Privacy and CSP
This page describes what Skyelight Build adds to your pages, what the review badge loads and stores for visitors, and how reviewers sign in. It also lists the Content Security Policy sources the badge needs.
Source paths in your previews
Stamps are plain attributes in your HTML. Anyone who can load a stamped page can read its file paths and component names in the page source.
For that reason, setup turns on stamps for preview and local builds only, and keeps production builds free of anything from Skyelight. Previews can still be public. For example, Vercel previews are public unless you turn on Deployment Protection.
If your previews are public and you don’t want your directory or component
names visible, set stamp: false in the plugin options. In a config without
a production key, SKYELIGHT_STAMP=0 does the same. The badge works
without stamps, and threads are saved without a source location.
What the plugin sends
The plugin sends nothing. It runs inside your build, adds attributes and a script tag, and makes no network calls. Your code stays on your machine or in your CI.
What the badge costs a visitor
The badge script is about 1.5 kB. For a visitor who isn’t reviewing, it makes no request, adds nothing to the page, stores nothing and starts no timer. It reads one flag and stops, so Skyelight receives nothing about visitors who don’t review.
The rest of the badge, about 250 kB, loads only when the badge starts: from a
link with ?skyelight=1, for a browser that has signed in on that site
before, or on Next.js previews and local builds, where the build shows the
badge’s mark on arrival. See
When the badge shows up. If the
visitor has the Skyelight Chrome extension installed, the
badge removes itself.
How reviewers sign in
- The first time, the badge redirects the reviewer to Skyelight to sign in, then back to the page. It uses a full-page redirect because Safari’s tracking prevention blocks sign-in through hidden iframes.
- After signing in, that browser stays signed in to the badge on that site for 30 days. The session doesn’t apply to other sites.
- The badge signs people in only on the project’s preview URLs, and only people who are members of the workspace.
- When you remove someone from the workspace, their badge stops working within about five minutes. When you remove an address from the list, every session on that address ends.
What a thread captures, how form fields are masked and how long captured data is kept are covered in Anchoring and context.
Content-Security-Policy
If your site sends a Content-Security-Policy, add these sources. If the policy blocks them, the badge doesn’t load, and the browser console shows the blocked request:
script-src https://app.skyelight.ai the badge script
connect-src https://*.convex.cloud the pins themselves
https://app.skyelight.ai signing in
frame-src https://app.skyelight.ai the thread drawer
img-src https://app.skyelight.ai avatars and marks
https://*.convex.cloud screenshots and attachments
data: blob: screenshots while they are taken
style-src 'unsafe-inline' the badge's own stylesStamps need nothing from your CSP, because they are only attributes.