Privacy Policy

Last updated: June 18, 2026

Kickbacks is a VS Code extension that shows a small sponsored line in the Claude Code and Codex spinners and pays you a share of the ad revenue. This page describes exactly what data the extension and the kickbacks.dev services handle. The short version: we measure ads, we never read your work.

What we never collect

Sign-in and Google user data

Signing in uses Google, GitHub, or Apple OAuth. We receive and store your provider account identifier, your email address, and your display name. We never see your provider password.

Google sign-in uses the openid, email, and profile scopes. Through that sign-in flow, Google sends Kickbacks:

We use this Google user data only to:

We do not receive or store your Google password. We do not store Google OAuth access tokens or Google OAuth refresh tokens. We do not request or access Gmail, Google Drive, Google Calendar, contacts, or other Google content. After sign-in, the extension and web dashboard use Kickbacks-issued tokens to talk to Kickbacks; they do not keep calling Google APIs.

We store your Google account identifier, email address, and display name in our account database for as long as your Kickbacks account is active or as needed for the accounting, security, and legal purposes described here. Temporary OAuth handshake records expire within minutes after sign-in completes or fails.

We do not sell Google user data, transfer it to advertisers, use it for retargeting or personalized advertising, use it to determine creditworthiness, or use it to develop, improve, or train generalized AI or machine learning models. You can use ads in demo mode without signing in at all; demo mode is tied only to the random device identifier below, not to any Google account.

Ad measurement events

To credit your earnings and bill advertisers, the extension reports an event when an ad is fetched, shown, viewed, or clicked. Each event contains:

These events are the billing ledger between you and advertisers, so we retain them. Serving tokens expire and are deleted within 24 hours.

Earnings and payouts

We keep a ledger of what you have earned and what has been paid out. Payouts run on a configured Stripeconnected-account path: when you set up payouts, we may send Stripe your email address and selected payout country to start that flow, and your bank and identity details go directly to Stripe through their hosted onboarding — we never see or store them. We store only your Stripe account identifier, payout country, and payout history. Stripe’s handling of your data is described in the Stripe Privacy Policy.

Service checks

The extension periodically polls our kill switch (so we can stop ad serving remotely if something goes wrong) and checks for extension updates. These requests carry version strings and no account identity.

The extension asks for your consent in-editor before measurement begins, and asks again whenever the terms version changes. Telemetry is opt-in.

Who we share data with

Retention and deletion

Sign-in handshake records live for minutes; serving tokens for up to 24 hours; provider account identifiers, email addresses, and display names are retained while your account is active; measurement events and the earnings ledger are retained as accounting, fraud-prevention, and payout records. To access or delete your account data, email privacy@kickbacks.dev from your sign-in address.

Security

Provider sign-in data is transmitted over HTTPS and stored with provider-managed access controls and at-rest protections. Operational access is limited to support, security, legal, and abuse-prevention needs. Kickbacks access tokens expire, refresh tokens rotate, and active token lookup is performed by stored token hashes rather than raw token strings.

Changes

We will update this page when our practices change, and material changes re-trigger the in-editor consent prompt with a new terms version.