Privacy Policy
Last updated: 19 September 2026
The short version. Clipping pages, articles and PDFs happens entirely in your browser and sends us nothing. Video caption clipping is metered, so it tells our server that one clip was used — and nothing else. We never receive the address of the page you clipped, its title, its contents, or the transcript.
1. The split, feature by feature
| Feature | Leaves your browser? |
|---|---|
| Pages, articles, selections, elements, PDFs | No. No account, no request to us, nothing recorded. There is no code path that sends this content anywhere. |
| Video captions | Your browser gets the captions from the video site itself and builds the transcript locally; it stays on your machine. Separately, a small message tells our server that one clip was used, so the monthly allowance can be counted. |
| Sending a clip somewhere | Only when you ask, and it goes directly from your browser to the destination you chose — never through us. |
2. What we never receive
For any feature, at any time, our servers never receive:
- the URL of a page you clip
- its title, its contents, or any text you selected
- caption or transcript text
- your browsing history, or any record of which sites you visit
- your clip history
This is a property of how the software is built, not only a promise: the request that counts a clip has no field capable of carrying any of it.
One thing worth spelling out: requests to the video site
To clip a video's captions, the extension asks the video site for them — from your browser, using the session you are already signed in with there, exactly as the page itself does when you switch captions on. On some videos it instead turns captions on and reads them off the player as it plays.
Either way, that request goes from your browser straight to that site. It does not pass through us, we do not see it, and it tells that site nothing it would not already learn from you watching the video in the same tab. We do not send the video's address, or anything else about it, to our own servers.
3. What we do store
If you never sign in
The first time you use video captions, the extension generates a random identifier in your browser and sends it with each clip so the free allowance can be counted. Against that identifier we store a monthly count, and the times it was first and last seen. It is not derived from anything about you, and clearing the extension's storage discards it.
If you create an account
- Your email address, received from Google when you sign in. We request only your identity and email — we have no access to your Gmail, Drive, contacts or anything else in your Google account.
- A normalised copy of that address, used to recognise that
[email protected]and[email protected]are the same inbox. - When the account was created, which is also the day your monthly allowance resets.
- Session tokens, stored only as irreversible hashes. The token itself exists in your browser and nowhere else.
To stop one person from taking an unlimited free allowance
Because the free tier does not require an account, we need some way to tell one device from a thousand. We use a deliberately coarse signal built from eight values your browser already exposes to every website:
- operating system family, browser major version
- number of CPU cores, approximate memory tier
- time zone, language
- touch-point count, screen colour depth
These values are never stored. They are combined and hashed with a secret key the moment they arrive, and only the resulting hash is kept. The hash cannot be turned back into the original values, and it is far too coarse to identify a person — many different machines produce the same one, which is why the allowances attached to it are sized for several people rather than one.
We deliberately do not use the invasive techniques normally associated with device fingerprinting: no canvas or WebGL rendering signatures, no audio fingerprinting, no font enumeration, no battery or plugin probing.
Your IP address is treated the same way: used to rate-limit abuse, stored only as a salted hash, never in the clear.
If you subscribe
- Payments are handled entirely by Stripe. Your card details go straight to Stripe and never reach our servers.
- We store a Stripe customer and subscription identifier, your plan, and the current period dates, so the extension knows you are a subscriber.
- We keep a log of the billing notifications Stripe sends us, as an audit trail for charges and refunds.
Stripe processes your payment data under its own privacy policy, as an independent controller.
Diagnostics
When a shared allowance refuses a request, we record which allowance refused it and which random device identifier was affected. This exists so we can tell whether a limit is catching abuse or accidentally blocking real people. It contains no content and no new personal data.
4. What we do not do
- No analytics or telemetry. No third-party analytics SDK, no pixels, no session recording, no crash reporting that includes page data.
- No advertising, and no profiling for it.
- We never sell or rent your data, and never share it with third parties except the processors named here (Google for sign-in, Stripe for payments, Cloudflare for hosting).
- No tracking across sites. The extension does not report which sites you visit, to us or anyone.
5. Data stored on your own device
Held in your browser's extension storage, readable only by the extension:
- Settings and templates.
- Clip history — the Markdown you clipped, so you can search, preview, export or delete it. You can switch history off or clear it at any time in Settings.
- Integration tokens for any note service you connect. They are used only to send a clip to that service, from your browser, directly.
- Your session token, if signed in.
None of this is visible to us. Uninstalling the extension removes all of it.
6. Chrome Web Store Limited Use
Our use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We request only your identity and email address, use them solely to operate your account and its allowance, and do not transfer them to others except as required to provide the service, comply with the law, or as part of a merger or acquisition.
7. How long we keep things
- Monthly counters expire with the period they belong to and are cleared afterwards.
- Account data is kept while your account exists.
- Billing records are retained as long as tax and accounting law requires, even after an account is deleted.
- Diagnostic records of refused requests are cleared periodically.
8. Your choices
- Use it without an account. Everything except the video allowance beyond the first two clips works without signing in.
- Delete your account. Email [email protected] and we will delete it, along with the counters and subscription records attached to it, except where law requires us to retain billing records.
- Get a copy of your data. Ask at the same address.
- Clear the local side any time from Settings, or by uninstalling.
If you are in the UK, EU, or a jurisdiction with comparable rules, you also have the right to object to processing, to have inaccurate data corrected, and to complain to your local supervisory authority.
9. Where data is processed
Our service runs on Cloudflare's network, which may process data in any region where Cloudflare operates. Sign-in is provided by Google and payments by Stripe, each under their own terms.
10. Children
Pocketdown is not directed at children under 13, and we do not knowingly collect their data.
11. Changes
If we change what we collect, we will update this page and the date at the top, and — where the change is material — tell you inside the extension rather than only editing this page.