Back to Source

Source privacy

Updated September 10, 2026

Website content stays in your browser

Source reads images, SVGs, colors, font names, links, and other assets when you start a scan or use the asset picker. It contacts the websites and asset hosts you choose to fetch their files. It does not send scanned pages, asset URLs, page text, or extracted files to the Source licensing service.

Licensing and scan limits

Source contacts its service hosted on Cloudflare to verify access and count free scans. If you enter a Source Pro license key, it is saved locally in your browser and sent over HTTPS to that service. The service verifies your membership with Whop. Neither the extension nor its package contains the business API key or webhook signing secret.

Your public IP address is visible to Cloudflare when you connect. The service hashes it for request rate limiting. This version creates a random installation identifier, saved locally and sent to the service, to count three free scans per installation in a rolling 24-hour window. Older extension versions without this identifier share scans by network. The service stores scan identifiers and times for quota enforcement. Old scan records are removed on the next quota check after they expire; if you stop using Source, records can remain until that check. Cloudflare may retain operational logs under the account's configured retention. Webhook receipt identifiers are retained for seven days.

For Pro, the service also stores a hashed installation identifier linked to your membership to allow one active browser installation. It stores activation and transfer times, and hashes of temporary transfer codes. Codes expire after ten minutes; a successful transfer replaces the active installation. These licensing records remain until removed through a support request. Removing a local license or uninstalling does not remove the server binding. Source checks access online before scans, exports and Asset Picker actions and periodically while the extension is open.

Purchases

For automatic activation, Source creates a private purchase claim stored locally. Its hash is attached to a Whop checkout configuration. Source verifies the resulting membership before granting access; a checkout message alone never grants Pro. Pending checkout references expire on the service after 30 days. Verified access records contain the claim hash and membership identifier and remain until removed through a support request. The private claim is saved locally as an access credential and sent only to the Source service over HTTPS. It is not sent to the scanned website.

Checkout opens in a separate secure window with an embedded Whop form. Whop and its payment providers collect the email, billing and payment details you enter directly; the extension does not read those form fields. Recurring subscription billing is managed by Whop. Some payment methods may open an external verification window. Source does not collect or store payment card details. Whop and Cloudflare process data under their own privacy policies. Removing your saved license does not cancel your subscription; use Manage subscription to cancel on Whop.

Local storage and control

Options, a random installation identifier, and an entered license key are stored locally. Your workspace stores extracted asset URLs, embedded images, colors, font names, and selections locally so they remain available after you close Source. Use the trash can button to clear scanned assets. A new scan replaces the previous results. You can remove the saved license in Options, revoke optional website access in Chrome, or uninstall Source to remove its extension storage. Reset restores options and does not cancel a subscription.

Limited use

Source uses website data only to provide the asset collection features you request, and licensing data only for access, quota enforcement, and service operation. Source does not sell this data or use it for advertising or unrelated purposes. Source's use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Contact

For support and privacy requests, contact designtoolboxcontact@gmail.com.

Only download and reuse assets when you have permission from their rights holder.