Privacy policy

Last updated 16 September 2026. Tweaksy is made by OptiCab Ltd, a company registered in England and Wales.

What the extension does with your data

Tweaksy lets you describe a change to a website in your account and applies that change in your Chrome. Your account holds your email, a hashed password (kept separately from everything else on the account), your changes (what makes the change, the text you typed to ask for it, the sites it applies to, who approved it and when, and up to three previous versions so you can undo), any requests waiting to be built, any notes you save about a site, a short record of each build (which AI model ran and how much text it processed, used for fair use and cost), and the list of computers logged in with the names you gave them. The extension keeps a copy of your changes on each logged-in computer so they apply without contacting us.

Nothing runs until you have approved it

When Tweaksy builds or changes something, the result is switched off everywhere until you approve that exact version, either in the extension (Keep it) or in your account. Until then it is only previewed in the tab it was built from, on the computer that built it. Any later change, or a change to where it applies, needs approving again. You can switch any change off at any time; the extension removes it from open tabs straight away and reloads any tab where behaviour, rather than appearance, had already run.

What we send to our server, and why

When you ask Tweaksy to create or change something, the extension sends the following to our server: the text of your request, the address of the page without anything after a question mark or hash, a structural snapshot of the page (element types, headings, button and field labels, table headers, class and id names, and short visible text fragments, capped at about 14,000 characters), and, if you pointed at an element, a copy of that element and its immediate surroundings. Any notes you have saved for that site or for a domain above it are sent with it. We send this so an AI model can build the change. It is processed by our AI provider (Anthropic) under their API terms and is not used to train models.

Before anything is sent, the extension leaves out hidden fields, password fields and what has been typed into text boxes, and shortens addresses. Our server then runs a second, best-effort pass over the whole request that removes typed values, hidden fields, text box contents, query strings, and anything shaped like a key, token, session id or card number. This is a safety net, not a guarantee: a snapshot can still include visible text from the page, such as names or amounts shown in a table, if that text is what you asked us to change. Do not use Tweaksy on a page showing information you would not want an AI provider to process. Snapshots are not stored; your request text and any notes are stored on your account as described above, and are deleted when you delete the change, the note, or the account.

The extension identifies itself with a device token issued when you log in, used to count seats on your plan and fair use per month. It checks in with our server every few minutes to fetch new changes; that check-in carries no page content and no browsing history. After a change is built, and if it later stops with an error on a page, the extension sends us a short result (how many things it found, the page address without its query string, and the error text if any). Page snapshots are only sent when a change is being built for a site you have asked to change.

Payments

Subscriptions are handled by Stripe. We never see your card number. We store your Stripe customer and subscription IDs on your account, and a record of which Stripe events we have already applied, so we can keep it active and let you manage or cancel the subscription.

Marketplace applications and purchases

If you apply as a creator, we store your chosen public name, introduction, country, individual or company selection, accepted terms version and application status. We review submitted automation descriptions and code. Approved listings show your public creator name, the supported website, description, purchase count and rating summary. Buyers' account email addresses are not shared with creators.

When paid sales open, we record orders, the purchased version, payment references, refunds, disputes, ratings and creator earnings so we can supply purchases, resolve problems and keep accurate accounts. Stripe collects identity, business and bank information directly during payout setup; Tweaksy stores the connected account identifier and its readiness status. We retain necessary transaction and earnings records for accounting, payment disputes and legal obligations, including where an account is closed. Contact hello@tweaksy.app about an application, purchase or your data.

Permissions the extension asks for

What we do not do

Enterprise enquiries

If you send an Enterprise enquiry, we use your name, email address, company, optional computer count and message to reply and discuss your requirements. Our email delivery provider, Resend, forwards the enquiry to our team inbox. The form does not create an account or subscribe you to marketing emails. Please do not include passwords or confidential customer information. Contact hello@tweaksy.app if you want to discuss or delete an enquiry.

Optional website analytics and cookies

If you accept optional analytics on tweaksy.app, we use Google Analytics to understand public-page visits, clicks through to our Chrome Web Store listing, completed sign-ups, checkout starts, trial starts, subscription payments, refunds and billing status changes such as cancellations or failed payments. Google processes this measurement data for us. Website measurement can include an Analytics cookie identifier, browser and device information, approximate location and the referring website. We send known page addresses and selected campaign labels, with sensitive URL parameters removed. A Store click records interest in the extension, not confirmation that it was installed. This website measurement is separate from the extension and does not collect activity on websites you modify with it.

With that permission, we also associate your Analytics identifier and consent with your Tweaksy account so our server can measure confirmed account and billing events from Stripe, including renewals when your browser is closed. Billing measurement can include the plan, amount, currency, tax and a pseudonymous transaction reference. We do not send your account email address, password, card details, Stripe checkout session identifier, change requests, saved notes or other websites' content to Analytics. If a browser blocks Analytics or its identifier is unavailable, those events are not linked through a made-up identifier.

Google Analytics does not load until you accept. You can use the website without accepting. We remember your choice for 180 days; Analytics cookies are used only after acceptance and expire after 180 days. After acceptance, selected campaign labels can be kept in this tab's session storage for up to 30 minutes so a visit to a guide can be connected to a later sign-up. Advertising measurement has a separate optional choice, which is off by default. Personalised advertising stays disabled.

If you also allow advertising measurement, Google may use an advertising click identifier from the current website address to connect an ad click with consented sign-up and billing events. This requires both choices to be accepted. We keep at most one validated click identifier in this tab for up to 90 days, within your consent period, and may associate it with your account on our server. We do not add old click identifiers to unrelated page visits or send them as custom Analytics event fields. Advertising measurement does not collect your extension activity.

Our expanded advertising choice also covers LinkedIn measurement. We load the LinkedIn Insight Tag only on selected public marketing and demonstration pages after you explicitly accept that choice. It uses cookies and browser information to match visits with LinkedIn members and measure advertising. We do not load it on sign-in, signup, account, administration or payment forms, or inside the extension. After a first successful payment, an optional, separate confirmation page can send LinkedIn a random event reference and the payment value and currency, only after our server verifies the payment and the advertising permission. It sends no email, account identifier, card details, requests or extension activity. Visitors who do not return after payment may not be measured by this browser-based conversion. Earlier advertising choices do not automatically enable LinkedIn; a new choice is required. We do not use this integration to create retargeting audiences. Read LinkedIn’s cookie policy and privacy policy.

Open at any time to withdraw permission, including after logging out. Rejecting analytics stops new browser collection (a page refresh unloads the LinkedIn tag when present) and clears accessible Analytics and advertising cookies, campaign labels and the saved advertising click. You can instead switch off advertising measurement while keeping analytics; this clears the advertising click and accessible advertising cookies and tells our server to stop advertising attribution. We keep narrow withdrawal tokens in this browser, separate from your login, so we can also tell our server to stop associated future account and billing measurement. If that request fails or you are offline, we retain it and retry when this browser reconnects or you next visit; server measurement stops when the withdrawal reaches us. These tokens can only withdraw analytics or advertising permission and cannot access your account. Withdrawal does not delete data already processed. Clearing all browser storage removes these tokens; you can sign in and reject analytics again, or contact us to withdraw account measurement.

Google may process data outside the UK under its applicable processing terms. Read how Google uses information from sites that use its services for more information. Contact us using the details below about data we hold or your privacy choices.

Referral offers

When you follow a referral link, we keep its code in this tab for up to 24 hours as functional signup information. This does not enable optional analytics or advertising. You can remove the selected referral before checkout. If you claim an offer, we keep the referring and referred account references, eligibility checks, payment status and credit history to operate and review the offer. Referrers see reward amounts and statuses, not the referred customer's name or email.

Who is responsible, where data goes, and how long we keep it

OptiCab Ltd, trading as Tweaksy, is the controller for the personal data described on this page under UK GDPR. Our service providers include: Anthropic (United States) to build changes from your requests, Stripe (Ireland and United States) for payments, and Cloudflare (worldwide edge, with account data held in Cloudflare's European Union region) to run the service and store accounts. Transfers to the United States rely on the UK International Data Transfer Addendum to the EU standard contractual clauses in each provider's terms. We process account and billing data to perform our contract with you, page snapshots to build the changes you ask for (also under that contract), and optional analytics only with your consent.

We keep your account, changes, requests, notes and documents for as long as the account exists, and delete them within 30 days of a deletion request. Page snapshots are not stored at all; they are passed to the AI provider and discarded when the build finishes. The account keeps a short activity record (the last 200 events: approvals, deletions, computers added or removed, billing and password changes, with the date and which computer or page did it) so you can see what happened on the account; it is deleted with the account. Session cookies last 30 days. Email confirmation links last three days. Server logs, which never contain page content, are kept for 7 days.

You can lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we handle your data. We would rather hear from you first at hello@tweaksy.app.

Your rights

Email hello@tweaksy.app to ask what we hold about you or to have your account deleted. Logging out of the extension removes the copy of your changes from that computer. Changing your password logs out every computer and website session on the account and cancels any other reset link.