Docs menu
Docs/Lyba Framer

What the plugin adds to your site

Lyba is a client review tool, so a small amount of project information has to reach Lyba before your client can review the site. The plugin keeps this to the minimum the feature needs, and it adds exactly one script to your site.

Nothing is sent until you connect the project

Opening the plugin doesn't send any project data. After you sign in, the plugin stops on Connect this project to Lyba, which lists each field it will send and why. No project data leaves Framer until you click Connect project.

Consent is recorded per Framer project, not per browser. Connecting one project never connects another, and every new project asks again. Signing out clears it, so a different Lyba account has to connect the project again.

What is sent to Lyba, and why

When you connect the project

  • Framer project ID. Sent when you click Connect project. It lets Lyba recognise the same Framer project each time you open it, so reconnecting doesn't create a duplicate. It's never shown to clients.
  • Project name. Sent when you connect. It labels the project in your Lyba dashboard so you can tell projects apart.
  • Published URL (your production URL, otherwise your staging URL). Sent when you connect, then kept in sync while the project is connected. The review overlay only runs on your published site, and the client's review link points at it. If you republish to a new domain, Lyba follows it so existing review links keep working.

When you create a review session

  • Session name. It names the round in the dashboard and on the client's review link.
  • Client email (optional). It lets Lyba email the review link. Leave it blank to share the link yourself; then no email is sent or stored.
  • Pages to review (optional). They scope the review to specific pages and show your client "Reviewing N pages".

No page content, designs, layers, component code, assets or other project metadata are sent. Nothing is sent for a project you never connect.

The custom code the plugin manages

To make client feedback possible, the plugin adds one <script> to your site's End of <body> custom code:

html
<!-- lyba:overlay start -->
<script src="https://lyba.io/v/<version>/overlay.js" defer></script>
<!-- lyba:overlay end -->

<version> is the overlay version number. The plugin shows the exact line for your site before it installs anything.

Installing is always your choice

Opening a project never changes your site. When a project doesn't have the review script yet, the plugin shows Install the review script with the exact line for your site, and waits for you to click Install review script. Review sessions can't be created until it's installed, because a review link without the overlay would show your client nothing.

Your own code is never overwritten

The snippet is wrapped in lyba:overlay marker comments and added after whatever custom code you already have in End of <body>. Your existing code is kept as it is.

It does nothing for ordinary visitors

The overlay script exits straight away unless a Lyba review token is in the URL, so visitors to your live site never see it.

Removing it is explicit too

Use Remove review script in the project menu, or Close project. Both ask you to confirm in the plugin, then remove only Lyba's snippet (the marked block, plus any tag written by an older version of the plugin) and leave everything else in place. Closing a project also archives its open sessions; you can reopen the project later.

The plugin checks your site, not a saved setting

While the plugin is open, it reads your site's actual custom code rather than trusting a cached setting. If you delete the tag by hand, or switch custom code off in Framer, the plugin notices straight away.

  • If it can't read your custom code, the plugin says so and pauses new sessions until it can.
  • If you switch custom code off, the plugin says so and pauses new sessions: the tag is still there, but no feedback can reach Lyba. A plugin can't turn custom code back on for you. Only you can, in Framer's custom-code settings.

It respects your Framer role

Editing custom code is a role-gated permission in Framer. If your role can't edit custom code, the plugin doesn't read or watch your custom code at all. Installing, removing, closing the project and creating sessions are unavailable, and the plugin explains why next to each disabled action. Ask the project owner to set up the review, or to give you access. Existing sessions still open normally.

The hosted overlay script

What happens on your site depends on one JavaScript file that Lyba hosts at a stable lyba.io address. The path is a fixed Lyba address on purpose, so the tag on your site never exposes where the file is actually stored, and Lyba can move its backend without touching the tag on already-published sites.

Versions never change underneath you

  • Each version of the overlay is a separate file that is never republished with different contents, and it's cached as immutable. Your site stays on the exact version it was installed with, so a new overlay release can't change how an already-published site behaves.
  • Breaking changes ship as a new version path, such as /v/2/overlay.js, and only new installs point at it. Sites on an earlier version keep loading their version untouched. Lyba never rewrites your custom code behind your back.
  • Reinstalling the review script from the plugin moves a site onto the current version.
  • One exception, for transparency: sites installed before versioning load the unversioned https://lyba.io/v/overlay.js. That path does receive updates, and changes to it stay backward-compatible. Reinstalling the script moves such a site onto a pinned, versioned path.

The overlay is small, framework-free JavaScript that exits unless a review token is present, so it stays inactive for real visitors whatever its version. When a reviewer chooses to record their review, the overlay loads a separate recorder script from the same versioned path.

Network activity while the plugin is open

The plugin checks Lyba for new activity at intervals rather than holding a live connection open. This is scoped and slows itself down:

  • Only the visible view checks for updates. The session list updates on the Active and Approved tabs, the activity feed only on the Activity tab, and comments only while a session is open. Only one of these runs at a time.
  • It backs off when nothing changes. A check that finds nothing new stretches the interval from 30 seconds to 60, then 120. Any new comment, reply or approval, switching tabs, or coming back to the tab resets it to 30 seconds.
  • It pauses when hidden. All checks stop while the Framer tab is in the background, and catch up as soon as you return.
  • Your own changes show up immediately. Checking only exists to pick up other people's activity.