Privacy Policy

Effective date: July 27, 2026

1. About ReflectLayer

ReflectLayer ("ReflectLayer," "we," "us," or "our") provides an observational tool for brands, sellers, vendors, studios, agencies, and other providers. Our website at reflectlayer.com and our companion Chrome extension let a user watch how Amazon's on-page AI assistant — presented as Alexa or Rufus depending on the supported marketplace and experience — interprets an Amazon product detail page and turn that into product intelligence. A limited guest free-test is available without an account; full use requires a connected ReflectLayer account.

This policy explains what information ReflectLayer collects through the website and the Chrome extension, how that information is used, who processes it on our behalf, and the choices users have.

2. Information we collect

2.1 Information you provide

  • Account information. When you create an account you provide an email address and a password. Authentication is provided by Supabase; ReflectLayer does not store your plaintext password. We store a user identifier and email in our authentication system.
  • User-supplied context. Optional brand name, model name, and custom context that you attach to a product for use during reflection generation.
  • Saved questions and notes. Questions you star and any notes you save alongside a reflection.
  • Billing information. If you subscribe, your payment card details are collected and processed by Stripe on our behalf through the ReflectLayer website. We do not receive or store full card numbers. The Chrome extension does not collect payment card details.
  • Uninstall feedback. If you choose to answer the optional survey after uninstalling the extension, we receive your responses along with a best-effort account identifier so we can attribute the feedback.

2.2 Information the extension observes on Amazon pages

The extension operates only on supported Amazon pages the user visits (currently amazon.com, amazon.co.uk, and amazon.de product detail pages). It observes:

  • the ASIN and product title of the page you are viewing;
  • the question you type into Alexa/Rufus and the response Alexa/Rufus returns;
  • competitive ASINs that Alexa/Rufus references in its response.

The extension reads limited product-page information and observes the Amazon AI response initiated by the user. It does not crawl unrelated pages or automate additional questions to Amazon. It does not send additional shopping-assistant questions or requests to Amazon on the user's behalf. The extension does communicate over HTTPS with ReflectLayer's own APIs to deliver observed content for reflection generation.

2.3 Information generated by ReflectLayer

  • Reflections, layer outputs, title variants, competitive analyses, and other product intelligence generated from the observed Alexa/Rufus responses.
  • Usage and quota information (for example, how many free reflections have been used) so we can apply plan limits.
  • A long-lived account connection token stored locally in the extension that links your installed extension to your ReflectLayer account.
  • Short-lived capture-session tokens issued per ASIN by ReflectLayer's API; these expire and are refreshed automatically while you are viewing a supported page.
  • A guest identifier used only to attribute one free test to an unauthenticated browser.

2.4 Automatically collected technical information

Our hosting provider (Cloudflare) and database provider (Supabase) receive standard request metadata such as IP address, user agent, and timestamps as part of routing and securing traffic. We do not operate an analytics product, error monitoring product, or advertising tag on the site or in the extension.

3. Information stored locally by the extension

The extension uses chrome.storage.local to store a small amount of state on your device: your extension token, cached reflection data for ASINs you have viewed, layer settings, and a guest identifier. This local data can be cleared by uninstalling the extension or clearing extension storage in your browser.

4. How we use information

  • To provide and operate ReflectLayer's reflection generation and seller tools.
  • To authenticate you and secure your account.
  • To apply plan limits, quota, and billing.
  • To debug, prevent abuse, and improve reliability.
  • To respond to support requests you send us.
  • To comply with legal obligations and enforce our terms.

We do not sell your personal information. We do not use your information for personalized advertising. We use information received from Google Chrome APIs only to provide or improve the user-facing features of ReflectLayer described in this policy.

5. Service providers

We use third-party service providers for account authentication, data storage, hosting and security, payment processing, transactional email, and AI processing.

When you request a reflection, relevant Amazon AI content and product context are processed by AI service providers solely to generate the requested results. Payment-card information is handled directly by our payment processor and is not collected by the ReflectLayer extension.

Service providers receive only the information reasonably necessary to perform services for ReflectLayer. We do not sell personal information or share it with third parties for their independent advertising or marketing.

6. Chrome Web Store Limited Use disclosure

The use of information received from Google Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

7. Data retention

We retain account and product-analysis information for as long as reasonably necessary to provide ReflectLayer, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion by contacting us at the address in Section 11.

8. Account and data deletion

To request deletion of your account or the information associated with it, email contact@reflectlayer.com from the email address on your account. We may need to verify your request.

Some information may be retained after a deletion request when we are required or permitted to keep it for legal, security, fraud-prevention, tax, billing, or transaction-record purposes.

9. Security

Information is transmitted over HTTPS and stored with our infrastructure providers using their standard security controls, including access control and encryption in transit. No system is perfectly secure; we cannot guarantee absolute security.

10. Children's privacy

ReflectLayer is a professional product-intelligence tool intended for brands, sellers, vendors, studios, agencies, and other providers. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

11. Contact

Questions about this policy, or requests related to your information, can be sent to contact@reflectlayer.com.

12. Changes to this policy

We may update this policy from time to time. When we do, we will update the effective date at the top of this page. Material changes will be communicated through the website or by email where appropriate.