your own inbox. You decide what to capture. Do not capture a page whose content you are not allowed to send to a third party.
| Data | Why | Where it is stored | Kept for |
|---|---|---|---|
| Measurements of the active tab: element structure, computed styles, CSS rules, fonts, inline SVG icons | They are the product — the specification is written from them | In memory. Sent to our service and to Anthropic in the paid modes | Not stored by us once the request completes |
| Screenshots of the active tab (up to 15 for a page capture) | Values express layout badly; a photograph shows what sits beside what | Same as above | Same as above |
| The specification Flora produced | So closing the panel does not lose your work | chrome.storage.session — in your browser, in memory | Deleted when you close the browser. Deliberately never written to disk |
| The measurements themselves, once the specification is written | — | Nowhere. Not kept, not even locally | Discarded |
3.4 What we deliberately do not collect
- No browsing history. Flora reads one tab, at the moment you ask, and that is the only tab it can read. It does not hold the
tabspermission, so it cannot enumerate your open tabs or their addresses. - No analytics, no telemetry, no advertising identifiers. There is no third-party analytics script anywhere in the extension.
- No sale or sharing of personal data for advertising, profiling or any other purpose.
- No link destinations. When a capture becomes a specification, every
hrefis emptied on purpose — a captured URL belongs to the site that was measured, not to us.
4. Who else sees the data
Four third parties, each for one thing:
| Who | What they receive | Why |
|---|---|---|
| Google LLC | The sign-in request. In return we receive your identifier, address and name | Sign-in — policy |
| Anthropic PBC | The measured document and its screenshots | Writing the specification — policy |
| Supabase | Your address, first and last name, and trade | Storing the sign-up — policy |
| Whop | Whatever you enter on their checkout page. We never see your card | Payments — policy |
Our own service runs on a server rented from Hetzner in Nuremberg, Germany. Google, Anthropic, Supabase and Whop are established in the United States, so using Flora involves a transfer of data outside the European Economic Area. We rely on those providers’ own transfer safeguards; their policies are linked above.
Anthropic’s commercial API terms state that data sent to their API is not used to train their models. We rely on that commitment; it is theirs and not ours, and their policy is its authoritative statement.
5. Why we are allowed to do this
Under the GDPR, our legal bases are:
- Performance of a contract — for your account, your credits, and sending a capture to be written up. Without this the product does not work.
- Legitimate interest — for knowing which trades use Flora, so it is built for the people who use it. A closed four-value field, nothing more.
- Consent — for signing in with Google, which you start yourself and can decline.
6. Permissions, and why each one exists
The extension asks Chrome for the following. Each is here for a reason we can name; none is speculative.
| Permission | Why it is needed |
|---|---|
activeTab | To read the page you are capturing, at the moment you ask |
scripting | To inject the reader into a tab that was already open before the extension was installed, and to read an animation library’s own registry so a duration is measured rather than approximated |
sidePanel | Flora’s whole interface is a side panel |
storage | Your settings, your credit balance, and the specifications produced |
clipboardWrite | To copy the result. The write is issued from the page because that is the document holding focus after a click |
identity | Sign in with Google |
<all_urls> | The broadest one, so here is the whole reason: a stylesheet served from another domain cannot be read from inside the page — the browser blocks it. Without re-fetching those files, every hover state, breakpoint and animation of the page you captured is silently lost, which is exactly what Flora exists to measure. It is used for that, and to reach our own service |
7. Your rights
You can ask us for a copy of your data, for it to be corrected, deleted, or for its use to be restricted. Write to stevenkuti20@gmail.com and we will answer within one month.
Most of it you can also do yourself, immediately and without asking us:
- Everything stored in your browser disappears when you remove the extension from
chrome://extensions. - The specifications disappear when you close the browser.
- Your Google authorisation can be revoked at myaccount.google.com/permissions.
The sign-up record in our database is the one thing only we can delete. Ask, and it goes.
If you are in the EU and think we have handled this badly, you may complain to your national data protection authority — in France, the CNIL.
8. Security
- Traffic to our service is encrypted in transit (HTTPS).
- The Anthropic API key never enters the extension. It exists only on our server, in a file readable by one system account. An extension package cannot leak it because it is not in it.
- The service listens on the local interface only, behind a reverse proxy, and does not run as an administrator.
- The database policy allows inserting a sign-up and nothing else — the key shipped in the extension cannot read the table back.
No system is perfect. If you find a weakness, tell us at stevenkuti20@gmail.com before telling anyone else, and we will credit you if you want us to.
9. Children
Flora is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes
If we change what we collect or who receives it, we will change the date at the top of this page and, for anything material, tell you inside the extension before it takes effect. We will not quietly widen the scope.
See also the Terms of Service, which cover what you may and may not capture.