Effective date: [insert on publish]
This Privacy Policy describes how Unveil (“Unveil,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information in connection with the Unveil browser extension, our website, and associated services (collectively, the “Service”).
For legal and operational purposes, the operator of the Service is the individual or entity identified in the Chrome Web Store listing, on our website, or in other official Unveil notice in effect at the time of your use (“Operator”). As of the effective date above, questions may be sent to support@unveil.shopping. By using the Service, you acknowledge the practices described here.
1.1 Scope
This policy applies to information processed through the Service, including when you install and use the extension, have a page analyzed, subscribe and have your subscription verified, submit feedback, or contact us. It does not govern the practices of Anthropic, Stripe, Vercel, the retailers whose pages you visit, or other third parties except as expressly described. The Service is primarily intended for users in the United States.
1.2 What We Collect
A. Page information from commerce sites you visit. When Unveil analyzes a qualifying page, it reads the visible policy-related text on that page (return policy, shipping terms, fee disclosures, subscription signals), basic product details (title, price), and the page’s web address (URL). This happens only on recognized or qualifying commerce pages — not on your general browsing.
B. Local usage data. Counts of scans, alerts, and clears; your monthly lookup count; and your subscription/session token are stored locally in your browser (chrome.storage.local / extension storage). This stays on your device. Additionally, after you verify your subscription, the email address you verified with is kept in your browser’s extension sync storage (chrome.storage.sync) so that reinstalling Unveil — or installing it on another device signed in to the same browser account — recognizes you; if browser sync is enabled, your browser (e.g., Google Chrome) syncs that value between your own devices under your browser account. It is not transmitted to us except as described elsewhere in this policy.
C. Account / email. If you subscribe, your email is used to verify your subscription status against our payment processor (Stripe). We don’t maintain a separate password — your subscription is verified by looking your email up in Stripe.
D. Payment information. Handled entirely by Stripe. We never receive, see, or store your card number or billing details.
E. Feedback. If you use the “Report site” / feedback form, we collect the site you reported, the category you chose, and any message you write. Please don’t include sensitive personal information in free-text feedback.
F. Device & diagnostics. Our backend and infrastructure providers may process limited technical information needed to operate and protect the Service — e.g. extension version, basic request metadata, error/diagnostic information, and anti-abuse/rate-limit signals. We do not use third-party advertising SDKs and do not use analytics for cross-app behavioral advertising.
1.3 How Your Data Flows When a Page Is Analyzed
- The extension reads the qualifying page in your browser and assembles a small structured summary of it (scraped policy/fee/subscription text, product title and price, and the page URL).
- That summary is sent over an encrypted connection to Unveil’s own backend service (
api/analyze), which holds our AI credentials securely server-side. (Your data passes through our server; it is not sent to the AI provider directly from your browser.) - When the page’s policy text couldn’t be read in the browser (e.g. a site blocks scripted reading), our backend may itself request the store’s public pages to read the policy or confirm where an item ships from. It requests only publicly available store pages — never anything tied to your account or session.
- Our backend sends the assembled text to Anthropic’s Claude API (model
claude-haiku-4-5) to generate the plain-English summary, which is returned to your browser and shown in the extension.
1.4 How We Use Information
We use information to: provide, maintain, and improve the Service; generate the plain-English summaries you see; verify your subscription and manage billing; show you your own usage stats; respond to feedback and support requests; detect, investigate, and prevent abuse, fraud, security incidents, and technical issues; and comply with applicable law. We may use de-identified or aggregated information for debugging and service improvement. We do not use your data for advertising, profiling, or cross-web tracking, and we do not sell, rent, or transfer it to data brokers or ad platforms.
1.5 How Information Is Stored
- On your device: cached summaries (keyed by site domain, capped at 500 domains), usage stats, and your subscription/session token are stored locally in your browser and removed when you uninstall the extension. The verified-email note in extension sync storage persists across uninstalls by design (that is what lets a reinstall recognize you); remove it by turning off extension sync or removing the extension’s synced data via your browser’s sync controls.
- On our backend: the analyze service is stateless — it processes your page information in transit to produce the summary and does not store it in a database. Transient operational logs may briefly capture diagnostic snippets for reliability and security; these are not used to build any profile of you.
- Subscription records (email): retained by us and by Stripe for as long as your subscription is active and as required for billing/tax records.
1.6 AI Processing Disclosure
When a page is analyzed, the assembled page text is processed by Anthropic’s Claude (claude-haiku-4-5) via our backend to produce the summary. This is fully automated — no human reviews the content. Data sent for AI processing is handled under the AI provider’s then-current commercial API terms, configuration, and retention settings; those practices may change, and we may change AI providers or routing and will update this policy accordingly. AI output is probabilistic and may be incomplete or inaccurate; always verify with the retailer for anything time-sensitive or high-value.
1.7 Who We Share Information With
We do not sell your personal information and do not share it for third-party cross-context behavioral advertising. We disclose information to:
- Anthropic (AI inference) — receives the assembled page text to generate the summary.
- Stripe (payments) — receives your email and payment details for billing and subscription verification.
- Vercel (hosting/infrastructure) — hosts our backend and website and processes related request metadata.
- Anti-abuse / rate-limiting infrastructure — request and rate-limit metadata may be processed to protect the Service. [Name the specific provider here once implemented.]
- Legal, compliance, and safety: we may disclose information where we believe in good faith it is necessary to comply with law or lawful process, enforce our terms, protect the security and integrity of the Service, or protect the rights, property, or safety of Unveil, our users, or others.
- Business transfers: if we are involved in a merger, acquisition, financing, asset sale, or similar transaction, information may be transferred as part of that transaction, subject to applicable law.
Each third party maintains its own terms and privacy practices.
1.8 Retention
We retain information only as long as reasonably necessary for the purposes above or as required by law. Local app data remains on your device until you uninstall or clear it. The backend does not retain page content beyond transient logs. Subscription/email records are retained while your subscription is active and as needed for billing, tax, dispute-resolution, and legal-compliance purposes. Short-lived anti-abuse/rate-limit data may persist temporarily according to provider TTLs and expire automatically. Deletion requests may not be immediate or universal — backups, security records, and records required by law may persist for a limited period.
1.9 Your Choices and Rights
You may: clear local cache and stats by uninstalling the extension; manage or cancel your subscription via the account link (Stripe portal); and request access to, correction of, or deletion of data we hold server-side (your subscription/email record) by contacting support@unveil.shopping. Some requests may be limited by legal obligations, identity verification, technical feasibility, or our need to operate the Service.
1.10 U.S. State Privacy Rights
Depending on your state of residence, you may have additional rights — to confirm whether we process your personal information, to request access or deletion, to correct inaccuracies, to opt out of “sale” or “sharing” (note: we do not sell or share personal information for cross-context behavioral advertising), and to appeal a denied request where required by law. To exercise these rights, contact support@unveil.shopping and tell us which state law you’re invoking so we can route the request appropriately. We will not discriminate against you for exercising these rights.
1.11 International Processing
Your information may be processed in countries other than where you reside, including where our service providers operate. Those countries may have different data-protection laws. Where required, we take reasonable steps to require appropriate safeguards, though no transfer mechanism eliminates all risk.
1.12 Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction — including keeping our AI credentials server-side and transmitting data over encrypted connections. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for the security of your own device and browser profile.
1.13 Children’s Privacy
Unveil is not directed to children under 13, and we do not knowingly collect their personal information. If local law sets a different age threshold for digital consent, that threshold applies. If you believe a child has provided information, contact us and we will take appropriate steps.
1.14 Changes to This Policy
We may update this policy from time to time. For material changes we will update the effective date and may notify users via the extension or our website. Continued use after the revised policy becomes effective means you acknowledge it.
1.15 Contact
support@unveil.shopping · [insert business address]
Chrome Web Store Limited Use disclosure (required statement): “The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.”