Browser extension privacy
Published by Colin Knapp · Updated September 9, 2026
This policy covers the Chrome/Chromium and Firefox versions of the 11 extensions listed below. It describes data accessed and processed on your device as well as data sent outside the extension. Local processing still involves handling data, even when nothing is sent to the publisher.
The extensions do not sell user data or use it for advertising, tracking, or analytics. Each uses data only for its described features. Explicit transfers, including conversion, image search, clipboard copying, local application handoffs, and media downloads, are explained below.
Find your extension
- Context Restore
- Element Note
- Feed Scout
- Image Relay
- Markdown Press
- Page Ferry
- Reload Pin
- Request Courier
- Tab Shepherd
- Video Sieve
- Tempo — Video Speed Control
Context Restore
Context Restore runs on ordinary webpages to restore right-click, selection, and copying. It handles context-menu, selection-start, and copy events, but does not read selected text or clipboard contents. It does not retain page content, URLs, tab metadata, forms, cookies, or browsing history.
Local extension storage holds only two on/off preferences: right-click restoration and selection/copy restoration. They remain until changed or the extension's local data is removed. The extension makes no background network requests.
Element Note
After you choose Pick an element, Element Note reads element geometry for its outline. Selecting an element creates a local snapshot of the page title and address, visible text, accessible labels, structural identifiers, geometry, computed styles, and nearby ancestor structure. An optional request you type stays with the snapshot in memory.
It omits form values, editable and hidden text, raw HTML content, cookies, browser history, and stored credentials. It removes URL user information, query strings, and fragments. Visible text, titles, paths, and identifiers can still contain personal information.
Clicking an element or Copy for AI writes the note to your system clipboard. No AI service receives it from the extension; you choose where to paste it. Closing the picker, starting a new selection, or leaving the page clears the draft, but does not erase the clipboard. Chrome's temporary clipboard document clears its text after copying and closes. There is no persistent extension storage or publisher transmission.
Feed Scout
Opening Feed Scout inspects the active page's feed-discovery link declarations and base URL to find RSS, Atom, and JSON feed addresses. It does not read general page content or fetch feeds. Results stay in popup memory and disappear when it closes; there is no stored browsing history.
Copy URL writes the chosen address to your clipboard. Opening a feed sends your browser to that destination only after you click it. Feed Scout does not send results to the publisher or run automatically on pages.
Image Relay
An image-menu link-search action reads the selected image URL and sends it to your chosen provider in a new tab. That provider may retrieve, process, retain, or index the image under its own policies. URL checks cannot identify every private or signed URL, so choose only public images you intend to share.
Manual-upload actions open the provider's page without the image URL. Any later upload takes place on that website under its controls. Provider pages may use normal website cookies, and result URLs may enter browser history and sync.
Image Relay does not download images, inspect page content, read form values or cookies, access browsing history, or save image URLs. It has no extension storage or publisher backend and sends no image data to the publisher.
Markdown Press
Pressing Convert sends your entered Markdown and selected document fields over HTTPS to md.colinknapp.com to generate the HTML, DOCX, or PDF you requested. Submitted fields are markdown, template, output_format, and any non-empty optional title, subtitle, contact, and footer fields. Include only information you intend to submit to that service.
Refresh templates from service requests template names without document content or metadata. Opening the editor makes no network request. The extension does not access or send the current webpage's URL or title, browsing activity, cookies, or analytics.
Editor content stays in the live tab's memory. The extension stores no documents or conversion history. Downloaded files remain on your device until you remove them. These local-retention statements do not establish a retention period for the conversion service's server logs.
Page Ferry
Opening Page Ferry temporarily reads the active page title, URL, and selected text to show a preview. Nothing leaves the browser during preview. The values stay in popup memory and disappear when it closes.
Send to Logseq places the previewed title, URL, and optional selection into a logseq://x-callback-url/quickCapture URL. The browser hands this to the application registered for the Logseq protocol, normally Logseq. This is a transfer outside the extension even when the application runs on the same computer. That application controls subsequent handling, including any storage or sync.
Page Ferry has no server, network requests, persistent extension storage, cookie access, or clipboard access. It does not capture automatically or send captures to the publisher.
Reload Pin
Reload Pin processes tab IDs, opaque request IDs, and the numeric HTTP status of a matching scheduled reload to decide when to stop retrying. For unrelated main-frame requests, it checks only tab and request IDs and stores nothing. It does not inspect page content, URLs, titles, headers, response bodies, forms, cookies, or credentials.
Schedule data includes the tab ID, interval, pin ownership, stop-on-success choice, timing values, and a request correlation ID while a retry is outstanding. Chrome keeps this in session storage; schedules end when Chrome closes or the extension reloads, updates, or is disabled. Firefox uses local extension storage. In both versions, stopping a schedule or closing its tab removes the schedule data. HTTP status codes are not retained.
Reload Pin does not send this data to a service. Scheduled reloads cause the browser to request the page from its website as a normal reload would.
Request Courier
Opening Request Courier takes a one-time local snapshot of the active page URL and resource URLs available in the page's Performance Resource Timing buffer. Up to 500 validated HTTP or HTTPS URLs stay in popup memory until it closes. Ordinary commands contain the selected URL and browser user-agent string, without cookies, authorization, request bodies, form data, referrers, or captured headers.
The optional session-cookie action reads cookies only after a warning, an optional permission grant for the selected site's scheme and hostname, and a fresh confirmation. Cookie values stay only in the local preview's memory for revealing or copying the command. They are not stored, logged, cached, synced, or sent to a service, and disappear when the preview closes. Optional permission grants may remain until you revoke them in the browser's extension settings.
Copying writes the command to your system clipboard. URLs can contain private query values, and cookie commands can contain sensitive session information. Review before copying or sharing. The extension never executes the command; if you run it yourself, it sends the command's request data to its destination. There is no persistent extension storage or publisher transmission.
Tab Shepherd
Tab Shepherd reads tab URLs, titles, window and group membership, and tab state to preview and organize tabs locally. It does not read page bodies, forms, cookies, credentials, or the browser's history database, and does not transmit browsing data.
Undo records describe the previous tab arrangement and groups. Chrome keeps undo in session storage, which survives popup closure but not a browser restart. Settings and optional tab-observation history use local storage. History is off by default; when enabled, popup refreshes retain up to 500 observations of supported open tabs, including IDs, URLs, titles, observation times and counts, last-accessed times, and whether each tab is still present. You can pause or clear this history.
Firefox also supports optional popup-driven cleanup and a local record of up to 100 recently cleaned tabs for recovery, including tab URLs, titles, and group details. Chrome does not offer automatic cleanup. Local settings and retained history remain until cleared, replaced by newer records within the limits, or removed with the extension's local data.
Video Sieve
Opening Video Sieve scans media-source URLs and technical video metadata in the active page, accessible same-origin frames, and open shadow roots. It reads declared type, dimensions, duration, player counts, and the active page URL for site recognition. It does not read page text, forms, cookies, credentials, browser history, other tabs, or cross-origin frame contents.
Save video… requests optional downloads permission and gives the selected direct URL and suggested filename to the browser, which requests the file from its host. The discovery results disappear when the popup closes.
Find more videos, Find YouTube video, or Find stream video requests optional local-helper access and sends the selected page or stream URL to the separately installed Video Sieve helper on your computer. The helper uses yt-dlp to request pages, player responses, manifests, and media metadata from the site's services and media hosts. Those destinations receive ordinary network requests, including your connection's IP address and the requested URL. Returned titles and technical metadata appear in the popup.
Save best quality asks the helper to download media and merge audio and video if needed. The helper does not import browser cookies, sign-in sessions, or credentials. It writes files under Downloads / Video Sieve; cancellation or failure may leave a partial file. Saved and partial files remain until you remove them, as do installed helper files and tool-path settings.
Save progress, filenames, and errors stay only in background memory: Chrome clears them when its service worker stops, and Firefox clears them when its background page unloads or the browser closes. The extension has no persistent browsing or download database and sends no media or browsing data through a publisher service.
Tempo — Video Speed Control
Tempo (project name video-tempo) runs on YouTube's desktop and mobile websites to handle playback-speed shortcuts and change video playback speed. It ignores shortcuts in editable controls. It stores one local preference, preferredSpeed, to restore your choice across navigation and browser restarts.
This preference stays until changed or the extension's local data is removed. Tempo does not use browser sync storage or make network requests. It has no account, tracking identifier, telemetry, or remote service.
Copies, destinations, and deletion
Clipboard copies, downloaded files, browser history, and data handed to another application can outlast the extension's own memory. Your operating system or other applications may access or sync clipboard contents. Clear these copies through the application that holds them; closing or uninstalling an extension does not erase them.
You can stop using an extension, revoke optional permissions, or remove it through your browser's extension manager. Use its clear-history controls where available. Local data is not available to the publisher for remote deletion. For data you deliberately send to a service, its handling and deletion options apply. No fixed server-log retention period is asserted by this policy.
Optional publisher links open only when clicked. Visiting ColinKnapp.com is separate from using an extension: this website loads Matomo, PostHog, and Notomo analytics. The statements above about extensions having no analytics do not describe website visits. Other destination websites may use their own cookies and storage.
Limited Use
Our use of user data, including information received through Google APIs where applicable, complies with the Chrome Web Store User Data Policy and its Limited Use requirements. We use data only to provide the disclosed purpose of each extension. We do not sell it, use it for personalized advertising, transfer it to data brokers, or use it to determine creditworthiness or lending eligibility. Transfers are limited to the described features you choose and other circumstances permitted by that policy. Human access is limited to its permitted circumstances, such as your explicit consent, security needs, or legal requirements.
Contact
For extension privacy questions, contact chrome-extensions@colinknapp.com. Include the extension name and browser, but do not send passwords or session cookies.