In short
Our extensions process your content on your own device. We do not collect the pages you capture, the prompts you type, or the sites you visit. What we do hold is what a paid licence requires, what an optional feature such as settings sync requires once you enable it, and what you send us by email. Some extensions need no account and hold nothing at all — each one’s policy says which it is.
Per-extension policies: Snapshot Studio
01Who is responsible for your data
ExtHive is the data controller for personal data processed through this website and our extensions.
Add your registered business address
Add your country of incorporation
Privacy contact: support@ext-hive.com
For purchases, Paddle.com Market Ltd. acts as Merchant of Record and is an independent controller of the payment data it collects. Their privacy notice governs that processing.
02Our operating principle
We design our extensions so that the sensitive work happens where the sensitive data already is: in your browser, on your machine. Capture, scanning, redaction and storage of your settings are local operations.
This means that, as a rule:
- we do not receive the content of pages you capture or prompts you write;
- we do not build a profile of your browsing;
- we do not sell, rent or share personal data with advertisers or data brokers — not now, and not under any future change to this policy;
- we do not use your content to train machine learning models.
Where a specific feature departs from this — for example a Team plan fetching an administrator’s policy file — it is documented in that extension’s own policy.
03What we do collect
Account and licence data
If you buy a paid plan, we process your email address, licence key, plan, subscription status and country of purchase. We need this to activate your licence, to let you manage it, and to meet tax obligations.
Settings you choose to sync
Some paid plans offer sync so that your own devices share one configuration. It is off until you turn it on. When it is on, we store the settings themselves — detector rules, preferences, allowlists — encrypted in transit with TLS. We do not store the content those settings are applied to.
Organisation data on Team plans
Where an organisation buys seats, we hold the administrator’s policy, the list of seats and their assignment, and audit metadata reported by each seat: which detector fired, when, and what the user did about it. Administrators see that a credential was caught, never the credential, and never the prompt around it.
Payment data
Card and billing details are collected and processed by Paddle. ExtHive receives only the transaction outcome, the last four digits of the card, and the billing country. We never receive or store your full card number.
Support correspondence
When you email us, we hold your message, address and any attachments so we can reply and to keep a record if the issue recurs.
Website analytics
If you accept it, we use Google Analytics 4 on this website to count visitors and see which pages are read. It sets a cookie holding a randomly generated identifier for your browser, which is what allows two visits from you to be counted as one visitor rather than two. That identifier is personal data, and Google acts as our processor for it on infrastructure that includes servers in the United States.
Google Signals, ad personalisation and data sharing for advertising are all disabled, so this is not used to build an advertising profile of you or to target you on other sites. What we see is aggregate: pages, referrers, approximate country, browser and device.
None of this happens unless you accept it. Until then no analytics script is loaded and no request reaches Google, and you can withdraw at any time from Cookie settings in the footer. The Cookie Policy sets out the cookie names and lifetimes.
Diagnostic data
If an extension crashes, it may record an error message, the extension version and your browser version locally. Nothing is transmitted unless you explicitly choose to send a report, and the report is shown to you in full before it is sent.
04Why we are allowed to process it
For users in the UK, EEA and Switzerland, our lawful bases under the GDPR are:
| Data | Purpose | Lawful basis |
|---|---|---|
| Licence & account data | Provide the paid plan you bought | Performance of a contract |
| Synced settings | Keep your own devices in step, at your request | Consent |
| Team policy & audit metadata | Operate the Team plan your organisation bought | Performance of a contract |
| Payment records | Tax, accounting and fraud prevention | Legal obligation |
| Support emails | Answer your question | Legitimate interests |
| Aggregate analytics | Understand which pages are useful | Consent |
| Release emails | Tell you when something ships | Consent |
06International transfers
Our processors may store data outside your country, including in the United States. Where personal data is transferred out of the UK or EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.
07How long we keep it
- Licence and subscription records — for as long as your subscription is active, then up to 7 years where tax law requires it.
- Synced settings — for as long as your subscription is active, then deleted within 30 days of it ending. Items you delete are kept as a marker for the same period, so that another of your devices cannot resurrect them, and then removed entirely. Turning sync off in the extension stops anything further leaving your device; ask us and we will delete what is already stored, without waiting for that window.
- Support correspondence — 24 months from the last message in the thread.
- Aggregate analytics — 12 months, and never linked to an individual.
- Data stored inside an extension — until you clear it or uninstall. It is on your device, so its lifetime is in your hands, not ours.
08Your rights
Depending on where you live, you have some or all of the following rights: to access the personal data we hold about you, to correct it, to erase it, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time.
Residents of California may additionally request disclosure of categories of personal information collected and opt out of “sale” or “sharing” — neither of which we do. We will never discriminate against you for exercising any privacy right.
To exercise any right, email support@ext-hive.com. We respond within 30 days and do not charge a fee. You also have the right to complain to your local data protection authority.
09Security
Data in transit is encrypted with TLS. Access to licence records is limited to the people who need it, protected by multi-factor authentication, and logged.
Our strongest security measure is architectural: the data most likely to hurt you if leaked — your captures, your prompts, your browsing — is never sent to us, so it cannot be exposed by a breach of our systems.
If a breach affecting personal data occurs, we will notify affected users and the relevant authority within 72 hours of becoming aware of it.
10Children
The Services are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact support@ext-hive.com and we will delete it.
11Changes to this policy
We will post any change here and update the date at the top of the page. If a change materially reduces the protection of data we already hold, we will notify affected users by email before it takes effect. Previous versions are available on request.
Questions about this document?
Write to support@ext-hive.com and a person will answer, usually within 1 business day.