Privacy

KeepWhy Privacy Policy

Last updated:

Product: KeepWhy, a Chrome extension by Ryan Chen. Privacy Policy URL: https://ryanchenxr.github.io/keepwhy/privacy/.

Purpose and local data

KeepWhy helps you record why you saved a webpage, organize that bookmark, and find it later by keyword or description. It has no account and no developer-operated bookmark sync/cloud backend. KeepWhy stores its bookmark records and AI settings in your browser's chrome.storage.local; a temporary panel token uses chrome.storage.session. Local records may contain URL, title, domain, your reason, Chrome bookmark IDs and folder paths, timestamps, category, tags, search hints, field-source information, and AI processing status. AI-generated category, tags, and search hints are optional. Search queries are processed locally and are not stored as a separate search history by KeepWhy.

When you click the toolbar icon on a normal webpage, KeepWhy reads that tab's URL, title and favicon URL to show the save panel. It does not collect browsing history or automatically monitor pages. It reads existing Chrome bookmarks to search them and to reuse matching bookmarks; it may create a Chrome bookmark when you save or restore a record. It does not automatically move, rename, or delete old Chrome bookmarks. The current implementation does not extract page body text or meta descriptions.

Optional AI and API Key

You may configure your own compatible AI provider, API Base URL, API Key, and model. The API Key is stored in chrome.storage.local; extension code reads it to authenticate requests directly to your selected provider. It is not sent to a KeepWhy developer-operated server and is not included in a KeepWhy backup export. Provider host access is optional at installation; clicking Connect requests only the origin of the URL you entered and sends the Key to its /models endpoint. This includes a user-selected local OpenAI-compatible provider at http://localhost or http://127.0.0.1. Saving AI configuration sends a fixed verification message to /chat/completions.

The AI configuration screen discloses these optional transmissions before connection. When AI enrichment is enabled, KeepWhy sends the saved page's title, URL, domain, your reason, and existing category/tag vocabulary to that provider for classification, tags, and search hints. A repair attempt may include a limited excerpt of the provider's preceding invalid answer. When you explicitly submit a search with low local confidence, it sends the current query and a small category/tag vocabulary to the provider for query expansion; it does not send the full bookmark library. AI output returns to KeepWhy and is used only as structured data for local organization/search. Without an AI configuration, saving, Chrome bookmark reuse, local search, Settings, and backup remain usable.

The provider is a separate third party with its own data practices. Review its terms and privacy policy before connecting. KeepWhy does not control a provider's retention or use of data sent to it. Normal browser navigation to a saved website or About link follows that site's own policies.

Backup, deletion, and security

Export creates a JSON file on your device containing KeepWhy-managed bookmarks, including URLs, titles, reasons and optional metadata. It excludes AI settings, API Key, Chrome bookmark IDs, and runtime errors. Treat this file as personal data and choose where to store or share it. Import reads a file you select, previews counts, then merges by canonical URL after confirmation; it may create Chrome bookmarks if no match exists. Import does not automatically invoke AI.

Removing the extension removes its extension-local storage under Chrome's normal extension lifecycle. Chrome-native bookmarks and backup files you exported are separate and may remain; manage them in Chrome or your file storage. KeepWhy does not promise encryption beyond the browser and operating system storage controls. Provider calls use HTTPS for remote services; HTTP is allowed only for a user-selected localhost or 127.0.0.1 provider. Keep your API Key and exported backups private.

Limited Use

KeepWhy uses data obtained through Chrome permissions only for its disclosed bookmark saving, organization, retrieval, optional AI, and backup features. It does not sell user data or transfer it to data brokers, does not use it for personalized or interest-based advertising, and does not provide a developer-operated server through which Ryan Chen can read your local bookmark data. Any information obtained from Google APIs is used and transferred in accordance with the Chrome Web Store User Data Policy, including its Limited Use requirements. KeepWhy does not permit human access to user data except where the policy allows it, such as a specific support request with the user's consent or a legal/security obligation. Optional provider transmissions described above are necessary for the AI features you choose to use.

Changes and contact

This policy describes the current V0.1 implementation. Material changes to data practices will be disclosed before the changed version is published.

For questions or privacy requests, use the public support or X links above. Do not post API Keys or private bookmark data in a public issue.

Policy reference: Chrome Web Store User Data Policy.