HomePrivacy policy

Privacy policy

What Lensable collects, what it never collects, and where the area you select actually goes.

LegalLast updated 4 September 2026

The short version

In one paragraph

Lensable does nothing until you select something. When you run a visual search or ask a question, the area you selected and your question are sent to the provider you chose so an answer can come back. We do not read your screen in the background, we do not build an advertising profile, and we do not sell your data. If you create an account, the password you choose goes directly to our sign-in provider, Supabase, over an encrypted connection; our own servers never receive it and nobody stores it in readable form.

Everything below is the longer, more careful version of that paragraph.

What we collect

The selection you make. When you run a visual search or ask about an area, Lensable captures the region you outlined or boxed, plus the URL of the page it came from. It is captured at that moment, for that action.

Your question. If you ask about a selection, the text of your question travels with it.

Page context, only when Content Aware is on. With Content Aware enabled, a small amount of surrounding text — typically the page title and nearby paragraphs — is included so the answer fits what you are reading. You can turn this off.

Account and billing basics. If you create an account, we store your email address and the account ID Supabase assigns to it. If you buy a plan or searches, we also store your plan, subscription status and billing period, the Stripe customer and subscription IDs needed to match payments to you, and a record of each billing event: what was bought, the amount and currency, the Stripe session or invoice ID, and whether a renewal payment succeeded or failed. To start a purchase we send Stripe your email address, your Lensable account ID and the plan you chose, which Stripe keeps on its customer and subscription records. Accounts, and the server-held data described on this page, are stored with Supabase, our database and sign-in provider. Card details are entered on Stripe’s own checkout and billing pages, are handled entirely by Stripe, our payment processor, and never reach our servers. How signing in works, and exactly what happens to the password you choose, is set out under Signing in and your password.

Search History. When a visual search returns results we keep a short record of it: the object we identified, its category, a thumbnail of it, how many matches came back, and the top match. It does not include the page you were on or the image you selected. You can pause it, or clear it entirely, from your account.

Saved Highlights. When a highlight syncs to your account, we store the passage you chose, its page title, source URL and saved date. The account labels this collection as server-synced because a browser-local extension copy may not have reached our server. Saved Highlights are stored on their own: they are not read to work out what you might be interested in.

Topics you follow. Following is something you start. Where it is available on your account, you add a topic yourself under Account → Interests. Lensable never creates a follow for you, and saving a highlight does not start one. For each follow we store the name you gave it, how often you asked us to check the topic — weekly or daily — and whether you have muted it. The canonical name of the topic itself is stored once and shared with everyone following the same topic, so it is not private to you. Checking is shared in the same way: a topic is checked once for everyone following it, and the shortest choice among people still following it may decide how often that happens. Checking is not delivery. A brief only reaches you when a check finds a meaningful update it can cite, so a shorter checking interval does not mean more briefs.

Briefs delivered to you. When a topic you follow produces a brief, we record that it was delivered to you, when it was delivered, and whether and when you opened it. The record also carries a field for marking a brief as notified. Lensable does not currently send emails, push messages or extension alerts, so nothing is sent on the back of that record.

Usage and cost records. We count how many visual searches you have used in the current period so quotas work. We also keep one row per billable action recording what kind it was, which model answered, and what it cost us to run. Those rows carry no page address, no page text, and no part of your selection.

Beta wait-list. If you enter your email address in the wait-list form on our homepage, we store it, with a note that it came from the homepage, so we can let you know when the beta build is ready. It is not linked to an account and is used for nothing else. Ask us to remove it at any time through the contact page.

Signing in and your password

You can install Lensable and keep highlights in your browser without an account, but a visual search or a question needs one, and so do paid plans, Search History, server-synced Saved Highlights and following. An account is free to create. The extension and this website offer the same two ways to sign in, and this section says exactly what each one collects, where it goes and how it is protected.

Email and password. When you create an account or sign in with an email address and a password, the extension or the website sends both, over an encrypted HTTPS connection, directly to Supabase, our sign-in provider, which checks them and returns a session. Your password goes nowhere else. Lensable’s own servers never receive it, it is never written to our logs, and Lensable never stores it on your device; your browser’s own password manager may offer to remember it, which is a browser feature under your control. Supabase does not keep the password itself either: it stores a one-way hash of it, which is what your next sign-in is checked against, and it cannot be turned back into the password. A password must be at least 6 characters. If you create an account this way, Supabase may send a confirmation message to the email address you gave before the account can be used. There is not currently a change-password or reset control in the extension or on this website; to change or recover a password, or to have the stored hash removed by closing the account, email us as described under Your rights.

Sign in with Google. Choosing Continue with Google opens Google’s own sign-in page, in a window that Chrome provides for extensions through the identity permission. Google tells Supabase who you are, and Supabase returns a session together with the email address on your Google account and a Lensable account ID. We never see your Google password. Supabase keeps what Google shares for the sign-in, typically your name, profile picture address and Google account identifier, in the account’s sign-in record, and Google’s own consent screen shows exactly what that is; Lensable itself uses only the email address and account ID. On the website the same sign-in happens through a redirect to Google and back, without the extension window.

The session we keep on your device. A successful sign-in, by either route, returns two tokens: an access token that proves to our servers that a request comes from you, and a refresh token used to obtain a new access token when the old one expires. The extension keeps them, with your account ID and email address, in Chrome’s extension storage on your device; the website keeps the same in your browser’s local storage for this site. They travel to our servers only as an authorisation header on requests that need your account, such as checking how many searches you have left or syncing a highlight, and to Supabase at sign-in, when they are refreshed and when you sign out. They are the only credential held on your device. Signing out removes them and asks Supabase to end the session; uninstalling the extension removes its copy, and clearing this site’s data in your browser removes the website’s copy.

What our servers learn from a sign-in. Each request that carries a session token is verified with Supabase, which returns your account ID and email address. That is how the server-held data described on this page is tied to you. Our servers never receive your password by this route or any other.

Why the extension declares authentication information. Because the extension contains a sign-in form, its Chrome Web Store listing declares that it handles authentication information. The paragraphs above are the complete account of that: your password is collected only to sign you in, is transmitted only to Supabase and only over HTTPS, is stored only as a one-way hash by Supabase, and is not used or shared for any other purpose.

What we never collect

  • Continuous or background screenshots of your screen.
  • Your browsing history, open tabs, or pages you visit without acting on them.
  • What you type on the pages you visit. Lensable has no keystroke logging, never reads form-field values out of a page, and ignores text you highlight inside a form control. The only password you ever type into Lensable is your own account password on our sign-in form, which is covered under Signing in and your password. A visual selection is a picture of the area you outlined, so anything visible inside that area is in the picture: do not outline a password or payment form.
  • Data from DRM-protected video, which is technically inaccessible to us and returns blank by design.
  • Interests worked out from what you read, save or search. A topic is followed only because you added it.
  • Anything used to build an advertising profile. We do not sell or rent personal data.

Where your selection goes

The selected image and your question are sent to the AI provider you picked for that question. Each choice in the picker is operated by a named company: ChatGPT by OpenAI, Claude by Anthropic, Gemini by Google, Grok by xAI, and Perplexity by Perplexity AI. Lensable Auto is not a separate provider — it means our server picks one of those five for you. Your selection also passes through our own servers, only insofar as we route the request and hold the provider credentials.

For product lookups, the selection is sent to visual search and shopping data providers so matches can be returned. Which provider serves a given search depends on what is configured and available at that moment; the full set we use is SerpApi (Google Lens and Google Shopping results), Serper, Scrapingdog and DataForSEO (search and shopping data), eBay’s Browse API (eBay listings), and Google Cloud Vision (finding where else an image appears). Those results include links to third-party retailers; nothing is sent to a retailer unless you click one of those links.

If you highlight a link and ask for the page behind it to be summarised, our server fetches that page itself. It is fetched from our server rather than your browser, so none of your cookies are sent and nothing on the page is executed. We send the address you highlighted; we do not send anything else about where you were.

Your account can generate Summary of selected highlights. When you ask for it, Lensable retrieves the selected server-synced highlights by their saved IDs and sends their passage text, page titles and source URLs to Google Gemini. In extension version 1.1.0, the extension instead sends the selected browser-local passage text, page titles and source URLs to Lensable for the same Gemini summary. Both paths run only when you ask, use Gemini rather than the provider selector used for questions, and do not browse or monitor sources.

Each provider handles data under its own policy. For actions that offer a provider choice, we do not send your selection to a provider you did not choose. The Saved Highlights summary uses Gemini as described above, as do the three follow-related uses described in the next section: suggesting a topic name, judging which retrieved items are relevant, and writing a brief.

Every party your data can reach. For the avoidance of doubt, this is the complete list:

PartyWhat it receivesWhy
OpenAI, Anthropic, Google, xAI, Perplexity AIThe selection you made and your question — only the provider you picked, or the one Lensable Auto picked for youAnswering you
Google (Gemini)Additionally: highlight passages, page titles and source URLs when you ask for a highlights summary; topic names and retrieved third-party material for followingSummaries and briefs, as described on this page
SerpApi, Serper, Scrapingdog, DataForSEOThe selected image, or the product query derived from itProduct matches
eBay (Browse API)The product query derived from your selectioneBay listings
Google Cloud VisionThe selected imageFinding pages where the image appears
arXiv, PubMed, the RSS/Atom feed hosts set up for a topic, and SerpApi as the web-search providerThe search query for a topic you follow, with no account identifier and nothing about who follows itGathering the material briefs are written from
Google (sign-in)Only if you choose Continue with Google: your sign-in, handled entirely on Google’s own page. Google then confirms your identity and email address to Supabase. Lensable never sees your Google passwordIdentity provider for Sign in with Google
SupabaseYour email address; the password you choose, sent to it directly over HTTPS and kept only as a one-way hash; your sign-in tokens; and the server-held data this page describes — Search History, Saved Highlights, topics you follow, usage and cost recordsOur database and sign-in provider
StripeThe payment details you enter at checkout, your email address and account ID so the payment can be matched to your account, and your subscription statusOur payment processor — card details never reach our servers
RenderData passes through it while requests are served; it hosts our serversOur hosting provider

No party beyond this table receives your data, and each of these receives it as a processor for an action you took — never for advertising, profiling or resale.

Following topics

This section describes following, and applies only where that feature is available on your account. Where it is not, nothing in it happens.

Naming a topic. When you ask for a suggested name while adding a topic, the text you typed into that box is sent to Google Gemini so it can propose a name and a one-line description of the subject area. It never runs unless you ask for it. Nothing about you accompanies it, nothing is stored by that request, and you can ignore the suggestion and follow the name you wrote.

What we retrieve. For a followed topic our server fetches publicly available material about the topic itself, never about you. Today that means arXiv, PubMed, RSS or Atom feeds set up for the topic, and, where it is switched on, a third-party web-search provider. The requests are made by our server, carry no account identifier, and say nothing about who follows the topic or what they have read.

What we keep from it. For each retrieved item we store its title, an excerpt, its address, the name of the source, any listed authors, the publication date where one is given, and a score and short reason recording why it was judged relevant to the topic. These rows belong to the topic rather than to you, and are shared by everyone following it.

Judging what is relevant. That score and reason come from a keyword rule first, which involves no model at all. Only the items the rule cannot settle are sent to Google Gemini, in one batched request per topic per retrieval run, carrying the topic name and each undecided item's title and excerpt — retrieved third-party material, and nothing else. No account identifier, no highlight or passage text, no search history and nothing about who follows the topic travels with it.

Briefs. The items retrieved for a period — their titles, excerpts, source names and publication dates — are sent to Google Gemini to write a short brief that cites them. Claims the model cannot tie back to a retrieved source are dropped before the brief is stored. A brief is written for the topic and shared by its followers; only a brief judged to contain a meaningful update is delivered, and a muted follow is delivered nothing. Briefs are written from third-party sources and can be wrong, incomplete or out of date — read the cited source before relying on one.

What following does not use. Your Saved Highlights, saved items, search history and questions are not read to choose topics, are not used to rank what you see, and are not sent with a retrieval, relevance or brief request. None of the three model steps above receives them. Nothing you follow is set up on your behalf, and no interest is worked out for you.

How we handle and protect it

Everything travels over encrypted connections. Traffic between your browser and our servers, between your browser and Supabase when you sign in, and between our servers and every provider named above, uses HTTPS/TLS.

Server-held data lives in Supabase, which encrypts it at rest. Our application runs on Render. The API keys used to call the AI, search and shopping providers above are held on the server and are never present in the extension, so nothing on your machine can leak them. The one key the extension does carry is Supabase’s publishable key, which is designed to be public and only identifies our Supabase project.

Your account password is handled only by Supabase, as set out under Signing in and your password: it travels over HTTPS, is never received or logged by our own servers, is never stored on your device, and is kept by Supabase only as a one-way hash. Session tokens are held on your device and removed when you sign out.

Access to server-held data is limited to the application itself and to us as its operator, for support and troubleshooting. We do not sell it, share it beyond the parties named above, or use it for advertising.

Our server logs record your account ID and email address next to each billable action and billing event, for troubleshooting and abuse prevention. They are held by Render, our hosting provider, for a limited time and are not used for anything else.

How long it is kept

DataKept forWhy
Selections and answers you did not saveNot stored after the answer is returnedThere is no reason to keep them
Search HistoryUntil you clear it or close your accountSo you can find a past search again
Saved Highlights and saved scenesUntil you delete them or close your accountSo you can find them again
Account and billing recordsDuration of the account, then as required by tax and accounting lawLegal obligation
Your account passwordHeld by Supabase as a one-way hash for as long as the account exists; never held on your device or on our serversSigning you in
Sign-in session tokensOn your device until you sign out, which also asks Supabase to end the session; the extension’s copy also goes when you uninstall it, and the website’s copy when you clear this site’s data. An expired access token is replaced automatically while you stay signed inProving that requests come from you
Beta wait-list email addressUntil we have let you know about the beta or you ask us to remove itSo we can tell you when the beta build is ready
Usage countersReset each billing periodQuota enforcement
Per-action cost recordsKept while the account existsCost control and capacity planning
Topics you followUntil you unfollow them or close your accountSo we know what to gather
Records of briefs delivered to youUntil you close your accountSo the same brief is not delivered twice and unread state survives
Retrieved items and the briefs written from themKept with the topic, not with your accountThey are shared by everyone following that topic

Your rights

You can delete an individual server-synced Saved Highlight from your account. You can delete a browser-local copy from inside the extension; when you are signed in and the highlight was synced, Lensable also attempts to delete the matching server copy. Browser-local and server-synced copies are separate, so deleting one does not guarantee the other copy has been removed.

Where following is available on your account, unfollowing a topic under Account → Interests removes your follow straight away. Briefs already delivered to you remain in your account until it is closed, and the topic itself — its shared name, its sources and the briefs written for it — is not removed, because other people may still follow it. Closing your account removes your follows and your delivery records.

To request access to, correction of, a copy of, or bulk deletion of server-held data, or to ask us to close your account, follow the instructions on the Delete data page and email us from the address on your account. These requests are handled by us; there is not currently a self-service bulk export or account-deletion control.

If you are in the UK, EEA or Switzerland you have rights under the UK GDPR and GDPR, including the right to object to processing and to lodge a complaint with your supervisory authority. If you are in California you have rights under the CCPA, including the right to know and the right to delete. We do not sell personal information as the CCPA defines it.

Children

Lensable is not directed at children and is not intended for anyone under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will remove it.

Changes and contact

If this policy changes in a way that materially affects you, we will say so in the extension before the change takes effect rather than quietly editing this page.

Questions about privacy go to our contact page.