Privacy policy

Your pool is end-to-end encrypted with your join code. The service cannot read your bookmarks or your extension list.

End-to-end encryption

Your browsers encrypt all pool data with keys derived from your join code before anything leaves the device. The join code never leaves your browsers. Without it, nobody can decrypt the pool — not the service, and not the operator of a self-hosted server.

What the service stores

  • Encrypted pool revisions (ciphertext)
  • Ciphertext hashes and keyed state hashes
  • Device public keys and the device names you choose

The service never stores plaintext bookmarks, extension lists, join codes, or encryption keys. It cannot recover a lost join code.

What the service does not do

  • No accounts, emails, or profiles
  • No analytics or advertising trackers
  • No sale or sharing of data with third parties

Crash reports are opt-in

The extension sends anonymous crash reports only when you turn them on. A report carries the error type, stack trace, error code, and extension version. Reports exclude pool data, join codes, URLs, and browsing activity. Custom servers disable all telemetry.

Data retention and deletion

Old encrypted revisions are pruned automatically after 30 days, down to the newest covering checkpoint. Deleting a pool from the extension removes all of its data from the server immediately and permanently.