The short version
Monterey Studio is the account behind fourteen browser extensions. Ten of them do everything inside your browser and only ever ask this server one question — has this person paid for this extension? Four of them do work on our servers that you cannot do in a closed browser, so they store what that work needs: a page you asked us to watch, a screenshot you asked us to host, a summary you asked us to generate, a record that an email you sent was opened.
Nothing here is advertising, and nothing here is analytics. We do not track you across sites, we do not build a profile, and we sell nothing to anyone. Each of the four sections below says exactly what that product holds, what it deliberately does not, and for how long.
The ten that never send us anything
These do their entire job in your browser. The only thing this server does for them is answer what your license says.
LoudenBoosts the volume of a tab
CadenceClicks on a schedule you set
SiftDownloads the images on a page
BrambleBlocks sites you choose
LinelighterDraws a reading ruler across the page
TreelineRenders JSON as a tree
TenBlueHides AI overviews in search results
Proxy CaptainRoutes requests through proxies by rule
Cookie CaptainDeletes cookies and site data after you leave a site
They contact this server for one reason: to ask what your license says. The request carries no page, tab or URL, because the answer never depends on one, and nothing you do with them is counted — the metering tables exist for products that make a server call we pay for, and none of these ten makes one. If you are on a free plan and never sign in, they never contact us at all.
What your account holds
One sign-in covers all fourteen. This part is the same whichever ones you use.
StoredYour email address and password (hashed by Better Auth, never readable by us), one license row per extension — plan, status, renewal date — and the customer and subscription ids Stripe gives us
HashedEvery extension token. The token itself is shown to your extension once, at pairing, and never written down — we keep its sha256 and its first few characters, so the account page can tell two devices apart
Short-livedA pairing code expires ten minutes after it is issued, and is deleted the moment it is claimed. A token lasts a year and renews as you use it; you can revoke one from your account page at any time
BoundA token is tied to one extension for its whole life. The product is read off the token, never off the request, so a Sift token cannot ask a question about Bramble — or reach Stakeout, Scrollshot or summarize.watch
One timestampA token records the date it was last used, so you can recognize a device you no longer own. That is one date, not a history
Stakeout — watching a page
Stakeout tells you when a page changes. Free monitors run in your browser; paid ones run on our servers, which is what lets a page be checked while Chrome is closed. Either way, a monitor lives in your account, so the free tier needs an account too.
Stored per monitorThe URL you asked us to watch, an optional CSS selector for the region of it, your own label, how often it runs, and a webhook address if you set one
Never the pageWe keep a hash of the extracted text and a 140-character preview of it, and nothing else. Keeping whole pages would turn a change monitor into an archive of other people's sites
Cloud checksOur servers fetch the page on your schedule. We identify ourselves honestly as StakeoutBot/1.0 with a contact URL rather than pretending to be Chrome, give up after ten seconds, and read at most the first five megabytes
Browser checksYour extension reads the page in your own tab and posts us the extracted text. We hash it here rather than trusting a hash, keep the same 140-character preview, and discard the rest
Check log (Pro)Time, outcome, HTTP status, how long the fetch took, the content hash, and any error. Kept 30 days. Free accounts get the rolling 30-check sparkline on the monitor instead
Change historyEvery detected change, with the previous and new previews. Kept 395 days, on every plan — this is the record you came for
Webhook alertsIf you set a webhook, we POST the monitor's URL, label and both previews to the address you gave — Slack, Discord, your own script. That is a transfer to a third party you chose, and it is the only alert channel we have. We send no email
Testing a pageThe dry run fetches the URL you typed, once, and shows you what our servers can actually read. Nothing is stored
Unseal — knowing an email was opened
Unseal puts a 1×1 transparent image in an email you send and tells you when it is fetched. The person who receives that email is not our customer and never agreed to anything, which is why the schema keeps as little about them as the feature can work with.
Stored per messageA random unguessable id, your account id, when you sent it, and sha256 hashes of the recipient address and subject line. Matching a hash back to your Sent list happens in your browser, not here
Plaintext is opt-inThe recipient and subject are stored as readable text only if you explicitly turn that on for the activity feed. Off by default, and off costs the product nothing
Stored per openThe time, our classification of the fetch, a two-letter country, a coarse device family (iOS, Android, macOS, Windows, Gmail's image proxy, other) and a coarse network class (Google, Apple, Microsoft, a security scanner, an ISP, other)
Never storedThe recipient's IP address, ever, and never their raw user-agent string. There is no lawful basis for retaining a stranger's address for our customer's convenience, and it would be useless anyway — Gmail hands us Google's address and Apple hands us a relay's
Never seenThe body of your email. The pixel is a URL; we never receive the message it sits in, and we do not connect to your mailbox
Honest countingA fetch is not a read. Apple Mail and corporate scanners load images automatically, so those are classified as machine or prefetch and are not counted as opens
Kept forOpen events 90 days. The message rows they belong to, 13 months
Scrollshot — hosting a screenshot
Scrollshot stores a screenshot you captured and gives you a link to it. The link is public by design: anyone who has it can open the image, so treat a share link the way you would treat the screenshot itself.
StoredThe image itself, in Cloudflare R2 under a key that contains your account id; its size, dimensions and image type — sniffed from the bytes, never trusted from the client — plus any title you set and a random 12-character slug
A separate domainImages are served from a different registrable domain than the dashboard, so bytes a stranger uploaded can never run in the origin that holds your session
Password links (Pro)The passphrase is stored as a salted PBKDF2-SHA256 hash. We cannot read it, cannot recover it, and cannot open the link for you if you lose it
ExpiryEvery link has one. Free links live 7 days, Pro links up to 365, and you can always choose shorter. It is enforced on every single request, not only by the nightly sweep — an expired link stops working the moment it lapses
View logThe time, a two-letter country and the referring host. Never an IP address and never a raw user-agent. Kept 90 days, and deleted with the link if that comes first
Identity is kept on purposeThere is no anonymous upload path and there will not be one. An image host that accepts bytes from anyone becomes someone else's phishing page, and knowing whose account an object came from is the only thing that makes an abuse report answerable
Abuse reportsAnyone can report a link without logging in. We record the reason, any detail, an optional contact address if the reporter gives one, and a daily fingerprint — sha256 of the link, the reporting address and today's date — so one person cannot flood the queue. It is not an address, and it stops being linkable to anything the next day
summarize.watch — summarizing a video
This is the one product where your data leaves our servers to be processed by somebody else. The extension reads the caption track off the YouTube page and sends it here, and we send it to a language model to be summarized. Both providers are US companies.
Sent onwardThe transcript text, the video's title and duration, and your chosen depth and language. Which model reads it is ours to decide, not yours to set; the second provider below is the failover when the first is unavailable. Nothing that identifies you goes with it: no name, no email, no account id
Not storedThe transcript. We keep its length in characters, for cost forensics, and throw the text away. Keeping it would turn a license database into a content archive
Your libraryThe summary text itself, kept under your account. It is your only copy and it has no expiry — it lives until you delete your account
A shared cacheA summary is also written to a cache keyed on the video, model, depth and language, so the next person to ask for the same video is served it instead of us paying for it twice. It holds the summary, the provider name and token counts — no account id, and nothing you supplied about yourself. Every input to it is public: an 11-character YouTube id and a caption track anyone can fetch
Video metadataThe YouTube id, title, channel, duration and language, cached so a lookup does not need the page
Request logOne row per request — video id, plan, model, provider, outcome, token counts, latency — because that is the only record of what a request cost us. Kept 13 months
The lookupWhen you open a watch page the extension asks whether you already have a summary for that video. It is a read; no row is written and nothing about the visit is logged
Demo modeBefore you sign in the extension builds a sample summary from the caption lines in your own browser. It calls nothing and sends nothing — no request reaches us on that path at all
Who else touches your data
The complete list. There are no others, and none of them is an advertiser.
StripePayments. Checkout and the billing portal run on Stripe and your card details never reach us — we hold the customer, subscription and price ids they issue
Anthropicsummarize.watch only. Receives transcript text to summarize, in the United States. Touches no other product
OpenAIsummarize.watch only, as the other side of the failover pair. Receives the same transcript text, in the United States
CloudflareHosts this service and its database, stores Scrollshot's images in R2, and routes mail sent to our addresses
Payments
Checkout runs on Stripe and we never see your card details. We keep the customer and subscription ids Stripe issues, a line in our own ledger for each payment — amount, currency, date, which extension — and the raw Stripe event behind each change, because an event we cannot replay is a license we cannot repair by hand. That raw event is the full Stripe object, including the billing address and email Stripe holds, so it is erased after 90 days; what remains is the ledger line, which carries no contact details.
How long we keep things
One nightly job applies all of this. These are its actual numbers.
Until you delete your accountLicenses, and your summarize.watch library
395 daysStakeout change history
365 daysA Scrollshot link on a paid plan, unless you set it shorter
180 daysThe shared summary cache
13 monthsUsage counters and the event log behind them, Unseal's tracked-message rows, the summary request log, and tokens that have already expired or been revoked
90 daysRaw Stripe event payloads, Unseal's open events, and Scrollshot view logs
30 daysStakeout's per-check log, and cached video metadata nothing refers to
7 daysA Scrollshot link on the free plan, unless you set it shorter
About a dayExpired pairing codes — they are only valid for ten minutes — and screenshot uploads that were started and never finished
Your data
- You can revoke any connected extension yourself, from your account page. It stops working on that device immediately.
- You can delete a monitor or a share link yourself, from the extension that made it, and deleting a link takes its image and its view log with it. A saved summary has no delete button yet; write to us and we will remove one.
- There is no self-serve delete-my-account button. Write to us and we will delete the account: it takes your licenses, tokens and pairing codes with it, and with them your monitors and their change history, your tracked messages and their opens, your uploads and their links and view logs, and your summary library.
- Two things survive deliberately. The payment ledger, which we are required to keep for accounting, with your account id removed so the line no longer points at a person. And Stripe's own records, which are theirs and are kept under their retention rules, not ours.