Privacy Policy

Effective: January 11, 2026Updated: July 27, 2026

1. Who we are

This Privacy Policy explains how the Services branded as “Extenshi” process personal data. The Services are operated by Maksim Kosterin, a self-employed individual (autónomo / sole trader) registered in Spain (“we”, “us”, “our”, or “Extenshi”).

Data controller (EU/UK GDPR): Maksim Kosterin (autónomo)
NIE: Z2447446K
Address: Calle de Alboraya 61, 46010, Valencia, Spain
Email: [email protected]

2. Scope

This Policy applies to personal data we process about: (a) visitors of our websites (including our blog), (b) registered users of the Services, and (c) users of our desktop application (“Extenshi”) who enable device sync features.

3. Data we collect

3.1 Account and profile data

When you create an account or sign in, we may process:

  • authentication identifiers (e.g., user ID from our auth provider),
  • email address,
  • display name and avatar URL (if provided),
  • account preferences (e.g., theme, language, sync settings).

3.2 Device data (Extenshi Desktop)

If you register a device, we may process:

  • device identifier (generated ID),
  • device name (if you provide it),
  • operating system (Windows/macOS/Linux) and OS version,
  • CPU architecture,
  • application version,
  • last sync timestamp.

3.3 Installation and event data (Extenshi Sync)

If you enable sync features, we may process:

  • browser type and browser profile identifiers (as reported by your device),
  • extension store (e.g., Chrome/Firefox/Edge) and extension store ID,
  • extension name and version (as reported by your device),
  • installation events (installed/updated/removed/enabled/disabled) with timestamps,
  • event metadata (e.g., previous version/new version).

Important: installation data may reveal information about your preferences or interests. You can disable sync at any time and request deletion of your sync data (see Sections 8 and 9).

3.4 Public extension catalog data (generally non-personal)

We operate a public catalog of browser extensions. We collect and store publicly available extension data from third-party sources (e.g., extension name, description, permissions, categories, ratings/reviews, media assets, version history, and automated security signals). This data generally relates to extensions, not to you as a user of Extenshi.

Data sources: We may obtain extension catalog data from multiple sources, including:

  • live scraping of publicly accessible browser extension store pages (Chrome Web Store, Firefox Add-ons, Microsoft Edge Add-ons),
  • public web archives such as CommonCrawl (WARC files containing historical snapshots of extension store pages) and the Internet Archive's Wayback Machine (archived API responses containing extension metadata, permissions, and version history),
  • publicly available APIs and sitemaps provided by extension stores,
  • public discussions mentioning extensions on third-party community platforms such as Hacker News (retrieved via the Algolia API).

This catalog data is processed through automated pipelines and may include historical versions of extension metadata derived from archived web pages.

3.5 User feedback and reporting data

If you submit feedback through the Services (e.g., flagging the accuracy of community discussion links on extension pages), we may process:

  • your user identifier (linked to your account),
  • the feedback action (e.g., accurate/inaccurate flag),
  • an optional free-text reason you provide.

If you submit an issue report about extension data or security scan results, we may additionally process:

  • a report category (e.g., incorrect data, incorrect scan, security concern, missing data),
  • a free-text description of the issue you provide (up to 5,000 characters),
  • an optional link to the extension store page,
  • references to the specific extension snapshot or scan execution the report relates to,
  • report status and any resolution notes added by our team.

If you submit a review of a security finding (e.g., to acknowledge or dispute an automated finding), we may process:

  • your user identifier (linked to your account),
  • the specific finding and scan result being reviewed,
  • your explanation text (up to 2,000 characters),
  • the review status (pending, acknowledged, or disputed).

3.6 Billing and subscription data

Payments are processed by third-party payment providers (e.g., Stripe). We may store:

  • subscription status and plan type,
  • license status,
  • payment-related references (e.g., customer/subscription IDs),
  • invoices/receipts metadata needed for accounting and compliance.

We do not store full payment card details.

3.7 Technical data, cookies, and logs

We process technical data needed to operate and secure the Services, such as:

  • IP address and user agent (in server logs where applicable),
  • authentication cookies/tokens,
  • security and abuse-prevention logs.

We use essential cookies/tokens to keep you signed in and protect the Services. If we use non-essential analytics cookies or similar identifiers, we will do so only where legally permitted and, where required, based on your consent.

Where you consent to analytics, we use PostHog with cross-subdomain cookies (*.extenshi.io) and browser local storage. If you are signed in, your analytics session is linked to your account identifier so we can understand feature usage across Extenshi subdomains (catalog, blog, dojo, genkan). You can withdraw analytics consent at any time (see our Cookie & Tracking Policy).

3.8 Automated pipeline processing data

Our Services include automated data processing pipelines that continuously collect, parse, and analyze extension data. These pipelines may process:

  • extension metadata extracted from HTML pages via automated parsers,
  • security scan results from multiple automated scanning tools, including raw scanner output and structured findings persisted to our database,
  • computed risk assessments and scores derived from scanner results, including severity breakdowns, confidence levels, and weighted scoring across multiple scanners,
  • extension package files (e.g., .crx, .xpi) stored in object storage for security analysis, along with file hashes (MD5, SHA-256) and size metadata,
  • extension status and lifecycle information (e.g., whether an extension is active, failed to process, or quarantined from further scanning),
  • pipeline operational data (processing timestamps, error logs, retry counts) used for system reliability and troubleshooting.

This automated processing relates to extension data, not to you personally, except where extension developer contact information may be included in publicly available extension metadata.

3.9 Operational metrics and monitoring data

We may collect aggregated operational metrics about pipeline and service performance (e.g., execution durations, success/failure counts, health check results) using monitoring tools such as Prometheus. This data is used solely for system reliability, performance optimization, and troubleshooting. It does not contain personal data.

3.10 Monitor extension data (Extenshi Companion)

If you install the optional “Extenshi Monitor” companion browser extension, the following data may be processed locally on your device:

  • network destination metadata (scheme, host, port, and first URL path segment) of requests initiated by other browser extensions installed in your browser,
  • the URL of your active browser tab, used to evaluate site-binding rules that automatically enable or disable extensions based on the site you are visiting,
  • extension management actions (enable/disable) performed through the companion extension at your direction or through site-binding rules you configure.

This data is stored locally on your device and communicated to the Extenshi desktop application via Native Messaging. It is not transmitted to our servers unless you explicitly enable sync features described in Section 3.3.

3.11 Extension developer data (collected indirectly)

In the course of building our public catalog, we may collect personal data about extension developers from publicly available sources (browser extension store listings). This data is not obtained directly from the developers themselves. In accordance with Article 14 GDPR, we provide the following information:

  • Categories of data: developer/publisher name, contact email address (where publicly listed), website URL, and social media links.
  • Source: publicly accessible browser extension store pages (Chrome Web Store, Firefox Add-ons, Microsoft Edge Add-ons) and public web archives.
  • Purpose: to attribute extensions to their developers in our catalog, enable author verification, and allow users to contact developers.
  • Legal basis: legitimate interest (Article 6(1)(f) GDPR) — providing accurate attribution and transparency about extension authorship.
  • Your rights: if you are an extension developer whose data appears in our catalog, you may exercise your rights under GDPR (access, rectification, erasure, objection) by contacting us at [email protected]. You may also use our developer dispute process.

3.12 Scan notification subscription data

If you subscribe to receive a notification when a security scan completes for a specific extension, we process:

  • your email address,
  • a confirmation token (single-use, for double opt-in verification),
  • a per-subscription unsubscribe token,
  • the extension you subscribed to.

Unconfirmed subscriptions are automatically deleted after 24 hours. Confirmed subscriptions with no scan activity are deleted after 90 days. Each notification email includes a one-click unsubscribe link.

3.13 Developer self-declaration data (questionnaire)

If you are a verified extension author and complete our developer questionnaire, we process the self-declarations you provide, which may include:

  • monetization model and payment provider information,
  • categories of personal data your extension collects and the legal basis you declare,
  • whether your extension processes health or protected health information, and if so, your declared HIPAA scope and data protection officer contact email,
  • backend domains and third-party SDKs your extension uses,
  • telemetry and obfuscation disclosures,
  • justifications for broad permissions,
  • data retention periods and transparency URLs you provide.

Questionnaire responses are versioned (each submission creates a snapshot) and changes are recorded in an append-only audit log. Approved responses may be used to generate transparency signals displayed on your extension's public catalog page.

3.14 Extenshi CLI data (developer pre-publish scanning)

If you use the Extenshi CLI, an optional command-line tool that scans an extension package for security issues before you publish it, we process:

  • API keys: we store a hashed form (SHA-256) of each API key you generate, together with a short non-secret key prefix, an optional label you provide, and the creation, last-used, and revocation timestamps. We do not store the API key in plaintext.
  • Uploaded extension packages: when you run a scan, the CLI uploads the extension package file (e.g., .zip, .crx, .xpi) you select to our scanning service. The package is unpacked and analyzed by automated, offline scanners and is processed transiently — it is deleted once the scan completes and is not retained in our storage. The uploaded package and its scan findings are not written to our logs.
  • Scan job records: for each scan we retain operational metadata such as a scan job identifier, your user identifier, the uploaded artifact size, timing, and the scan outcome (success/failure). We do not retain the scan findings content or the uploaded file.
  • Credit balance and purchase records: your remaining and granted scan credits, and records of credit-pack purchases (credits added, amount, currency, and Stripe references). Payments are processed by Stripe as described in Section 3.6; we do not store full payment card details.

Extension packages you scan with the CLI may contain your own proprietary or unpublished code. They are submitted by you for the sole purpose of generating security analysis results and are not added to our public catalog.

3.15 Developer growth tools (uninstall feedback and welcome pages)

We offer optional developer tools that let a verified extension author configure an Extenshi-hosted page for their own extension: an uninstall-feedback survey (shown when an end user removes the extension) and a welcome / onboarding page (shown on first install). These pages are hosted by us on the author's behalf and collect data from the end users of that third-party extension, who are generally not Extenshi account holders. For submissions made through the uninstall-feedback survey we process:

  • the uninstall reason the end user selects (from a fixed taxonomy or the author's custom options),
  • an optional free-text comment the end user provides (up to 2,000 characters),
  • an optional contact email, only where the author enabled the contact field and the end user chooses to provide it,
  • the extension version, browser, and locale reported by the request.

For the welcome / onboarding page we record confirmed-install events with the extension version, browser, and locale, but no comment, email, or other content. For both tools we also store a one-way hashed (SHA-256, truncated) form of the submitter's IP address, used solely for abuse-prevention and rate-limiting; we do not store the raw IP address for these submissions.

Submissions are not linked to an Extenshi account and are readable only by the verified author who configured the page. For data collected through these tools, the configuring developer is the data controller and Extenshi acts as a processor/service provider on the developer's behalf; the developer is responsible for providing any notice and lawful basis required toward their own end users. This data is not added to our public catalog and is not used for our own marketing.

3.16 Extenshi CLI & MCP usage telemetry (anonymous, opt-out)

The Extenshi CLI and the Extenshi MCP server are optional tools you install on your own machine (e.g., via npm). By default these tools send anonymous usage telemetry so we can understand which commands and tools are used, which fail, and what errors recur. This telemetry is on by default and you can opt out at any time (see below and Section 9). When enabled, we process:

  • the command or tool name invoked and the surface (“cli” or “mcp”),
  • the tool version, Node.js version, and coarse operating system and CPU architecture, and whether the tool ran in a CI environment,
  • the names (never the values) of the command-line flags you pass,
  • a coarse error classification and operation durations,
  • a path-redacted error signature (error message and stack trace with home-directory paths stripped) when a command fails,
  • a single install event when the package is first installed as a real dependency (including the tool version, Node.js version, and coarse os/arch).

This telemetry is keyed to an anonymous per-install identifier (a random UUID stored in ~/.extenshi/config.json). It identifies an installation, not a person, and is not linked to your API key or account. The telemetry never includes file paths, extension package names or contents, manifest data, API keys, or other raw input you provide. Telemetry is processed by PostHog (EU region) on our behalf (see Section 7). Our legal basis is legitimate interest (Article 6(1)(f) GDPR) in maintaining and improving the tools, balanced against your interests by limiting collection to anonymous, non-content data.

How to opt out: set the environment variable DO_NOT_TRACK=1, set EXTENSHI_TELEMETRY=0 (or off/false/no), or set "telemetry": false in ~/.extenshi/config.json. Any of these disables both the runtime telemetry and the install event.

3.17 Developer integration data (GitHub and Chrome Web Store connections)

If you are a developer, you can optionally connect third-party developer accounts to your Extenshi account from the developer cabinet's Integrations page, so we can act on those accounts at your direction. These connections are established by you and can be disconnected at any time.

  • GitHub: when you install the “Extenshi Dojo” GitHub App on your account or organisation and select repositories, we process your GitHub account login, account type (personal or organisation), avatar URL, the app installation identifier, the permission scopes you grant, and the names and metadata of the repositories you select. With your authorisation we read the contents of the selected repositories — including private source code and manifest.json files — to audit and security-scan them, and, only where you additionally grant write access, we may commit generated assets, open pull requests, and store an Extenshi API key as an encrypted GitHub Actions secret in a repository you select. We do not store your GitHub access tokens; short-lived tokens are generated on demand from the app's own credentials.
  • Chrome Web Store: to let you prove ownership of, and manage, your extension listings, we provision a dedicated Google Cloud service account for your connection. You grant that service account access to your Chrome Web Store publisher account from your own Chrome Web Store Developer Dashboard. We then process your Chrome Web Store publisher ID, the identifiers of the listings you control, and the service-account email and Google Cloud project associated with your connection.

Where we store credentials for these integrations (such as the Chrome Web Store service-account private key), they are stored encrypted at rest (AES-256-GCM). Disconnecting an integration removes the connection and revokes the associated credential. These features transmit data to, and access your accounts on, GitHub and Google (Google Cloud and the Chrome Web Store API); see our processors in Section 7.

4. Purposes of processing

We process personal data to:

  1. Provide and operate the Services (authentication, account management, dashboards).
  2. Enable device registration, sync, and installation history features (if enabled).
  3. Provide public catalog functionality and related insights.
  4. Provide automated security/risk signals and historical timelines.
  5. Operate automated data pipelines for extension metadata collection, security scanning, and catalog updates.
  6. Provide customer support and service communications.
  7. Send newsletters and marketing communications to subscribers who opt in.
  8. Send scan completion notifications to subscribers who opt in via double opt-in.
  9. Collect and display developer self-declarations about extension data practices (questionnaire).
  10. Process subscriptions, billing, and license validation.
  11. Provide the Extenshi CLI pre-publish security scanning service for extension developers (API key management, processing uploaded extension packages, and credit accounting).
  12. Operate optional developer growth tools (Extenshi-hosted uninstall-feedback surveys and welcome pages) on behalf of verified extension authors.
  13. Understand usage of, and diagnose errors in, the optional Extenshi CLI and MCP developer tools (anonymous, opt-out telemetry).
  14. Operate optional developer integrations that connect your GitHub and Chrome Web Store accounts, at your direction, to audit and security-scan your extension source code, verify listing ownership, and commit generated assets or manage listings on your behalf.
  15. Secure the Services, prevent abuse, and troubleshoot issues.

Where GDPR/UK GDPR applies, we rely on:

  • Contract: to provide the Services you request (account, core functionality, paid access).
  • Consent: for optional features such as installation sync (and non-essential cookies where required).
  • Legitimate interests: to operate, secure, and improve the Services and maintain our public catalog, balanced against your rights.
  • Legal obligation: to retain certain records required by law (e.g., accounting/tax).

6. Sharing and disclosure

We share data only as needed:

  • Service providers (processors): hosting, storage, authentication, email delivery, monitoring, and payment providers.
  • Legal and safety: to comply with law, enforce our Terms, or protect rights and safety.
  • Business transfers: in a merger, acquisition, or asset sale (with appropriate safeguards).

7. Our processors (service providers)

We use third-party processors to deliver the Services. We have entered into data processing agreements (DPAs) with each processor in accordance with Article 28 GDPR. Our processors include:

  • Supabase (authentication and user management)
  • Hetzner Online GmbH (S3-compatible object storage, EU region)
  • Stripe (payments, subscriptions, invoices)
  • Infisical (secrets management for secure configuration of our Services)
  • Infrastructure hosting (deployment and hosting platform used to run our Services)
  • Cloudflare (Turnstile CAPTCHA for bot prevention during authentication and on public forms such as notification subscriptions and support requests)
  • PostHog (product analytics on our websites where enabled with user consent, and anonymous opt-out usage telemetry for the Extenshi CLI and MCP developer tools)
  • SMTP provider(s) (transactional email, where enabled)
  • Anthropic (AI-based security analysis of extension code and metadata)
  • GitHub, Inc. (source-code hosting integration — reading, and where you grant write access, writing to the repositories you connect via the “Extenshi Dojo” GitHub App; only for developers who connect a GitHub account)
  • Google LLC (Google Cloud service accounts and the Chrome Web Store API, used to verify and manage extension listings for developers who connect a Chrome Web Store publisher account)

8. International transfers

Some of our processors are based in the United States or other countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards:

  • EU-US Data Privacy Framework (DPF): where the processor is certified under the EU-US DPF (e.g., Stripe, Cloudflare, PostHog, Google, GitHub).
  • Standard Contractual Clauses (SCCs): the European Commission's approved standard contractual clauses, incorporated into our data processing agreements.
  • Adequacy decisions: where the European Commission has determined that a country provides an adequate level of data protection.

9. Your choices and controls

  • Sync control: You can enable/disable installation sync at any time in settings (where available).
  • Access/export: You can request a copy/export of your data.
  • Deletion: You can request deletion of your sync data and/or your account.
  • Withdraw consent: If processing is based on consent (e.g., sync), you can withdraw it at any time.
  • Newsletter: You can unsubscribe from marketing emails at any time using the link in each email.
  • CLI/MCP telemetry: The optional Extenshi CLI and MCP tools send anonymous, opt-out usage telemetry that is on by default. You can disable it with DO_NOT_TRACK=1, EXTENSHI_TELEMETRY=0, or "telemetry": false in ~/.extenshi/config.json (see Section 3.16).

10. Retention schedule

We retain personal data only as long as necessary for the purposes described and then delete or anonymize it, unless longer retention is required by law.

10.1 Default retention periods

  • Account & profile data: retained while your account is active. After account deletion, deleted or anonymized within 30 days, except where legally required to retain certain records.
  • Device records: retained while linked to your account; deleted within 30 days after device removal or account deletion.
  • Installation & event history (sync): retained for 24 months on a rolling basis (from event timestamp), then deleted or anonymized/aggregated.
  • Security and abuse-prevention logs: retained up to 180 days.
  • Scan notification subscriptions: unconfirmed subscriptions deleted after 24 hours; confirmed subscriptions with no scan activity deleted after 90 days.
  • Operational/server logs (including IP logs where applicable): retained up to 90 days.
  • Extenshi CLI data: uploaded extension packages are processed transiently and deleted once the scan completes (not retained). API keys are retained until you revoke them or delete your account. Scan job records and credit-purchase records are retained while your account is active and then deleted or anonymized within 30 days of account deletion, except billing records required to be kept under Section 10.2.
  • Developer growth tools (uninstall feedback & welcome pages): end-user submissions and confirmed-install events are retained while the configuring author keeps the page and their Extenshi account active; they are deleted when the author deletes the form or their account.
  • Support communications: retained up to 24 months after resolution, unless earlier deletion is requested and feasible.
  • Backups: may persist up to 90 days before automatic expiry.

10.2 Billing and tax records

We retain invoices and legally required billing/tax records for the statutory periods applicable to our obligations, which may be up to 10 years in certain VAT regimes. We retain such records even if you delete your account, to the extent required by law.

11. Security

We implement administrative, technical, and organizational measures designed to protect personal data. However, no system can be guaranteed 100% secure.

12. Children

The Services are not intended for children under 16. We do not knowingly collect personal data from children.

13. Your rights (EEA/UK)

Depending on your location, you may have rights to access, rectify, delete, restrict processing, object to processing, and data portability in certain cases. You may also lodge a complaint with your local supervisory authority. To exercise rights, contact [email protected].

14. Changes to this policy

We may update this Policy from time to time. We will publish the updated version and update the “Last updated” date.