Back to PageTuck

PageTuck Privacy Policy

Effective date: October 4, 2026. Applies to PageTuck 1.0.2.

PageTuck assists with reading and writing using text you choose to attach and an AI provider you configure. Publisher: weichao. Public support and privacy contact: lazywc@gmail.com.

Information handled

Connection settings and API keys. Provider origin, model ID, interface/response language, appearance, and save-history preferences are stored locally in Chrome. By default, the API key is stored in Chrome session storage and is removed when the browser session ends. If you select Remember key, it is stored in local Chrome storage without encryption, until you remove it or uninstall the extension. It is never synced to a Google account. Session storage is restricted to trusted extension contexts. Local storage is also restricted when Chrome supports this API; older versions lack that restriction. PageTuck has no persistent content scripts, and its packaged page-text extraction function does not access storage or credentials. Keys are sent in the authorization header only to your configured provider. HTTP is permitted only for localhost services; other providers must use HTTPS. Requests do not follow redirects.

Attached page text and messages. When you click Attach page, or use the selection context menu, the extension reads the selected text or visible main-frame text and the current page title and URL. URL query strings and fragments are removed. Extraction excludes hidden text, form inputs, form content, and editable fields. It does not read Chrome's browsing history database, cookies, or passwords. Ordinary visible page text can still contain personal, financial, health, or other sensitive information. Review the source preview before sending. Nothing is sent to an AI provider merely by attaching a page or selecting a shortcut.

When you send a message, its text, selected recent conversation messages, attached source text, page titles, and cleaned URLs are transmitted directly to your chosen provider to produce a response. We do not operate a developer AI proxy or receive a copy of this traffic. Your provider receives your network IP address as part of the connection and applies its own privacy, retention, training, and billing terms. PageTuck does not control those terms. OpenAI, DeepSeek, OpenRouter, or a custom/local provider may be the recipient, depending on your configuration.

Saved work. With Save conversations enabled, messages and attachments are saved locally, up to the history count and storage limits. Old history is evicted when the 7 MiB history budget is exceeded. Disabling history prevents new saves and does not delete existing history. Saved notes and reusable workflows are also local. Local saved content is unencrypted, and may be included in device backups. Exported Markdown and JSON files are written to your chosen download location. Backups exclude API keys and license credentials. We do not upload notes or backups.

Licenses and purchases. In a publisher-configured commercial build, activating, validating, and deactivating a Pro license sends the license key and device instance information to Lemon Squeezy. Its response may include purchase/customer metadata; the extension retains only the key, instance ID, validation time, validity, and expiry. License verification is cached for up to 24 hours; a previously valid license may work during a temporary service outage for no more than 72 hours after the last successful check, and never beyond known expiry. Checkout opens Lemon Squeezy's hosted payment page. The extension does not collect payment card information. The publisher/payment processor may receive purchase records needed for fulfillment, support, refunds, and applicable obligations. In the default free build, purchasing and license requests are disabled.

Data use and sharing

Data is used only for the disclosed AI reading/writing functionality and, when configured, license fulfillment. There are no analytics SDKs, advertising trackers, background webpage collection, sales of browsing data, or remote executable code. We do not sell user data or use it for targeted advertising. PageTuck's use and transfer of information received from Chrome/Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

If you contact support, the publisher receives the information you deliberately provide through that support channel. Do not include API keys, full license credentials, private page contents, or personal information in public reports. No automatic error reports are uploaded by the extension.

Control, retention, and deletion

Changes and contact

Material changes to data handling will be disclosed in the extension and store listing before new behavior is enabled. The public policy will be updated accordingly. Use the public support contact shown on the publisher's website and Chrome Web Store listing for privacy requests.

For privacy requests, email lazywc@gmail.com.