Skip to content

Lit Inspector privacy policy

This page is the privacy policy of Lit Inspector, the browser extension for Chrome and Firefox that inspects Lit components from DevTools. It covers the extension only; the Vite plugin and the lit-devtools CLI run on your own machine and are not part of it.

Last updated: 7 October 2026.

Lit Inspector is an independent, unofficial tool. It is not affiliated with, endorsed by, or produced by Google, Mozilla or the Lit project.

Lit Inspector collects no personal data and sends nothing anywhere. It has no server, no analytics, no telemetry and no accounts. Everything it keeps stays in your browser, and removing the extension removes it.

What Where Why
Enabled sites chrome.storage.local, key enabledOrigins The sites you clicked Enable on this site for: origins in Chrome (https://example.com), hosts in Firefox (http://localhost).
Panel settings chrome.storage.local, keys devframe:settings:* Your preferences in the Lit tab, such as appearance and performance tracks.
Panel preferences mirror The extension’s own localStorage A synchronous copy of the same preferences, so the panel paints with them before storage answers.
Page-side preferences The enabled site’s localStorage, lit-devtools-* The preferences the injected runtime applies in the page, such as update flashing and the color scheme.
Tab identifiers The enabled site’s sessionStorage A random id per browser tab, so a panel talks to the right tab. Cleared when the tab closes.

chrome.storage.local is local to your browser profile; the extension does not use chrome.storage.sync. The two page-side rows apply only to sites you enabled, and hold only the values listed.

The extension reads the Lit components of a page you enabled (their tag names, properties, state and update timings) to show them in the Lit tab. That data stays in memory in DevTools and is gone when you close it. A timeline recording is not saved.

The extension does not:

  • send any data to the developer or to anyone else, or make network requests other than fetching an enabled site’s own scripts, sourcemaps and Custom Elements Manifests from that site, to show where a component is defined and what its documentation says;
  • collect personal information, browsing history, page content, form input, cookies or credentials;
  • run analytics, telemetry, crash reporting or advertising;
  • load or execute code from outside the extension package.
Permission Why
scripting Registers two content scripts on the sites you enabled: one in the page’s main world that reads Lit component state for the panel, and one in the isolated world that relays it to the panel.
storage Keeps the enabled sites and the panel settings listed above.
activeTab (Firefox only) Lets the toolbar popup read the address of the tab you opened it on, to name the site it would enable. Nothing else is read, and only after your click.
Host access (<all_urls>, optional, per site) Not granted at install. When you click Enable on this site, the browser asks for that one site: the origin in Chrome, the host on any port in Firefox. The grant registers the content scripts there and lets the Lit tab fetch the site’s scripts and sourcemaps.
  • One site. In the Lit tab (or Firefox’s toolbar popup), click Disable on this site. The extension unregisters its scripts and forgets the origin. Removing the site’s permission in the extension’s details does the same.
  • Everything. Remove the extension at chrome://extensions or about:addons. The browser deletes its chrome.storage.local data and its own localStorage.
  • Page-side keys. Keys the runtime left in an enabled site’s storage stay with that site. Clear them from the site’s data in the browser’s settings, or in DevTools under Application > Storage (Firefox: Storage).

Changes to this policy are published on this page, with a new date above, and recorded in the repository’s history.

Open an issue at github.com/oddcelot/vite-plugin-lit/issues.