Privacy Policy
Last updated: __EFFECTIVE_DATE__
The short version
- Weaver works without an account. Until you turn on Sync or sign in, your data never leaves your browser.
- We collect only what we need to run Sync, hosted AI and your subscription.
- We don’t sell your data, show ads, or track you across the web.
- You can export or delete your data at any time.
Who we are
Weaver (“we”, “us”) is a browser extension and service operated by __LEGAL_ENTITY__. Questions about this policy can be sent to support@weavertab.work.
Data that stays on your device
Your Spaces, folders, bookmarks, sticky notes and settings are stored in Chrome’s extension storage on your computer. The list of your open tabs and browsing history is read locally to show them on your new tab and is never sent to us. AI API keys you enter are stored only on your device and are never synced or exported.
Data we process when you use online features
| Feature | What we process | Why |
|---|---|---|
| Account | Email address, name and avatar from your sign-in provider (Google, GitHub or email), sign-in timestamps, device names you register | To identify you and secure your account |
| Weaver Sync (Pro) | Your Spaces, folders, bookmarks (titles and URLs), sticky notes, sync settings and version history | To keep your devices in sync and let you restore earlier versions |
| Hosted AI (credits) | For each item you ask Weaver to organize: its title (truncated), domain and URL path — never query strings, page content or incognito tabs. Token and credit counts. | To generate an organization plan and meter your credits. Item contents are not stored after the request completes. |
| Subscription | Plan, status, renewal dates and an order reference. Card details are handled by our payment partner and never reach us. | To provide Weaver Pro |
| Service logs | Request metadata such as timestamps, error codes and coarse region, without bookmark contents | Security, abuse prevention and debugging |
When you use AI Organize with your own API key, requests go directly from your browser to the provider you configure. We never see those requests; that provider’s privacy policy applies.
Service providers
We rely on a small number of providers who process data on our behalf under contract:
- Supabase — authentication, database and server functions (account, sync and credit data).
- __AI_PROVIDER__ — language model for hosted AI Organize, under terms that prohibit training on your data.
- Waffo Pancake — payment processing as merchant of record; it is the seller of record for your subscription and handles tax.
- __EMAIL_PROVIDER__ — delivery of sign-in codes and service emails.
Data may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses.
Retention
- Sync data and version history: kept while your account is active; version history is limited to the last 30 days.
- Hosted AI request contents: not stored after the response is returned.
- Account data: deleted within 30 days after you delete your account; encrypted backups roll off within a further 7 days.
- Billing records: kept as long as tax law requires.
- Service logs: up to 14 days.
Your choices and rights
- Export — export your bookmarks at any time from Settings (JSON or HTML), and request a copy of your account data.
- Delete — delete your account from Settings. Your local data on each device is not affected unless you clear it.
- Correct or object — contact us to correct your data or object to processing.
- Depending on where you live (for example the EU, UK or California), you may have additional rights, including the right to complain to your data protection authority.
Chrome Web Store Limited Use
Weaver’s use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this data only to provide the features you see in Weaver; we do not transfer it for advertising, credit-worthiness or any purpose unrelated to Weaver’s single purpose, and humans do not read it except with your permission, for security, or as required by law.
Security
Data in transit is protected with TLS. Sync data is stored in access-controlled databases where each account can read only its own rows. No system is perfectly secure; we will notify you of a breach affecting your data as required by law.
Children
Weaver is not directed to children under 13 (or 16 where local law requires), and we do not knowingly collect their data.
Changes
If we make material changes we will update the date above and notify you in the extension or by email before they take effect.