1. Who we are
This Privacy Policy explains how the Services branded as “Extenshi” process personal data. The Services are operated by Maksim Kosterin, a self-employed individual (autónomo / sole trader) registered in Spain (“we”, “us”, “our”, or “Extenshi”).
Data controller (EU/UK GDPR): Maksim Kosterin (autónomo)
NIE: Z2447446K
Address: Calle de Alboraya 61, 46010, Valencia, Spain
Email: support@extenshi.io
2. Scope
This Policy applies to personal data we process about: (a) visitors of our websites (including our blog), (b) registered users of the Services, and (c) users of our desktop application (“Extenshi”) who enable device sync features.
3. Data we collect
3.1 Account and profile data
When you create an account or sign in, we may process:
- authentication identifiers (e.g., user ID from our auth provider),
- email address,
- display name and avatar URL (if provided),
- account preferences (e.g., theme, language, sync settings).
3.2 Device data (Extenshi Desktop)
If you register a device, we may process:
- device identifier (generated ID),
- device name (if you provide it),
- operating system (Windows/macOS/Linux) and OS version,
- CPU architecture,
- application version,
- last sync timestamp.
3.3 Installation and event data (Extenshi Sync)
If you enable sync features, we may process:
- browser type and browser profile identifiers (as reported by your device),
- extension store (e.g., Chrome/Firefox/Edge) and extension store ID,
- extension name and version (as reported by your device),
- installation events (installed/updated/removed/enabled/disabled) with timestamps,
- event metadata (e.g., previous version/new version).
Important: installation data may reveal information about your preferences or interests. You can disable sync at any time and request deletion of your sync data (see Sections 8 and 9).
3.4 Public extension catalog data (generally non-personal)
We operate a public catalog of browser extensions. We collect and store publicly available extension data from third-party sources (e.g., extension name, description, permissions, categories, ratings/reviews, media assets, version history, and automated security signals). This data generally relates to extensions, not to you as a user of Extenshi.
Data sources: We may obtain extension catalog data from multiple sources, including:
- live scraping of publicly accessible browser extension store pages (Chrome Web Store, Firefox Add-ons, Microsoft Edge Add-ons),
- public web archives such as CommonCrawl (WARC files containing historical snapshots of extension store pages) and the Internet Archive's Wayback Machine (archived API responses containing extension metadata, permissions, and version history),
- publicly available APIs and sitemaps provided by extension stores,
- public discussions mentioning extensions on third-party community platforms such as Hacker News (retrieved via the Algolia API).
This catalog data is processed through automated pipelines and may include historical versions of extension metadata derived from archived web pages.
3.5 User feedback and reporting data
If you submit feedback through the Services (e.g., flagging the accuracy of community discussion links on extension pages), we may process:
- your user identifier (linked to your account),
- the feedback action (e.g., accurate/inaccurate flag),
- an optional free-text reason you provide.
If you submit an issue report about extension data or security scan results, we may additionally process:
- a report category (e.g., incorrect data, incorrect scan, security concern, missing data),
- a free-text description of the issue you provide (up to 5,000 characters),
- an optional link to the extension store page,
- references to the specific extension snapshot or scan execution the report relates to,
- report status and any resolution notes added by our team.
If you submit a review of a security finding (e.g., to acknowledge or dispute an automated finding), we may process:
- your user identifier (linked to your account),
- the specific finding and scan result being reviewed,
- your explanation text (up to 2,000 characters),
- the review status (pending, acknowledged, or disputed).
3.6 Billing and subscription data
Payments are processed by third-party payment providers (e.g., Stripe). We may store:
- subscription status and plan type,
- license status,
- payment-related references (e.g., customer/subscription IDs),
- invoices/receipts metadata needed for accounting and compliance.
We do not store full payment card details.
3.7 Technical data, cookies, and logs
We process technical data needed to operate and secure the Services, such as:
- IP address and user agent (in server logs where applicable),
- authentication cookies/tokens,
- security and abuse-prevention logs.
We use essential cookies/tokens to keep you signed in and protect the Services. If we use non-essential analytics cookies or similar identifiers, we will do so only where legally permitted and, where required, based on your consent.
Where you consent to analytics, we use PostHog with cross-subdomain cookies (*.extenshi.io) and browser local storage. If you are signed in, your analytics session is linked to your account identifier so we can understand feature usage across Extenshi subdomains (catalog, blog, dojo, genkan). You can withdraw analytics consent at any time (see our Cookie & Tracking Policy).
3.8 Automated pipeline processing data
Our Services include automated data processing pipelines that continuously collect, parse, and analyze extension data. These pipelines may process:
- extension metadata extracted from HTML pages via automated parsers,
- security scan results from multiple automated scanning tools, including raw scanner output and structured findings persisted to our database,
- computed risk assessments and scores derived from scanner results, including severity breakdowns, confidence levels, and weighted scoring across multiple scanners,
- extension package files (e.g., .crx, .xpi) stored in object storage for security analysis, along with file hashes (MD5, SHA-256) and size metadata,
- extension status and lifecycle information (e.g., whether an extension is active, failed to process, or quarantined from further scanning),
- pipeline operational data (processing timestamps, error logs, retry counts) used for system reliability and troubleshooting.
This automated processing relates to extension data, not to you personally, except where extension developer contact information may be included in publicly available extension metadata.
3.9 Operational metrics and monitoring data
We may collect aggregated operational metrics about pipeline and service performance (e.g., execution durations, success/failure counts, health check results) using monitoring tools such as Prometheus. This data is used solely for system reliability, performance optimization, and troubleshooting. It does not contain personal data.
3.10 Monitor extension data (Extenshi Companion)
If you install the optional “Extenshi Monitor” companion browser extension, the following data may be processed locally on your device:
- network destination metadata (scheme, host, port, and first URL path segment) of requests initiated by other browser extensions installed in your browser,
- the URL of your active browser tab, used to evaluate site-binding rules that automatically enable or disable extensions based on the site you are visiting,
- extension management actions (enable/disable) performed through the companion extension at your direction or through site-binding rules you configure.
This data is stored locally on your device and communicated to the Extenshi desktop application via Native Messaging. It is not transmitted to our servers unless you explicitly enable sync features described in Section 3.3.
3.11 Extension developer data (collected indirectly)
In the course of building our public catalog, we may collect personal data about extension developers from publicly available sources (browser extension store listings). This data is not obtained directly from the developers themselves. In accordance with Article 14 GDPR, we provide the following information:
- Categories of data: developer/publisher name, contact email address (where publicly listed), website URL, and social media links.
- Source: publicly accessible browser extension store pages (Chrome Web Store, Firefox Add-ons, Microsoft Edge Add-ons) and public web archives.
- Purpose: to attribute extensions to their developers in our catalog, enable author verification, and allow users to contact developers.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR) — providing accurate attribution and transparency about extension authorship.
- Your rights: if you are an extension developer whose data appears in our catalog, you may exercise your rights under GDPR (access, rectification, erasure, objection) by contacting us at support@extenshi.io. You may also use our developer dispute process.
3.12 Scan notification subscription data
If you subscribe to receive a notification when a security scan completes for a specific extension, we process:
- your email address,
- a confirmation token (single-use, for double opt-in verification),
- a per-subscription unsubscribe token,
- the extension you subscribed to.
Unconfirmed subscriptions are automatically deleted after 24 hours. Confirmed subscriptions with no scan activity are deleted after 90 days. Each notification email includes a one-click unsubscribe link.
3.13 Developer self-declaration data (questionnaire)
If you are a verified extension author and complete our developer questionnaire, we process the self-declarations you provide, which may include:
- monetization model and payment provider information,
- categories of personal data your extension collects and the legal basis you declare,
- whether your extension processes health or protected health information, and if so, your declared HIPAA scope and data protection officer contact email,
- backend domains and third-party SDKs your extension uses,
- telemetry and obfuscation disclosures,
- justifications for broad permissions,
- data retention periods and transparency URLs you provide.
Questionnaire responses are versioned (each submission creates a snapshot) and changes are recorded in an append-only audit log. Approved responses may be used to generate transparency signals displayed on your extension's public catalog page.
3.14 Extenshi CLI data (developer pre-publish scanning)
If you use the Extenshi CLI, an optional command-line tool that scans an extension package for security issues before you publish it, we process:
- API keys: we store a hashed form (SHA-256) of each API key you generate, together with a short non-secret key prefix, an optional label you provide, and the creation, last-used, and revocation timestamps. We do not store the API key in plaintext.
- Uploaded extension packages: when you run a scan, the CLI uploads the extension package file (e.g., .zip, .crx, .xpi) you select to our scanning service. The package is unpacked and analyzed by automated, offline scanners and is processed transiently — it is deleted once the scan completes and is not retained in our storage. The uploaded package and its scan findings are not written to our logs.
- Scan job records: for each scan we retain operational metadata such as a scan job identifier, your user identifier, the uploaded artifact size, timing, and the scan outcome (success/failure). We do not retain the scan findings content or the uploaded file.
- Credit balance and purchase records: your remaining and granted scan credits, and records of credit-pack purchases (credits added, amount, currency, and Stripe references). Payments are processed by Stripe as described in Section 3.6; we do not store full payment card details.
- Pre-review verdicts (
review-risk): thereview-riskcommand analyses your package on your own machine. If you run it while signed in and you tell it which listing the package is for (--extension-id), the CLI additionally sends us the resulting verdict (CLEAR,SLOW, orREJECTED), the version of the rule set that produced it, and a one-way SHA-256 hash of the package file, which we use only to recognise a repeat run of the same artifact. The package itself, its contents, and the individual findings are not sent. We store the verdict against your account alongside what the store subsequently did with that listing, so we can measure how accurate our pre-review checks are. If you are not signed in, or do not pass an extension id, nothing is sent and the command stays entirely local.
Extension packages you scan with the CLI may contain your own proprietary or unpublished code. They are submitted by you for the sole purpose of generating security analysis results and are not added to our public catalog.
3.15 Developer growth tools (uninstall feedback and welcome pages)
We offer optional developer tools that let a verified extension author configure an Extenshi-hosted page for their own extension: an uninstall-feedback survey (shown when an end user removes the extension) and a welcome / onboarding page (shown on first install). These pages are hosted by us on the author's behalf and collect data from the end users of that third-party extension, who are generally not Extenshi account holders. For submissions made through the uninstall-feedback survey we process:
- the uninstall reason the end user selects (from a fixed taxonomy or the author's custom options),
- an optional answer to a follow-up question the author attaches to that reason — either free text (up to 2,000 characters) or up to eight options the end user picks from a list the author defines — stored together with a snapshot of the question as it was worded when it was asked,
- an optional free-text comment the end user provides (up to 2,000 characters),
- an optional contact email, only where the author enabled the contact field and the end user chooses to provide it,
- the extension version, browser, and locale reported by the request.
For the welcome / onboarding page we record confirmed-install events with the extension version, browser, and locale, but no comment, email, or other content. For both tools we also store a one-way hashed (SHA-256, truncated) form of the submitter's IP address, used solely for abuse-prevention and rate-limiting; we do not store the raw IP address for these submissions.
Submissions are not linked to an Extenshi account and are readable only by the verified author who configured the page. For data collected through these tools, the configuring developer is the data controller and Extenshi acts as a processor/service provider on the developer's behalf; the developer is responsible for providing any notice and lawful basis required toward their own end users. This data is not added to our public catalog and is not used for our own marketing.
3.16 Extenshi CLI & MCP usage telemetry
The Extenshi CLI and the Extenshi MCP server are optional tools you install on your own machine (e.g., via npm). These tools send usage telemetry so we can understand which commands and tools are used, which fail, and what errors recur. When enabled, we process:
- the command or tool name invoked and the surface (“cli” or “mcp”),
- the tool version, Node.js version, and coarse operating system and CPU architecture, and whether the tool ran in a CI environment,
- the names (never the values) of the command-line flags you pass,
- a coarse error classification and operation durations,
- a path-redacted error signature (error message and stack trace with home-directory paths stripped) when a command fails,
- a single install event when the package is first installed as a real dependency (including the tool version, Node.js version, and coarse os/arch).
How these records are identified depends on which tool you use. When you run the CLI, or run the MCP server locally on your own machine, telemetry is keyed to an anonymous per-install identifier (a random UUID stored in ~/.extenshi/config.json): it identifies an installation, not a person, and is not linked to your API key or account. When you instead use our hosted (remote) MCP connector, which you authorise through your Extenshi account, each record instead carries your account identifier and an identifier for the connection it came from, so we can see how the connector is used and support you when a call fails. Telemetry from the hosted connector is therefore not anonymous: it is personal data relating to you. Your email address is not sent to our analytics provider in either case — it stays in our own database.
In all cases the telemetry never includes file paths, extension package names or contents, manifest data, API keys, the text of your queries or tool results, or any other raw input you provide. Telemetry is processed by PostHog (EU region) on our behalf (see Section 7). Our legal basis is legitimate interest (Article 6(1)(f) GDPR) in maintaining, supporting, and improving the tools, balanced against your interests by limiting collection to non-content data, by withholding your email address from the processor, and — for the tools you install yourself — by asking you first and honouring a refusal.
Choice and opt-out (CLI and locally installed MCP server). The first time you run the CLI interactively it asks you once whether to share anonymous usage data, shows what would be sent, and records your answer in ~/.extenshi/config.json. Nothing is reported before you answer, and declining stores no identifier at all. You can change the answer at any time with extenshi telemetry on, extenshi telemetry off, or inspect it with extenshi telemetry status. You can also opt out with the environment variable DO_NOT_TRACK=1, with EXTENSHI_TELEMETRY=0 (or off/false/no), or by setting "telemetry": false in ~/.extenshi/config.json. Any of these disables both the runtime telemetry and the install event. Where there is nobody to ask — a non-interactive run, or a continuous-integration environment — the question is not put and telemetry stays on by default until you opt out by one of the means above.
Choice and opt-out (hosted MCP connector). Usage telemetry is part of operating the hosted connector and is not separately switchable. You can stop it by disconnecting the connector or revoking its access from your Extenshi account, and you may object to this processing at any time under Section 13.
3.17 Developer integration data (GitHub, Chrome Web Store, and analytics connections)
If you are a developer, you can optionally connect third-party developer accounts to your Extenshi account from the developer cabinet's Integrations page, so we can act on those accounts at your direction. These connections are established by you and can be disconnected at any time.
- GitHub: when you install the “Extenshi Dojo” GitHub App on your account or organisation and select repositories, we process your GitHub account login, account type (personal or organisation), avatar URL, the app installation identifier, the permission scopes you grant, and the names and metadata of the repositories you select. With your authorisation we read the contents of the selected repositories — including private source code and
manifest.jsonfiles — to audit and security-scan them, and, only where you additionally grant write access, we may commit generated assets, open pull requests, and store an Extenshi API key as an encrypted GitHub Actions secret in a repository you select. We do not store your GitHub access tokens; short-lived tokens are generated on demand from the app's own credentials. - Chrome Web Store: to let you prove ownership of, and manage, your extension listings, we provision a dedicated Google Cloud service account for your connection. You grant that service account access to your Chrome Web Store publisher account from your own Chrome Web Store Developer Dashboard. We then process your Chrome Web Store publisher ID, the identifiers of the listings you control, and the service-account email and Google Cloud project associated with your connection.
- Your own analytics project: you can connect an analytics project you already operate — currently PostHog, on PostHog Cloud or a self-hosted instance — to an extension whose ownership you have verified, so that its usage numbers appear in your developer cabinet. We process the provider host, the project identifier, an optional event filter you define, the last four characters of the credential, and the connection's sync state and error history. The personal API key you supply is checked against the provider and then stored encrypted at rest; it is never returned to any client. Roughly every 30 minutes we query that project on your behalf and store daily aggregates only: active-user and event counts per day, counts broken down by extension version and by browser, the most frequent event names, and weekly/monthly active-user and return-rate figures. The first sync reads up to 90 days of history; later syncs re-read only the most recent days. We do not retrieve or store individual events, end-user identifiers, or any other end-user record from your project.
Where we store credentials for these integrations (such as the Chrome Web Store service-account private key or an analytics provider's personal API key), they are stored encrypted at rest (AES-256-GCM). Disconnecting an integration removes the connection and revokes the associated credential; disconnecting an analytics source also deletes the daily aggregates and the sync log we hold for it. These features transmit data to, and access your accounts on, GitHub, Google (Google Cloud and the Chrome Web Store API), and — where you connect one — the analytics provider you nominate; see our processors in Section 7.
If you ask us to publish a release of your extension for you, we upload and submit the package to the Chrome Web Store under your publisher account using the credentials you granted us. Every publish we perform on your behalf is recorded in an audit trail (who requested it, when, which listing, and the outcome) and we notify you by email each time we do it.
3.18 Installed-extension inventory (Extenshi Guard)
Extenshi Guard is an optional command-line tool you run on your own machine to audit the browser extensions installed on it. Guard reads the local profile data of the Chromium- and Firefox-family browsers it finds on your device and builds the inventory locally. Extension names, descriptions, on-disk paths, and your browsing data never leave your machine.
When you run a scan that requests analysis from our servers, Guard transmits, for each detected extension: the store extension ID, the store it maps to, the version, whether it is enabled, the install origin (e.g., web store, sideloaded, enterprise policy), the install timestamp, and the update URL — grouped by browser identifier, browser name, and browser profile name — together with the tool version and your operating-system platform. Built-in browser components, and identifiers that cannot be store IDs, are excluded before anything is sent. We use this to look each extension up in our catalog and return risk recommendations to you.
Storing the inventory requires your separate consent. The analysis is performed and returned to you either way; your inventory is stored on your account only if you accept the consent notice Guard displays before sending. If you consent, we additionally record the consent itself — the version of the consent text you accepted, the time, the source, and your IP address and user agent as a forensic record of the consent — plus an entry in an append-only consent audit log. A stored inventory is shown in your Extenshi profile and may be used, in aggregate, for statistics on extension usage and activity.
Withdrawing consent: you can revoke at any time in your developer cabinet settings (dojo.extenshi.io → profile). Revoking marks the consent record as withdrawn, clears the IP address and user agent held on it, and permanently deletes the stored inventory.
Enforcement stays on your device. If you ask Guard to remove or disable a flagged extension, it does so by writing browser enterprise-policy settings on the machine it is running on and keeps a local, reversible record of every change it made. Those changes are applied locally; we do not receive them.
Analyses are metered: each account receives one free inventory analysis, after which an analysis consumes prepaid inventory credits purchased through Stripe as described in Section 3.6.
3.19 Extension monitoring subscriptions (Delisting Watch)
You can ask us to watch an extension in our catalog and tell you when its status in the store changes — for example when a listing stops being publicly available. If you start a watch, we process:
- your user identifier and the catalog extension you chose to watch,
- where the listing was proven to belong to a publisher account you connected (see Section 3.17), a reference to that connection, so events can be grouped by publisher account,
- whether the watch is currently active, and when it was created and last changed — we keep the record and mark it inactive rather than deleting it, so that stopping and restarting a watch does not lose its history,
- the store status transitions we observe for the extensions you watch (the previous and new status and when each was observed), which relate to the extension rather than to you,
- a delivery record for each alert — which event, which recipient, and which channel — kept so that a retry cannot send you the same alert twice.
Alerts are sent to the email address on your account and are also shown as in-app notifications. Unlike our other transactional email, these arrive unprompted after a single subscription, so every alert carries a link to stop watching that extension. The link is scoped to the one extension it is about, so silencing a noisy listing does not silence alerts about your others. You can also start and stop any watch from the Monitoring page in your developer cabinet. Our legal basis is performance of the service you asked for (Article 6(1)(b) GDPR), and you can end it at any time by stopping the watch.
3.20 Hosted privacy-policy pages
If you are a verified extension author, you can ask us to publish the privacy policy you draft in the developer cabinet at a public URL for your own extension — at privacy.extenshi.io/{code}, at dojo.extenshi.io/privacy/{code}, or on a domain you control — so that a store reviewer or one of your end users can fetch it without signing in. Unlike our other hosted developer pages, a published policy page is deliberately indexable by search engines. Publishing is part of the paid plan; generating and downloading the document is not. For a published page we process:
- the policy text itself, in markdown and as rendered HTML. It is your document, and it will normally contain your or your company's name, a contact email address, and a website — all of which become publicly visible at the published URL,
- a snapshot of the answers you gave the policy generator, together with a fingerprint of the data practices they describe, which we use to tell you when your published policy no longer matches what your extension declares,
- every earlier version, kept append-only — publishing, editing, updating with AI, or reverting adds a version rather than overwriting one, so the text that was live at a past date can still be produced,
- the short public code the page is served under, and whether the page is currently switched on.
Update with AI. If you ask us to bring a policy you have edited back in line with your current declared practices, the merged draft — that is, your policy text — is sent to Anthropic (see Section 7) to reconcile the wording, and the result is stored as a new version marked as AI-updated. The merge itself is deterministic and runs on our own servers; where the model is unavailable, or its answer drops a disclosure the merge required, we keep the deterministic result instead.
Your own domain. If you point a hostname you control at our hosted pages, we store that hostname, a verification token, the verification status, and the time and error of the last check, and we make DNS queries against that hostname to confirm you control it. We do not collect any other data about your domain or its visitors beyond what this Section and Section 3.15 already describe for the page being served.
A published page remains reachable while it is switched on and your account exists — including after a paid plan lapses, so that a store listing already pointing at the URL does not break. You can switch the page off, or remove the custom domain, at any time in the developer cabinet.
4. Purposes of processing
We process personal data to:
- Provide and operate the Services (authentication, account management, dashboards).
- Enable device registration, sync, and installation history features (if enabled).
- Provide public catalog functionality and related insights.
- Provide automated security/risk signals and historical timelines.
- Operate automated data pipelines for extension metadata collection, security scanning, and catalog updates.
- Provide customer support and service communications.
- Send newsletters and marketing communications to subscribers who opt in.
- Send reactivation and win-back offers to customers who have previously purchased from us, selected from their remaining credit balance and how long they have been inactive. Every such email contains an opt-out link.
- Send scan completion notifications to subscribers who opt in via double opt-in.
- Collect and display developer self-declarations about extension data practices (questionnaire).
- Process subscriptions, billing, and license validation.
- Provide the Extenshi CLI pre-publish security scanning service for extension developers (API key management, processing uploaded extension packages, and credit accounting).
- Operate optional developer growth tools (Extenshi-hosted uninstall-feedback surveys and welcome pages) on behalf of verified extension authors.
- Publish and serve, at a public URL, the privacy policy a verified extension author drafts for their own extension, keep its version history, and — at the author's request — reconcile it with their current declared practices using AI assistance.
- Understand usage of, diagnose errors in, and provide support for the optional Extenshi CLI and MCP developer tools (see Section 3.16 for how those records are identified).
- Watch the extensions you subscribe to for changes in their store status, and alert you by email and in-app notification when one changes (Delisting Watch).
- Measure how accurate our automated pre-review checks are, by comparing the verdict recorded for a scan or a signed-in
review-riskrun against what the store subsequently did with that listing. - Operate optional developer integrations that connect your GitHub and Chrome Web Store accounts, at your direction, to audit and security-scan your extension source code, verify listing ownership, and commit generated assets, or build, upload and submit releases of your extension on your behalf.
- Query an analytics project you connect, at your direction, and store the daily usage aggregates it returns so we can display them for your extension in your developer cabinet.
- Analyse the installed-extension inventory you submit through Extenshi Guard and return risk recommendations, and — where you consent — store that inventory on your account, display it in your profile, and use it in aggregate for statistics on extension usage and activity.
- Secure the Services, prevent abuse, and troubleshoot issues.
5. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on:
- Contract: to provide the Services you request (account, core functionality, paid access).
- Consent: for optional features such as installation sync, storing the installed-extension inventory you submit through Extenshi Guard (and non-essential cookies where required).
- Legitimate interests: to operate, secure, and improve the Services and maintain our public catalog, and to send our own existing customers reactivation and win-back offers for services similar to those they already bought — in each case balanced against your rights, and subject to your right to object at any time.
- Legal obligation: to retain certain records required by law (e.g., accounting/tax).
6. Sharing and disclosure
We share data only as needed:
- Service providers (processors): hosting, storage, authentication, email delivery, monitoring, and payment providers.
- Legal and safety: to comply with law, enforce our Terms, or protect rights and safety.
- Business transfers: in a merger, acquisition, or asset sale (with appropriate safeguards).
7. Our processors (service providers)
We use third-party processors to deliver the Services. We have entered into data processing agreements (DPAs) with each processor in accordance with Article 28 GDPR. Our processors include:
- Supabase (authentication and user management)
- Hetzner Online GmbH (S3-compatible object storage, EU region)
- Stripe (payments, subscriptions, invoices)
- Infisical (secrets management for secure configuration of our Services)
- Infrastructure hosting (deployment and hosting platform used to run our Services)
- Cloudflare (edge hosting and content delivery for the public catalog, including caching of rendered pages, and Turnstile CAPTCHA for bot prevention during authentication and on public forms such as notification subscriptions and support requests)
- PostHog (product analytics on our websites where enabled with user consent, and anonymous opt-out usage telemetry for the Extenshi CLI and MCP developer tools). Where a developer connects their own PostHog project under Section 3.17, that project is the developer's own service, not ours: we query it only on their instruction and only for the daily aggregates described there.
- SMTP provider(s) (transactional email, where enabled)
- Anthropic (AI-based security analysis of extension code and metadata, and — only when a developer asks for it — the optional AI reconciliation of a privacy policy they host with us, described in Section 3.20)
- GitHub, Inc. (source-code hosting integration — reading, and where you grant write access, writing to the repositories you connect via the “Extenshi Dojo” GitHub App; only for developers who connect a GitHub account)
- Google LLC (Google Cloud service accounts and the Chrome Web Store API, used to verify and manage extension listings for developers who connect a Chrome Web Store publisher account)
8. International transfers
Some of our processors are based in the United States or other countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards:
- EU-US Data Privacy Framework (DPF): where the processor is certified under the EU-US DPF (e.g., Stripe, Cloudflare, PostHog, Google, GitHub).
- Standard Contractual Clauses (SCCs): the European Commission's approved standard contractual clauses, incorporated into our data processing agreements.
- Adequacy decisions: where the European Commission has determined that a country provides an adequate level of data protection.
9. Your choices and controls
- Sync control: You can enable/disable installation sync at any time in settings (where available).
- Access/export: You can request a copy/export of your data.
- Deletion: You can request deletion of your sync data and/or your account.
- Withdraw consent: If processing is based on consent (e.g., sync), you can withdraw it at any time.
- Newsletter: You can unsubscribe from marketing emails at any time using the link in each email.
- Reactivation and win-back offers: You can opt out of these emails using the link in each message or in your developer cabinet settings, without affecting service and transactional emails.
- Guard inventory: Storing your installed-extension inventory is optional and consent-based. You can withdraw consent and permanently delete the stored inventory at any time in your developer cabinet settings (see Section 3.18).
- CLI/MCP telemetry: The CLI asks you once, on its first interactive run, whether to share anonymous usage data. You can change that answer at any time with
extenshi telemetry on/off(or check it withextenshi telemetry status), or opt out withDO_NOT_TRACK=1,EXTENSHI_TELEMETRY=0, or"telemetry": falsein~/.extenshi/config.json. Telemetry from the hosted MCP connector carries your account identifier and is not separately switchable; disconnect or revoke the connector to stop it (see Section 3.16). - Extension monitoring alerts: Every Delisting Watch alert contains a link to stop watching that extension, and you can start or stop any watch from the Monitoring page in your developer cabinet (see Section 3.19).
10. Retention schedule
We retain personal data only as long as necessary for the purposes described and then delete or anonymize it, unless longer retention is required by law.
10.1 Default retention periods
- Account & profile data: retained while your account is active. After account deletion, deleted or anonymized within 30 days, except where legally required to retain certain records.
- Device records: retained while linked to your account; deleted within 30 days after device removal or account deletion.
- Installation & event history (sync): retained for 24 months on a rolling basis (from event timestamp), then deleted or anonymized/aggregated.
- Security and abuse-prevention logs: retained up to 180 days.
- Scan notification subscriptions: unconfirmed subscriptions deleted after 24 hours; confirmed subscriptions with no scan activity deleted after 90 days.
- Operational/server logs (including IP logs where applicable): retained up to 90 days.
- Extenshi CLI data: uploaded extension packages are processed transiently and deleted once the scan completes (not retained). API keys are retained until you revoke them or delete your account. Scan job records and credit-purchase records are retained while your account is active and then deleted or anonymized within 30 days of account deletion, except billing records required to be kept under Section 10.2.
- Developer growth tools (uninstall feedback & welcome pages): end-user submissions and confirmed-install events are retained while the configuring author keeps the page and their Extenshi account active; they are deleted when the author deletes the form or their account.
- Connected analytics sources: the encrypted provider credential, the daily aggregates read from your project, and the per-sync log are retained while the connection exists, and are deleted when you disconnect the source or delete your account.
- Hosted privacy-policy pages: the published page and its append-only version history are retained while the page exists and your account is active — the history is the record of which text was live at which time, so switching a page off does not erase it. Deleting the page, the project, or your account deletes both. A custom-domain record is retained until you remove the domain or delete your account.
- Guard installed-extension inventory: retained only while your consent stands, and deleted permanently as soon as you revoke consent or delete your account. The consent record and the consent audit-log entry are retained as our proof of consent, with the IP address and user agent cleared from the consent record on revocation.
- Extension monitoring (Delisting Watch): your watch record and its alert-delivery records are retained while your account is active and are deleted with it; stopping a watch marks it inactive rather than deleting it, so that restarting it does not lose when it was first created. Observed store status transitions relate to the extension, not to you, and are retained as catalog history.
- Pre-review verdicts (
review-risk) and store outcomes: retained while your account is active and then deleted or anonymized within 30 days of account deletion. - Support communications: retained up to 24 months after resolution, unless earlier deletion is requested and feasible.
- Backups: may persist up to 90 days before automatic expiry.
10.2 Billing and tax records
We retain invoices and legally required billing/tax records for the statutory periods applicable to our obligations, which may be up to 10 years in certain VAT regimes. We retain such records even if you delete your account, to the extent required by law.
11. Security
We implement administrative, technical, and organizational measures designed to protect personal data. However, no system can be guaranteed 100% secure.
12. Children
The Services are not intended for children under 16. We do not knowingly collect personal data from children.
13. Your rights (EEA/UK)
Depending on your location, you may have rights to access, rectify, delete, restrict processing, object to processing, and data portability in certain cases. You may also lodge a complaint with your local supervisory authority. To exercise rights, contact support@extenshi.io.
14. Changes to this policy
We may update this Policy from time to time. We will publish the updated version and update the “Last updated” date.