STRATA STUDIO

Your data & your choices

Privacy policy

How Strata Studio handles the screenshots, code, and context you use to explain website issues.

Effective date: · Last updated:

At a glance

  • Captures and debugging records are saved in your browser.
  • Page diagnostics are buffered locally while supported pages are open, including before you take a capture.
  • When you run AI framing, included evidence is sent to your chosen AI provider.
  • No Strata account or GitHub sign-in is required in the current free release.
  • The extension does not send your captures to a SteProTECH-operated collection server or include advertising analytics.

1. About this policy

Strata Studio is a browser extension developed by SteProTECH. Its purpose is to help you capture and explain website interface issues and prepare debugging tasks for developers and AI coding assistants.

This policy covers the extension and its optional Strata local source-code bridge. It describes the current free release, in which licensing and activation are disabled. AI providers, GitHub, Chrome synchronization, and services you independently choose have their own privacy practices.

2. Information the extension handles

InformationWhat it includes and why it is used
Website contentScreenshots and imported images; selected elements; rendered HTML, styles, layout measurements, and available accessibility observations. These help document how an issue appears.
Page and activity contextPage titles, URLs, capture times, viewport and display-scale details, console messages and error stacks, failed or slow request metadata, and a limited interaction timeline. These help explain the circumstances of an issue.
Your debugging workIssue descriptions, expected behavior, reproduction steps, annotations, element notes, reference selections, AI prompts and responses, and saved task evidence.
Credentials and settingsAI API keys you enter, provider endpoints and model selections, local-bridge pairing keys, public repository settings, and display or capture preferences. Credentials authenticate the connections you configure.
Local source contextWhen the bridge is connected: the linked project path, matching file paths, line ranges, and bounded source snippets used to relate the visual issue to your code.

Captured pages, images, source files, and console messages may contain names, contact details, personal communications, financial or health information, credentials, or other sensitive content. Strata does not need those details to identify you, but they can be included in the material you capture or submit. Review the evidence before sharing it.

Strata does not request your precise geographic location or read Chrome's complete browsing-history database. Page URLs and request URLs included in debugging evidence are nevertheless browsing-related information.

3. Diagnostics collected while pages are open

On supported pages where the extension has site access, its packaged diagnostic script runs when the page starts loading. It keeps bounded, in-memory buffers of console messages, JavaScript errors, failed or slow network request metadata, and limited interaction events. This happens before a capture so earlier events can help explain the issue.

The interaction timeline records click and form-submission events, a limited target identifier, a timestamp, and the scroll position. It does not intentionally record keystrokes or typed form values. The network probe records information such as URL, method, status, and duration; it does not intentionally record request or response bodies. Page console messages and URLs can themselves contain sensitive information.

These buffers remain in the page until overwritten or the page is unloaded. When you capture or request additional inspection, Strata can read relevant diagnostic evidence into the capture or task. The buffers are not automatically uploaded to SteProTECH or an AI provider.

4. Connections and sharing

Optional AI providers

When you run AI framing, Strata sends your request and the included debugging evidence directly to the provider or compatible endpoint you configured. This can include page context, diagnostics, source snippets, annotations, and screenshots or element images when image inclusion is enabled. Model-list and connection checks also contact the selected service and use its configured credential when required.

Your API key is sent to its configured provider to authenticate requests; the bridge pairing key is used for the local bridge. Strata does not intentionally insert these saved credentials into the AI prompt. Receiving services also receive ordinary connection information, such as your IP address. Their retention, processing location, and possible use of submitted data are governed by their policies and your account settings. Strata cannot delete data already retained by them.

Local source-code bridge

The optional bridge is a separate, read-only program you run on your computer. It listens on the loopback interface and requires a pairing key. The extension sends element or component search hints to it and receives matching source context from the linked project. The bridge excludes common dependency, build, hidden, and credential files, but these filters cannot identify every secret. Returned snippets may subsequently be included in an AI request or export. Connecting the bridge is not an upload of your entire repository.

Public GitHub source

If you configure an anonymous public repository, Strata may request its metadata and source files from GitHub to resolve source context, including as a fallback when local lookup does not resolve it. GitHub receives the requested repository or file identifiers and normal connection metadata. The current release does not require GitHub authentication or access private repositories through a GitHub account.

Exports and support

Copying or exporting a capture or task places information on your clipboard or in files you control. Sharing those items with another person or service is your choice. If you voluntarily contact SteProTECH and provide an example or diagnostic material, that material is used to respond to your request. Do not include API keys or other secrets in support messages.

5. Storage and retention

Captures, saved evidence, AI-provider credentials, custom provider definitions, and bridge connection settings are stored locally in extension or browser storage. Some preferences, such as theme and selected provider or model, use Chrome's synchronized storage and may be synchronized according to your Chrome settings. The extension does not intentionally store capture images or API keys in Chrome synchronized storage.

Local records remain until you remove them, the extension replaces older records under its history limits, or browser data is cleared. There is no universal time-based deletion schedule for all locally stored records. Page diagnostic buffers are temporary; saved captures and AI histories can outlast the page that produced them.

The local bridge separately retains its connection configuration on your computer. Removing the extension does not remove downloaded bridge files or that configuration. Exported files, clipboard contents, backups, and copies held by external providers are also separate from the extension's local history.

6. Your controls

  • Choose what to capture. Use region or element capture to limit the visible material included.
  • Review before sending. Check screenshots, notes, and source context. Exclude images from AI framing when appropriate, or use capture and annotation without configuring AI.
  • Manage saved work. Clear AI run history from the prompt/output history view and delete unwanted captures from Capture history. Clearing both addresses different saved records.
  • Manage connections. Clear saved provider keys, remove custom providers, or disconnect source links in Settings. Stop the local bridge to end its availability.
  • Control site access. Use Chrome's extension controls to restrict site access, disable Strata, or uninstall it. Reload already-open pages after disabling or changing access to remove previously injected page scripts.
  • Manage other copies. Delete exported files separately and use your provider's controls for requests already sent. Revoke API keys at the provider if necessary.

You can contact SteProTECH about privacy questions or applicable data rights. Because your local captures are not held on a SteProTECH capture server, we cannot remotely retrieve or erase them for you.

7. Security and redaction limits

Built-in remote AI and GitHub connections use HTTPS. The local bridge uses authenticated HTTP on your own computer. Custom endpoints are user-configured and can use HTTP or HTTPS; choose HTTPS for remote services, because plain HTTP does not encrypt transmitted credentials or evidence.

Credentials are stored using browser storage rather than a separate encrypted Strata credential vault. Protect your browser profile, device, backups, and API keys. No storage or transmission method can be guaranteed completely secure.

Strata filters some sensitive text patterns and HTML attributes when preparing evidence, but this is not comprehensive anonymization. Screenshots are not automatically inspected for every secret. Blur affects image pixels; it does not remove corresponding text from HTML, logs, source snippets, or an earlier saved capture. Resetting image edits can restore the original unredacted image. Review each form of evidence before sending or exporting it.

8. Limited use of information

Strata Studio's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Information handled by the extension is used to provide its visual-debugging features and the connections you choose for that purpose.

SteProTECH does not sell extension user data, use it for targeted advertising, transfer it for unrelated purposes, or use it to determine creditworthiness or for lending. The extension has no advertising trackers and does not send captures or debugging histories to a SteProTECH-operated analytics service.

Transfers described in this policy support the user-facing debugging workflow. SteProTECH does not routinely access your locally stored captures. Any information you separately provide to support is handled for that request, or as necessary for security or legal obligations. A user-selected AI provider's own data practices remain subject to that provider's terms and settings.

9. This privacy-policy page

This HTML page contains no analytics scripts, tracking pixels, external fonts, or forms, and it does not set cookies itself. The service hosting the page may process ordinary web-request information, such as IP address, browser information, and request time, according to its configuration and policies. Following an external link takes you to a service with its own privacy practices.

10. Changes and contact

We will update this policy when Strata's data practices change and revise the date at the top. Where required, material changes will also be disclosed in the extension and consent obtained before the new processing begins. A future licensing or account feature would require updated disclosures before activation.

For privacy questions or requests, contact SteProTECH through steprotech.com and identify your request as relating to Strata Studio.