Privacy Policy for KeepIt
KeepIt is designed with data minimization and transparency at its core. For offline users, saved sessions,
auto-save snapshots, and settings are stored locally in your browser (chrome.storage.local). If you
choose to sign in and enable Cloud Sync or Session Sharing, your selected session data is synced securely to our
database. KeepIt inspects open tab metadata (titles, URLs, favicons) strictly to save sessions, organize
folders, and manage tab freezing—never to track your personal browsing history, profile your activity, or serve
advertisements.
1 What Information We Collect
Depending on how you use KeepIt (offline local mode vs. optional Google Sign-in & Cloud Sync), we collect and process the following categories of data:
chrome.identity, we receive your email address, full name,
profile picture, and Google User ID. We never receive or store your Google password.
What we do NOT collect: We do not track ambient browsing activity outside of open tabs you explicitly save, we do not log form inputs or page contents, and we do not run third-party advertising or analytics trackers.
2 How We Use Your Data
We process data strictly to provide, maintain, and support the core functionality of KeepIt:
- Saving & Restoring Sessions: Capturing open window tabs, Tab Groups, and folders so you can restore them instantly.
- Auto-Save Recovery: Storing local periodic snapshots so you can recover lost browser tabs after unexpected Chrome crashes.
- Auto-Freeze Feature: Monitoring tab idle times locally to discard inactive background tabs and free up system RAM.
- Cloud Syncing (Opt-In): Uploading sessions to our database provider, Supabase, so you can restore your tab sessions across multiple computers or browsers.
- Peer Session Sharing: Delivering shared session packages directly to another user's shared inbox using their chosen username.
- Subscription Verification: Verifying Pro plan status via secure webhooks to unlock premium features (e.g. unlimited cloud sync, enhanced auto-save frequencies).
3 Third-Party Service Providers
We work with trusted third-party service providers to handle infrastructure, authentication, and payments under strict data handling standards:
- Google LLC (Google Identity Services) — Handles authentication via OpenID Connect OAuth 2.0. Governed by Google's Privacy Policy.
-
Supabase Inc. — Serves as our secure backend database provider (
*.supabase.co) to host cloud-synced sessions, folders, usernames, and subscription metadata. Governed by Supabase's Privacy Policy. - Lemon Squeezy, LLC — Our Merchant of Record; manages subscription payments and checkout. When upgrading to Pro, Lemon Squeezy collects payments directly under its PCI-DSS compliant infrastructure. Governed by Lemon Squeezy's Privacy Policy.
We do not sell, rent, or trade your personal data to any third parties or advertisers.
4 Extension Permissions Explained
Chrome requires explicit permissions for extensions to interact with your browser. KeepIt requests only necessary permissions:
tabs: Required to read tab titles, URLs, and favicons when saving sessions, and to discard inactive background tabs for Auto-Freeze.tabGroups: Required to preserve native Chrome Tab Group titles, colors, and collapsed states.storage: Required to store your sessions, folders, auto-save snapshots, and settings locally on your device.alarms: Required to trigger background auto-save snapshots and periodic subscription re-verifications.sessions: Required to support recovery of recently closed windows.identity: Required to open the Google OAuth sign-in flow.
5 Data Storage & Security
Local Storage: Local sessions and auto-save snapshots are kept strictly inside Chrome's
isolated extension storage (chrome.storage.local) on your local hard drive.
Cloud Security: All cloud-synced data transmitted to Supabase is encrypted in transit using TLS 1.2/1.3 (HTTPS). Cloud database access is restricted using Supabase Row Level Security (RLS) policies—ensuring your saved sessions and folders are only accessible by your authenticated Google account (or designated recipients you explicitly share sessions with).
6 Data Retention & Your Controls
- Local Deletion: You can edit or delete any saved session, folder, or auto-save snapshot
anytime inside the KeepIt extension. Uninstalling the extension automatically removes all local data stored in
chrome.storage.local. - Cloud Session Deletion: Deleting a cloud session inside KeepIt permanently removes it from our cloud database.
- Full Account Deletion: You may request complete deletion of your KeepIt account, username profile, and all associated cloud-stored data by emailing us at contact.naveen.work@gmail.com. We will process and confirm account deletion requests within 30 days.
- Subscription Cancellation: You can cancel your Pro subscription anytime via the extension settings. Subscription cancellation takes effect at the end of the current billing cycle.
7 Children's Privacy
KeepIt is not directed at children, and we do not knowingly collect personal information from children under the age of 13 (or the minimum legal age in your jurisdiction). If we learn that a child under 13 has provided us with personal information, we will delete it promptly.
8 Policy Updates
We may update this Privacy Policy from time to time to reflect feature additions or legal requirements. Material updates will be posted on this page with a revised "Effective Date" at the top.
Questions or Data Requests?
If you have any questions about this Privacy Policy, data privacy rights, or wish to request complete account deletion, please get in touch:
Contact Support Email