Clipper Privacy Policy

Effective: August 11, 2026 · Contact: volthesitan@gmail.com

This policy explains how the Clipper Chrome extension handles user data. Clipper has one purpose: saving user-selected web content and configured sources into a personal working library, then helping users continue reading, organize, compare, and research that material through the new tab, the in-page floating assistant, and AI tasks they choose to configure.

Core features do not require an account. A user may choose to sign in to Shadow to use an official model or send explicitly selected clips to a Buddy in a community. Clipper has no advertising or usage analytics.

1. Information Clipper handles

  • Website content and browsing activity: URLs, titles, page text, authors, dates, visible comments, transcripts, images, PDFs, snapshots, and feed entries from pages the user saves or adds to a capture task.
  • Organization data: folders, favorites, tags, ratings, read state, highlights, notes, saved searches, capture tasks, run records, sync state, quick notes, and saved tab sessions.
  • Browser data: the URLs, titles, favicons, grouping, and selection state of currently open tabs, used for the visible tab workspace, saved tab sessions, capture jobs created by the user, and recognition of an optional source for the current site. Bookmarks, Reading List entries, and recent history are used only after separate authorization for the related feature. Clipper does not modify original bookmarks or browsing history and does not upload the open-tab list to the developer.
  • Calendar, place, and widget data: upcoming event titles and times shown from Google Calendar; public place labels and image location details already present in selected content; a city chosen for weather; and public ticker symbols chosen for market data. Clipper does not request live device location.
  • Optional Shadow account data: account ID, username, display name, avatar, possible email address, and available community, channel, and Buddy information.
  • Settings and diagnostics: interface choices, enabled sources, granted permissions, per-source Do not remind me again choices, the most recent reminder time for a source, migration state, and content-free local diagnostic summaries. A diagnostic file is created only when the user exports it.
  • Credentials: remote AI keys, GitHub tokens, WebDAV credentials, local-service tokens, note-connection tokens, and Shadow sign-in credentials. These remain only for the current browser session. Old plaintext copies found from an earlier version are moved into the current session and deleted. Google Drive authorization is managed by Chrome.

2. How information is used

Clipper uses this information only to provide visible features: extracting and saving content, building a local index, displaying the library, running capture tasks created by the user, organizing tabs, showing selected widgets, exporting files, connecting to services chosen by the user, and completing AI, sync, or community actions started by the user.

Clipper does not sell user data, serve ads, create advertising profiles, or use data for creditworthiness, lending, or unrelated analytics.

3. Storage and retention

Content, attachments, indexes, settings, and non-sensitive run records stay in the current Chrome profile until the user deletes them or uninstalls the extension. Keys, passwords, and Shadow sign-in credentials remain only for the current browser session and can also be cleared in settings.

Clipper does not add separate encryption to local library content. Users should protect it with their Chrome profile, operating-system account, and device access controls. Copies exported, synchronized, or shared by the user are retained under the chosen destination's settings and policies.

4. Transfers and external services

Most features run in the browser. Information leaves the browser only when needed for a feature the user configures, authorizes, or starts:

  • Source websites receive requests for pages, public interfaces, images, transcripts, PDFs, or other attachments. Requests may use an existing Chrome sign-in for that site.
  • Remote AI providers receive selected content, instructions, model settings, and the required key after the user chooses a provider and runs an action.
  • Sync destinations receive selected archive files and required credentials after the user starts synchronization to Google Drive, GitHub, or HTTPS WebDAV. Google Drive access is limited to files Clipper created or the user explicitly provided to it.
  • Shadow receives authorization and profile requests after sign-in. When the user sends clips to a community Buddy, the selected titles, sources, text, metadata, instructions, and task status are sent to that community.
  • Google Calendar, Open-Meteo, geocoding, and market-data services receive only the limited calendar-page request, chosen city or coordinates, place name, or public ticker needed for the widget or lookup the user opens.
  • Local destinations may receive selected content through browser file access, the clipboard, or a connection to a service on the same device after a user action.
  • Interactive HTML previews request HTTPS scripts, styles, fonts, images, or services referenced by a generated or imported interactive document when the user opens it. Those resources may receive normal network-request information and data that the document deliberately sends. The preview runs only in the manifest-declared sandbox page, has no extension privileges, and cannot read the Clipper library or account credentials or change extension behavior.

External services process received data under their own terms and privacy policies. Users should connect only services they trust.

5. Permissions and user control

Clipper uses current-page, script, snapshot, scheduling, identity, and storage access to complete requested features. It uses tab access for the visible tab workspace, jobs created by the user, and recognition of an optional source for the current site.

Website source access is not all granted at installation. Settings and Studio use the same source groups: everyday sources are preselected on a fresh install, while other sources can be enabled individually or as a group. Chrome requests the corresponding site access only when a source or group is enabled. Studio actions remain inactive until the source is enabled and authorized, and a click can request access and continue. When a supported site is visited, Clipper may show an enable reminder no more than once per source in 24 hours; the user can choose Do not remind me again. Bookmarks, Reading List, browsing history, calendar pages, and custom service addresses are also requested separately when the related feature first needs them. Users can decline or revoke optional access; only the related feature will stop working.

6. Sharing and Limited Use

Except for source websites, AI providers, sync destinations, Shadow communities, local destinations, and widget services selected by the user, the developer does not receive or sell Clipper data. Support personnel review specific data only when the user submits it, when needed for security, or when required by law.

Clipper's use and transfer of user data are limited to providing or improving the clipping, local organization, export, synchronization, AI, and user-initiated sharing features disclosed here and in its store listing. Clipper complies with the Chrome Web Store User Data Policy, including Limited Use requirements.

7. Deleting information

Users can delete archive items, clear credentials, sign out of Shadow, revoke permissions, and delete exported diagnostic files. Uninstalling normally removes the extension's local data from the current Chrome profile. Copies sent to another service must be deleted at that destination.

8. Policy changes and contact

If Clipper materially changes its information practices, this policy and its effective date will be updated, and consent will be requested where required. For privacy questions or deletion requests, email volthesitan@gmail.com.