Last updated: August 20, 2026
This policy explains how the Provide feedback and My feedback features handle data. This is a user-initiated support submission, not telemetry or behavior analytics. Opening, editing, or closing the form does not transmit data.
Information collected and purpose
Before anything is sent, the extension shows the complete payload and requires explicit confirmation. Required fields are the feedback type, title, and user-written description. Reproduction steps and the expected result are optional.
Basic environment information is enabled by default but can be disabled. It is limited to allowlisted values such as the Singular Blockly and VS Code versions, operating-system family and major version, architecture, interface language, normalized host and workspace types, workspace trust, selected board, programming language, relevant tool versions or readiness, and the last stable error stage and code. Recent structured events are disabled by default and, when enabled, contain only bounded timestamps, stages, stable event codes, and outcomes.
The feature does not automatically read or send source code, Blockly workspace content, generated code, file or folder names, full or partial paths, machine or device identifiers, serial ports, Wi-Fi information, IP addresses, environment variables, tokens, credentials, raw errors, or raw logs.
One screenshot may be attached voluntarily. It is re-encoded locally, original metadata is removed, and it is limited to 1920 pixels and 3 MiB before a second server-side check. Visible names, email addresses, paths, program content, or other private information may still appear, so the preview must be checked before sending.
Identity, network, and security data
The extension creates a random 256-bit secret in VS Code SecretStorage so the reporter can view, add to, or delete their feedback without an account. The service stores only a server-keyed, non-reversible HMAC representation. A backup link places the secret in the URL fragment, which is not sent in a normal HTTP request; after exchange, the browser uses an HttpOnly, Secure, SameSite session lasting at most 24 hours.
Cloudflare may process the source network address briefly to protect the service. The application uses only an HMAC-derived value for rate limiting and does not store the raw IP address in the feedback database. Cloudflare, network providers, and GitHub may process request metadata under their own security-log policies.
Processors, location, and cross-border transfer
Feedback text and state are stored in Cloudflare D1, and screenshots are stored in a private Cloudflare R2 bucket. A maintainer working copy is synchronized to a project-maintainer-only private GitHub repository.
Cloudflare and GitHub may process and back up data in different countries or regions, so data may be transferred across borders under their infrastructure, terms, and security-backup policies.
Maintainer access and public summaries
Internal maintainer notes are private by default. Only an explicit public reply or public status action is shown to the reporter.
A public development issue can be created only after separate project-owner approval and may contain only a de-identified summary. The public issue is not linked back to the private feedback record.
Retention, deletion, and backups
Feedback content, public messages, and screenshots are retained until the reporter deletes them. Idempotency records are intended to remain for 7 days, browser sessions for at most 24 hours, and content-free security audit records for at most 90 days. Rate-limit and external-event deduplication data use shorter or otherwise bounded retention.
Deleting one or all reports removes primary content, public messages, screenshots, and original content from the private GitHub working copy. A content-free deletion tombstone may remain to prevent retry-based restoration. An owner-approved de-identified public development issue may remain.
Cloudflare, GitHub, or other provider security backups may retain encrypted copies briefly under provider policy and cannot always be erased item-by-item immediately. The service does not promise immediate deletion from every backup.
Children and students
Singular Blockly is often used in education, but the feedback form does not request a name, email address, or age. Students should not include their own or another person's personal information in text or screenshots and should ask a teacher, parent, or guardian to review the payload when needed. Obtain guardian consent first where applicable law requires it.
Rights and contact
Use My feedback or the private backup link to view, add to, and delete data. Use the Support page for general support or privacy requests. Report security vulnerabilities through the private process in the project SECURITY.md, not through public feedback.
If the anonymous secret and backup link are lost, we cannot safely prove ownership and may be unable to recover or delete a specific report. Material policy changes are disclosed in the extension changelog and this policy.