Privacy Policy
1. Scope and who is responsible
This policy covers extops.dev, Product Web and its installable PWA, the Ext Ops Panel Chrome extension, the API, and hosted welcome and uninstall pages. Ext Ops Panel is the controller of developer account, device and service-operations data.
When an extension developer enables a hosted uninstall survey, that developer decides why feedback is collected and how it is used. The developer is responsible for the notice and legal basis presented to the extension user; Ext Ops Panel processes that feedback to provide the service.
2. Data we process
- Account data. When you use Google or Apple sign-in, we receive a provider identifier and the profile fields the provider releases, such as email, name and profile picture. Apple may provide a relay address or omit some fields.
- Device and session data. We store a public cryptographic key and its fingerprint to authenticate signed requests. The non-exportable private key remains on your device. Product Web also uses a secure session cookie.
- Extension and configuration data. Chrome extension IDs, roles, public Chrome Web Store metadata, hosted-page copy and settings, sources, endpoints, monitoring configuration, notification preferences and setup status.
- Lifecycle data. Event identifiers, event type, source and time for installs, uninstalls, reinstalls and feedback, plus daily aggregates. We do not collect end-user browsing history.
- Feedback. Selected uninstall reasons and optional free-text comments. A user may include personal information in free text, so developers must not request sensitive information that is unnecessary for the survey.
- Monitoring and notifications. Configured URLs, heartbeat reports, availability results, status changes and notification inbox state. If enabled, we also process Telegram chat/message identifiers or a Web Push endpoint and encrypted push key material.
- Credentials you provide. Custom-metric authentication secrets and optional Telegram bot tokens are encrypted at rest. Heartbeat tokens are stored as one-way hashes. Secret values are not returned to dashboard clients.
- Technical logs and local storage. Privacy-minimised operational logs may record request method and path without query parameters, time, status, response size and duration. Client IP is used transiently for rate limiting but is not written to the operational log, lifecycle analytics or product database; user-agent and referer are not written either. The site and PWA store theme, language, install-prompt and offline-snapshot preferences on your device.
3. Why we use data
We process data to authenticate you; provide dashboards, hosted lifecycle pages, feedback, monitoring and notifications; secure and troubleshoot the service; prevent abuse; comply with law; and improve reliability. Depending on the context, the legal basis is performance of our agreement with you, our legitimate interests in operating and protecting the service, compliance with legal obligations, or consent where required for an optional capability.
We do not sell personal data, run third-party behavioural advertising, or use extension-user data for unrelated profiling.
4. Sources
Data comes from you and your devices, Google or Apple when you sign in, public Chrome Web Store pages, lifecycle links and hooks configured by an extension developer, the optional uninstall form completed by an extension user, and systems or URLs that a developer explicitly connects for monitoring.
5. Service providers and disclosures
We disclose only what is needed to operate a selected capability:
- hosting, network, database and security providers process service traffic and stored data;
- Google or Apple processes sign-in requests when you choose that provider;
- Telegram receives message content and identifiers only when you connect Telegram; depending on your settings, messages can include lifecycle counts, monitoring status, uninstall reasons or feedback text;
- your browser's push service receives a destination and privacy-minimal notification payload when you enable Web Push;
- authorities or other parties may receive data when required by law or necessary to protect users and the service.
Paid checkout is not active at the date of this policy. If it is introduced, this policy and the checkout notice will identify the payment provider before payment data is processed.
6. Retention
- raw lifecycle events: 90 days;
- uninstall feedback: 180 days;
- Chrome Web Store history: 180 days, while the latest snapshot may be kept for the connected listing;
- daily lifecycle aggregates: kept while the relevant project or account remains active, including historical aggregates where the plan allows them to be displayed;
- custom-metric responses: rendered on demand and not stored as a historical time series;
- monitoring: the latest accepted snapshot and current status are kept while monitoring is configured; no heartbeat history is kept as a time series;
- account, configuration and notification data: kept while needed to provide the account or until deletion, subject to security, dispute and legal-record needs;
- encrypted backups: rotated within 30 days; a deleted record can remain in a backup until that backup expires and is restored only for disaster recovery;
- privacy-minimised infrastructure logs: kept only for the operational lifecycle and used for security, abuse prevention and diagnostics, not product analytics.
7. Your choices and rights
You can disconnect Telegram or Web Push, unlink an identity provider when another sign-in method remains, remove extensions and sources, and clear local site or PWA storage in your browser. You may request access, correction, export, restriction, objection or deletion where applicable. Self-service account deletion is planned; until it is available, send a request by email. We may need to verify the requester before acting.
If you submitted feedback through an extension's uninstall page, identify the extension and approximate submission time. We may coordinate the request with that extension's developer. You may also complain to your local data-protection authority.
8. International transfers
Service providers and optional channels may process data in countries other than yours. Where required, we use an applicable transfer mechanism and contractual or technical safeguards. Telegram, Google, Apple and browser push services apply their own privacy terms to their independent processing.
9. Security
We use encrypted transport, signed device requests, access controls, data minimisation, encryption or hashing for supported secrets, and bounded payloads and rate limits. No service can guarantee absolute security. Please do not send secrets or unnecessary sensitive personal data in feedback.
10. Chrome Web Store Limited Use
Use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Ext Ops Panel uses such information only to provide or improve its user-facing extension operations features.
11. Children and changes
The service is intended for extension developers and is not directed to children. We may update this policy as the product changes. We will update the date above and provide additional notice when a change materially affects your rights or our use of personal data.
12. Contact
Privacy questions and rights requests: husky.haul0925@gmail.com.