Skip to Content
Skyelight BuildPrivacy and CSP

Privacy and CSP

This page describes what Skyelight Build adds to your pages, what the review badge loads and stores for visitors, and how reviewers sign in. It also lists the Content Security Policy sources the badge needs.


Source paths in your previews

Stamps are plain attributes in your HTML. Anyone who can load a stamped page can read its file paths and component names in the page source.

For that reason, setup turns on stamps for preview and local builds only, and keeps production builds free of anything from Skyelight. Previews can still be public. For example, Vercel previews are public unless you turn on Deployment Protection.

If your previews are public and you don’t want your directory or component names visible, set stamp: false in the plugin options. In a config without a production key, SKYELIGHT_STAMP=0 does the same. The badge works without stamps, and threads are saved without a source location.

What the plugin sends

The plugin sends nothing. It runs inside your build, adds attributes and a script tag, and makes no network calls. Your code stays on your machine or in your CI.

What the badge costs a visitor

The badge script is about 1.5 kB. For a visitor who isn’t reviewing, it makes no request, adds nothing to the page, stores nothing and starts no timer. It reads one flag and stops, so Skyelight receives nothing about visitors who don’t review.

The rest of the badge, about 250 kB, loads only when the badge starts: from a link with ?skyelight=1, for a browser that has signed in on that site before, or on Next.js previews and local builds, where the build shows the badge’s mark on arrival. See When the badge shows up. If the visitor has the Skyelight Chrome extension installed, the badge removes itself.

How reviewers sign in

  • The first time, the badge redirects the reviewer to Skyelight to sign in, then back to the page. It uses a full-page redirect because Safari’s tracking prevention blocks sign-in through hidden iframes.
  • After signing in, that browser stays signed in to the badge on that site for 30 days. The session doesn’t apply to other sites.
  • The badge signs people in only on the project’s preview URLs, and only people who are members of the workspace.
  • When you remove someone from the workspace, their badge stops working within about five minutes. When you remove an address from the list, every session on that address ends.

What a thread captures, how form fields are masked and how long captured data is kept are covered in Anchoring and context.

Content-Security-Policy

If your site sends a Content-Security-Policy, add these sources. If the policy blocks them, the badge doesn’t load, and the browser console shows the blocked request:

script-src  https://app.skyelight.ai      the badge script
connect-src https://*.convex.cloud        the pins themselves
            https://app.skyelight.ai      signing in
frame-src   https://app.skyelight.ai      the thread drawer
img-src     https://app.skyelight.ai      avatars and marks
            https://*.convex.cloud        screenshots and attachments
            data: blob:                   screenshots while they are taken
style-src   'unsafe-inline'               the badge's own styles

Stamps need nothing from your CSP, because they are only attributes.

Last updated on