Summary
Information JourneyLens handles
Recorded web interactions
When recording is explicitly active, JourneyLens may process URLs, page titles, clicks, selected elements, form values, selected options, checkbox state, accessible names, roles, selectors, XPath candidates, viewport dimensions, navigation events, screenshots, and time between actions.
Page diagnostics
JourneyLens may capture page errors, console warnings and errors, failed resources, fetch request URLs, methods, status codes, timing, resource timing, transfer sizes, page-load timing, accessibility findings, and keyboard focus order. Request and response bodies are not collected by default.
User-created QA content
The extension stores waits, assertions, regex patterns, branch conditions, datasets, network contracts, mock response bodies, visual masks, performance budgets, environment profiles, reusable flows, schedules, version labels, training notes, and generated reports that the user creates.
Sensitive values
Password fields are replaced with placeholders during recording. Pro users can store secrets encrypted with AES-GCM using a key derived from a master password. The master password is not stored. Users should still review exports before sharing them.
Where data is stored
JourneyLens uses Chrome’s extension-local storage. Information remains associated with the local Chrome profile unless a user explicitly exports a file. Removing the extension normally removes extension-local data according to Chrome’s behavior. Browser or enterprise backup tools may retain copies outside JourneyLens’s control.
Visual baselines and screenshots can consume substantial storage. Users control retention by deleting journeys, steps, screenshots, histories, baselines, schedules, reusable flows, or the extension itself.
When JourneyLens accesses the network
JourneyLens interacts with web applications only when the user records, replays, scans, or schedules a journey. It does not send those journeys to a JourneyLens server.
Website access
The extension requests access to HTTP and HTTPS pages so it can record and replay the sites chosen by the user. Local schedules open the configured page in a background tab on the same device while Chrome is available.
Font delivery on this website
This static website requests the Satoshi webfont stylesheet from Fontshare. Fontshare may receive ordinary web-request information such as the visitor’s IP address and user agent under its own policies. The JourneyLens extension itself does not require Fontshare to record or replay journeys.
Pro licensing and Lemon Squeezy
When a user chooses to activate, validate, or deactivate a production Pro license, JourneyLens contacts Lemon Squeezy’s License API. The request includes the license key and an instance identifier or instance name. Lemon Squeezy returns license, store, product, variant, order, and customer metadata.
JourneyLens verifies that the returned store, product, and variant identifiers match the configured JourneyLens Pro product. License information is used only to determine the local entitlement. Temporary development licenses do not contact Lemon Squeezy and must be disabled before a production release.
Chrome permissions
| Permission | Purpose |
|---|---|
| activeTab / scripting | Inject the recorder and replay actions after explicit user interaction. |
| storage | Store local journeys, settings, schedules, baselines, reports, and encrypted vault entries. |
| sidePanel | Display the JourneyLens recorder, editor, tools, and plan interface. |
| downloads | Save Loompath, Playwright, reports, backups, and Pro journey packages. |
| contextMenus | Add the native JourneyLens submenu for values, assertions, conditions, regex, and waits. |
| alarms | Trigger explicitly configured local Pro schedules while Chrome is available. |
| notifications | Notify the user when an explicitly scheduled local run fails. |
| Optional website origins | Record and replay user-selected HTTP and HTTPS applications. |
| Optional Lemon Squeezy origin | Activate or validate Pro only after the user requests it. |
Retention and deletion
Users can delete individual steps, complete journeys, local versions, histories, schedules, baselines, and encrypted secrets. Archived journeys remain stored locally until deleted. Retained run-history limits can be configured. Removing JourneyLens removes its extension-local storage subject to Chrome’s behavior.
Security measures and limitations
JourneyLens uses local processing, password-field redaction, optional AES-GCM encryption for Pro secrets, hard-coded Lemon Squeezy product checks, and explicit permission prompts. No browser extension can guarantee that a recorded page contains no sensitive information. Users should avoid recording real production credentials and should inspect packages before distribution.
Local fetch mocking changes selected requests only during an explicit replay and only in the current page. Imported journeys should be reviewed before execution because they can navigate, interact with pages, fill fields, and run configured Loompath-compatible steps.
Your controls
- Do not grant website access if you do not want JourneyLens to interact with pages.
- Stop recording at any time.
- Delete or archive recorded journeys.
- Remove local schedules or pause them per journey.
- Remove the Pro license from the browser.
- Review and redact files before sharing them.
- Remove the extension to clear its local storage according to Chrome’s behavior.
Contact
For privacy questions, deletion guidance, security reports, or product support, email support@builtbykris.com.