Privacy Policy
Last updated: June 18, 2026
Kickbacks is a VS Code extension that shows a small sponsored line in the Claude Code and Codex spinners and pays you a share of the ad revenue. This page describes exactly what data the extension and the kickbacks.dev services handle. The short version: we measure ads, we never read your work.
What we never collect
- Your source code or file contents. The extension does not read, store, or transmit the contents of your projects.
- Your prompts or AI conversations. What you say to Claude Code or Codex, and what they say back, never leaves your machine through us.
- Keystrokes or browsing activity.
Sign-in and Google user data
Signing in uses Google, GitHub, or Apple OAuth. We receive and store your provider account identifier, your email address, and your display name. We never see your provider password.
Google sign-in uses the openid, email, and profile scopes. Through that sign-in flow, Google sends Kickbacks:
- a stable Google account identifier,
- your Google account email address,
- your Google profile or display name, and
- short-lived OAuth handshake data, such as the authorization code and ID token used to finish sign-in.
We use this Google user data only to:
- create or find your Kickbacks account,
- issue Kickbacks session tokens for the VS Code extension and kickbacks.dev dashboard,
- credit ad measurement events and earnings to the correct account,
- show your email, earnings, consent state, payout state, and recent credited activity in the user dashboard,
- match advertiser campaigns to the signed-in Google email when you use the advertiser dashboard or prefill a billing email field,
- pass your email to Stripe when you start payout onboarding, so Stripe can create or connect the payout account, and
- provide support, process account deletion requests, enforce the terms, and investigate fraud or abuse.
We do not receive or store your Google password. We do not store Google OAuth access tokens or Google OAuth refresh tokens. We do not request or access Gmail, Google Drive, Google Calendar, contacts, or other Google content. After sign-in, the extension and web dashboard use Kickbacks-issued tokens to talk to Kickbacks; they do not keep calling Google APIs.
We store your Google account identifier, email address, and display name in our account database for as long as your Kickbacks account is active or as needed for the accounting, security, and legal purposes described here. Temporary OAuth handshake records expire within minutes after sign-in completes or fails.
We do not sell Google user data, transfer it to advertisers, use it for retargeting or personalized advertising, use it to determine creditworthiness, or use it to develop, improve, or train generalized AI or machine learning models. You can use ads in demo mode without signing in at all; demo mode is tied only to the random device identifier below, not to any Google account.
Ad measurement events
To credit your earnings and bill advertisers, the extension reports an event when an ad is fetched, shown, viewed, or clicked. Each event contains:
- the event type and a one-time identifier used to deduplicate it,
- which ad and campaign were shown, and a short-lived serving token,
- a random device identifier generated on install (it identifies the installation, not you or your hardware),
- timestamps and how long the ad was visible,
- the extension version and the Claude Code version string,
- basic environment info: operating system and version, CPU architecture, and editor name (e.g.
darwin,arm64,Visual Studio Code).
These events are the billing ledger between you and advertisers, so we retain them. Serving tokens expire and are deleted within 24 hours.
Earnings and payouts
We keep a ledger of what you have earned and what has been paid out. Payouts run on a configured Stripeconnected-account path: when you set up payouts, we may send Stripe your email address and selected payout country to start that flow, and your bank and identity details go directly to Stripe through their hosted onboarding — we never see or store them. We store only your Stripe account identifier, payout country, and payout history. Stripe’s handling of your data is described in the Stripe Privacy Policy.
Service checks
The extension periodically polls our kill switch (so we can stop ad serving remotely if something goes wrong) and checks for extension updates. These requests carry version strings and no account identity.
Consent
The extension asks for your consent in-editor before measurement begins, and asks again whenever the terms version changes. Telemetry is opt-in.
Who we share data with
- Processors: Google, GitHub, and Apple (sign-in), Convex (database and API hosting), Vercel (web hosting and API proxying), and Stripe (payout onboarding and payouts).
- Advertisers see aggregate statistics only — impression and click counts — never your identity, email, or device identifier.
- We may disclose limited account or event data when needed to comply with law, enforce our terms, protect the service, or investigate abuse.
- We do not sell personal data, and we do not share Google user data with ad networks, data brokers, or information resellers.
Retention and deletion
Sign-in handshake records live for minutes; serving tokens for up to 24 hours; provider account identifiers, email addresses, and display names are retained while your account is active; measurement events and the earnings ledger are retained as accounting, fraud-prevention, and payout records. To access or delete your account data, email privacy@kickbacks.dev from your sign-in address.
Security
Provider sign-in data is transmitted over HTTPS and stored with provider-managed access controls and at-rest protections. Operational access is limited to support, security, legal, and abuse-prevention needs. Kickbacks access tokens expire, refresh tokens rotate, and active token lookup is performed by stored token hashes rather than raw token strings.
Changes
We will update this page when our practices change, and material changes re-trigger the in-editor consent prompt with a new terms version.