In short
Our extensions process your content on your own device. We do not collect the pages you capture, the prompts you type, or the sites you visit. What we do hold is what a paid licence requires, what an optional feature such as settings sync requires once you enable it, and what you send us by email. Some extensions need no account and hold nothing at all — each one’s policy says which it is.
Per-extension policies: Snapshot · Prompt Guard · Tab Hive · Clip Vault · Page Pulse
01Who is responsible for your data
ExtHive is the data controller for personal data processed through this website and our extensions.
Add your registered business address
Add your country of incorporation
Privacy contact: privacy@exthive.com
For purchases, Paddle.com Market Ltd. acts as Merchant of Record and is an independent controller of the payment data it collects. Their privacy notice governs that processing.
02Our operating principle
We design our extensions so that the sensitive work happens where the sensitive data already is: in your browser, on your machine. Capture, scanning, redaction and storage of your settings are local operations.
This means that, as a rule:
- we do not receive the content of pages you capture or prompts you write;
- we do not build a profile of your browsing;
- we do not sell, rent or share personal data with advertisers or data brokers — not now, and not under any future change to this policy;
- we do not use your content to train machine learning models.
Where a specific feature departs from this — for example a Team plan fetching an administrator’s policy file — it is documented in that extension’s own policy.
03What we do collect
Account and licence data
If you buy a paid plan, we process your email address, licence key, plan, subscription status and country of purchase. We need this to activate your licence, to let you manage it, and to meet tax obligations.
Settings you choose to sync
Some paid plans offer sync so that your own devices share one configuration. It is off until you turn it on. When it is on, we store the settings themselves — detector rules, preferences, allowlists — encrypted in transit and at rest. We do not store the content those settings are applied to.
Organisation data on Team plans
Where an organisation buys seats, we hold the administrator’s policy, the list of seats and their assignment, and audit metadata reported by each seat: which detector fired, when, and what the user did about it. Administrators see that a credential was caught, never the credential, and never the prompt around it.
Payment data
Card and billing details are collected and processed by Paddle. ExtHive receives only the transaction outcome, the last four digits of the card, and the billing country. We never receive or store your full card number.
Support correspondence
When you email us, we hold your message, address and any attachments so we can reply and to keep a record if the issue recurs.
Website analytics
We use privacy-preserving, cookie-free analytics on this website to count page views and referrers in aggregate. It sets no cookies, stores no identifiers and cannot follow you to other sites. See the Cookie Policy for detail.
Diagnostic data
If an extension crashes, it may record an error message, the extension version and your browser version locally. Nothing is transmitted unless you explicitly choose to send a report, and the report is shown to you in full before it is sent.
04Why we are allowed to process it
For users in the UK, EEA and Switzerland, our lawful bases under the GDPR are:
| Data | Purpose | Lawful basis |
|---|---|---|
| Licence & account data | Provide the paid plan you bought | Performance of a contract |
| Synced settings | Keep your own devices in step, at your request | Consent |
| Team policy & audit metadata | Operate the Team plan your organisation bought | Performance of a contract |
| Payment records | Tax, accounting and fraud prevention | Legal obligation |
| Support emails | Answer your question | Legitimate interests |
| Aggregate analytics | Understand which pages are useful | Legitimate interests |
| Release emails | Tell you when something ships | Consent |
06International transfers
Our processors may store data outside your country, including in the United States. Where personal data is transferred out of the UK or EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.
07How long we keep it
- Licence and subscription records — for as long as your subscription is active, then up to 7 years where tax law requires it.
- Synced settings — for as long as sync is enabled, and deleted within 30 days of you turning it off, ending the subscription or deleting your account.
- Team policy and audit metadata— for the life of the organisation’s subscription, or a shorter period where the administrator sets one.
- Support correspondence — 24 months from the last message in the thread.
- Aggregate analytics — 12 months, and never linked to an individual.
- Data stored inside an extension — until you clear it or uninstall. It is on your device, so its lifetime is in your hands, not ours.
08Your rights
Depending on where you live, you have some or all of the following rights: to access the personal data we hold about you, to correct it, to erase it, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time.
Residents of California may additionally request disclosure of categories of personal information collected and opt out of “sale” or “sharing” — neither of which we do. We will never discriminate against you for exercising any privacy right.
To exercise any right, email privacy@exthive.com. We respond within 30 days and do not charge a fee. You also have the right to complain to your local data protection authority.
09Security
Data in transit is encrypted with TLS. Access to licence records is limited to the people who need it, protected by multi-factor authentication, and logged.
Our strongest security measure is architectural: the data most likely to hurt you if leaked — your captures, your prompts, your browsing — is never sent to us, so it cannot be exposed by a breach of our systems.
If a breach affecting personal data occurs, we will notify affected users and the relevant authority within 72 hours of becoming aware of it.
10Children
The Services are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact privacy@exthive.com and we will delete it.
11Changes to this policy
We will post any change here and update the date at the top of the page. If a change materially reduces the protection of data we already hold, we will notify affected users by email before it takes effect. Previous versions are available on request.
Questions about this document?
Write to legal@exthive.com and a person will answer, usually within 1 business day.