Effective date: August 30, 2026
This Privacy Policy describes how Unveil (“Unveil,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information in connection with the Unveil browser extension, our website, and associated services (collectively, the “Service”).
For legal and operational purposes, the operator of the Service is the individual or entity identified in the Chrome Web Store listing, on our website, or in other official Unveil notice in effect at the time of your use (“Operator”). As of the effective date above, questions may be sent to support@unveil.shopping. By using the Service, you acknowledge the practices described here.
1.1 Scope
This policy applies to information processed through the Service, including when you install and use the extension, have a page analyzed, subscribe and have your subscription verified, submit feedback, or contact us. It does not govern the practices of Anthropic, Stripe, Vercel, Upstash, the retailers whose pages you visit, or other third parties except as expressly described. The Service is primarily intended for users in the United States.
1.2 What We Collect
A. Page information from commerce sites you visit. When Unveil analyzes a qualifying page, it reads the visible policy-related text on that page (return policy, shipping terms, fee disclosures, subscription signals), basic product details (title, price), and the page’s web address (URL). This happens only on recognized or qualifying commerce pages — not on your general browsing. When Unveil reads a store’s policy pages, it does so without your session: the request carries none of your cookies or sign-in, so it reads the same terms any visitor would see.
B. Local usage data. Counts of scans, alerts, and clears; your monthly lookup count; and your subscription/session token are stored locally in your browser (chrome.storage.local / extension storage). This stays on your device. Additionally, after you verify your subscription, a single yes/no marker — that you have verified before, and nothing about which account — is kept in your browser’s extension sync storage (chrome.storage.sync), so that reinstalling Unveil, or installing it on another device signed in to the same browser account, takes you straight to the verification step instead of the welcome page. It contains no email address. If browser sync is enabled, your browser (e.g., Google Chrome) syncs that marker between your own devices under your browser account. It is never transmitted to us.
C. Account / email. If you subscribe, your email is used to verify your subscription status against our payment processor (Stripe). We don’t maintain a separate password — your subscription is verified by looking your email up in Stripe.
D. Payment information. Handled entirely by Stripe. We never receive, see, or store your card number or billing details.
E. Feedback. If you use the “Report site” / feedback form, we collect the site you reported, the category you chose, and any message you write. The report also includes a short technical summary of what Unveil itself displayed on that site — for example whether it showed an alert, an all-clear, or nothing at all, and which version of our judgment produced it. That summary describes our own behavior, not your browsing: it contains no page address, no product details, and no record of what you were looking at. Please don’t include sensitive personal information in free-text feedback.
F. Device & diagnostics. Our backend and infrastructure providers may process limited technical information needed to operate and protect the Service — e.g. extension version, basic request metadata, error/diagnostic information, and anti-abuse/rate-limit signals. We do not use third-party advertising SDKs and do not use analytics for cross-app behavioral advertising.
1.3 How Your Data Flows When a Page Is Analyzed
- The extension reads the qualifying page in your browser and assembles a small structured summary of it (scraped policy/fee/subscription text, product title and price, and the page URL).
- That summary is sent over an encrypted connection to Unveil’s own backend service (
api/analyze), which holds our AI credentials securely server-side. (Your data passes through our server; it is not sent to the AI provider directly from your browser.) - When the page’s policy text couldn’t be read in the browser (e.g. a site blocks scripted reading), our backend may itself request the store’s public pages to read the policy or confirm where an item ships from. It requests only publicly available store pages — never anything tied to your account or session.
- Our backend sends the assembled text to Anthropic’s Claude API (model
claude-haiku-4-5) to generate the plain-English summary, which is returned to your browser and shown in the extension.
1.4 How We Use Information
We use information to: provide, maintain, and improve the Service; generate the plain-English summaries you see; verify your subscription and manage billing; show you your own usage stats; respond to feedback and support requests; detect, investigate, and prevent abuse, fraud, security incidents, and technical issues; and comply with applicable law. We may use de-identified or aggregated information for debugging and service improvement. We do not use your data for advertising, profiling, or cross-web tracking, and we do not sell, rent, or transfer it to data brokers or ad platforms.
1.5 How Information Is Stored
- On your device: cached summaries (keyed by site domain, capped at 750 entries), usage stats, and your subscription/session token are stored locally in your browser and removed when you uninstall the extension. A single yes/no marker in extension sync storage persists across uninstalls by design — that is what lets a reinstall skip the welcome page. It contains no email address. Earlier versions of Unveil stored the verified email address here; the extension now removes it automatically. Remove the marker itself by turning off extension sync or removing the extension’s synced data via your browser’s sync controls.
- On our backend: your page information is processed in transit to produce the summary and is not stored in a database. We do keep two things, and both are keyed to the store rather than to you: a cached summary for each site, so that a store already analyzed for one subscriber does not need re-analyzing for the next; and the short technical record of each analysis described in 1.8. Neither contains page content, a page address, or any identifier for you. Transient operational logs may briefly capture diagnostic snippets for reliability and security; none of this is used to build any profile of you.
- Subscription records (email): retained by us and by Stripe for as long as your subscription is active and as required for billing/tax records.
1.6 AI Processing Disclosure
When a page is analyzed, the assembled page text is processed by Anthropic’s Claude (claude-haiku-4-5) via our backend to produce the summary. This is fully automated — no human reviews the content. Data sent for AI processing is handled under the AI provider’s then-current commercial API terms, configuration, and retention settings; those practices may change, and we may change AI providers or routing and will update this policy accordingly. AI output is probabilistic and may be incomplete or inaccurate; always verify with the retailer for anything time-sensitive or high-value.
1.7 Who We Share Information With
We do not sell your personal information and do not share it for third-party cross-context behavioral advertising. We disclose information to:
- Anthropic (AI inference) — receives the assembled page text to generate the summary.
- Stripe (payments) — receives your email and payment details for billing and subscription verification.
- Vercel (hosting/infrastructure) — hosts our backend and website and processes related request metadata.
- Upstash (key-value storage, via Vercel) — holds rate-limit and usage-cap counters, cached per-store summaries, and the short technical records described in 1.8.
- Legal, compliance, and safety: we may disclose information where we believe in good faith it is necessary to comply with law or lawful process, enforce our terms, protect the security and integrity of the Service, or protect the rights, property, or safety of Unveil, our users, or others.
- Business transfers: if we are involved in a merger, acquisition, financing, asset sale, or similar transaction, information may be transferred as part of that transaction, subject to applicable law.
Each third party maintains its own terms and privacy practices.
1.8 Retention
We retain information only as long as reasonably necessary for the purposes above or as required by law. Local app data remains on your device until you uninstall or clear it. The backend does not retain page content beyond transient logs. We do keep a short technical record of each analysis — the store’s domain, whether it succeeded, how long it took, and a summary of the result we produced — for up to 30 days, so that a problem someone reports to us can be investigated. These records are keyed to the store, not to you: they contain no account identifier, no page address, and no page content. Subscription/email records are retained while your subscription is active and as needed for billing, tax, dispute-resolution, and legal-compliance purposes. Short-lived anti-abuse/rate-limit data may persist temporarily according to provider TTLs and expire automatically. Deletion requests may not be immediate or universal — backups, security records, and records required by law may persist for a limited period.
1.9 Your Choices and Rights
You may: clear local cache and stats by uninstalling the extension; manage or cancel your subscription via the account link (Stripe portal); and request access to, correction of, or deletion of data we hold server-side (your subscription/email record) by contacting support@unveil.shopping. Some requests may be limited by legal obligations, identity verification, technical feasibility, or our need to operate the Service.
1.10 U.S. State Privacy Rights
Depending on your state of residence, you may have additional rights — to confirm whether we process your personal information, to request access or deletion, to correct inaccuracies, to opt out of “sale” or “sharing” (note: we do not sell or share personal information for cross-context behavioral advertising), and to appeal a denied request where required by law. To exercise these rights, contact support@unveil.shopping and tell us which state law you’re invoking so we can route the request appropriately. We will not discriminate against you for exercising these rights.
1.11 International Processing
Your information may be processed in countries other than where you reside, including where our service providers operate. Those countries may have different data-protection laws. Where required, we take reasonable steps to require appropriate safeguards, though no transfer mechanism eliminates all risk.
1.12 Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction — including keeping our AI credentials server-side and transmitting data over encrypted connections. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for the security of your own device and browser profile.
1.13 Children’s Privacy
Unveil is not directed to children under 13, and we do not knowingly collect their personal information. If local law sets a different age threshold for digital consent, that threshold applies. If you believe a child has provided information, contact us and we will take appropriate steps.
1.14 Changes to This Policy
We may update this policy from time to time. For material changes we will update the effective date and may notify users via the extension or our website. Continued use after the revised policy becomes effective means you acknowledge it.
1.15 Contact
Unveil Shopping, a sole proprietorship operated by Ki Chung
971 US Highway 202N #7298, Branchburg, NJ 08876, USA
support@unveil.shopping
Chrome Web Store Limited Use disclosure (required statement): “The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.”