Privacy Policy

Last updated: September 22, 2026

The Short Version

Pocket Pet works without an account. Saved content is stored in your browser and is uploaded to Supabase if you choose to sign in for cloud sync. Chrome can separately sync extension settings. Error reporting is enabled in the extension, including when signed out. Signed-in sync also sends limited activity signals. Pocket Pet does not use saved content for advertising.

Data Stored on Your Device

Local storage holds saved links (titles, URLs, favicons and tags), rich-text notes, reminders, named tab sessions, files and account session credentials when signed in. Recently Deleted keeps recoverable copies of deleted links, notes and named sessions for up to 30 days; expired copies are removed during subsequent recovery operations.

Deliberately chosen per-site pet positions are stored locally without a time or site-count limit, until reset or local extension data is removed. Older positions are migrated from Chrome sync storage without deleting the legacy copy on other devices.

Chrome storage.sync holds preferences, hidden website names and the global default position. These may travel with your Chrome profile if Chrome sync is enabled, independently of a Pocket Pet account. Files, Recently Deleted and new per-site positions are not uploaded by Pocket Pet cloud sync.

Optional Account and Cloud Sync

Google or email sign-in uses Supabase authentication. Account information can include your email, user ID and profile name or avatar supplied by the sign-in provider. Authentication credentials are stored in the browser to keep you signed in.

When you enable cloud sync, links, notes, reminders, named sessions and selected preferences are uploaded to Supabase so the extension and web app can share them. Signing in through the extension's Plus purchase flow does not by itself enable content sync. Preferences include pet choice, name, size, theme, aura and reminder settings. Saved URLs, tab titles and note or reminder contents are part of this data.

Signed-in preference updates include extension version, platform, a count of pet-panel opens and a last-active timestamp. These are activity signals, not a recording of every page you visit. Locally queued edits may upload when connectivity or sign-in resumes.

Optional Plus Purchases

Lemon Squeezy handles checkout, billing details, payment and receipts. Pocket Pet does not receive full card details. Our server sends your account email and a checkout reference to Lemon Squeezy. Purchase records in Supabase link your account ID to checkout and order IDs, product, environment, payment/refund status, amount, currency and processing timestamps. Signed webhook requests verify delivery; a local account-bound ownership cache allows previously verified Plus access during temporary network outages.

Purchase sign-in and checks work separately from content sync. We do not send your links, notes, sessions or reminders to the payment provider. Billing and purchase-support records are retained separately from saved content to handle delivery, disputes and recovery; deleting cloud content does not delete these records. Contact support with your receipt for purchase or account-closure help. A new account does not automatically inherit an old account's purchase.

Page Access and Permissions

The content script runs on supported websites to display the pet. Saving a page captures its title, URL and favicon; a context-menu action can save selected text or an image URL. Visual placement can inspect page geometry and background colors.

The optional tabs permission supports saving open tabs as links or named sessions. After permission is granted, automatic session snapshots can also store open-tab titles and URLs locally; only the most recent three automatic snapshots are retained. Promoting a snapshot to a named session makes it eligible for optional cloud sync.

Storage and unlimitedStorage support saved data and files. activeTab supports current-page actions; contextMenus adds right-click actions; identity supports sign-in. Optional alarms and notifications deliver reminders. The extension does not request Chrome's browsing-history permission.

Diagnostics and Other Network Requests

The extension sends error reports to Sentry by default, even without sign-in. Reports can include error messages, stack traces, filenames or URLs in those traces, timestamps, extension version and the affected extension surface. Error text can contain contextual information. Session replay and performance tracing are not enabled by the extension's reporting code. There is currently no in-extension diagnostics opt-out.

Network providers receive connection metadata needed to handle requests. Google handles Google sign-in and font requests. Favicon requests may go to a saved site's host or Google's favicon service, exposing the requested hostname to that service.

The website uses Vercel Web Analytics for site usage measurement and Sentry where configured for errors. The web app uses Supabase for authentication and saved data. Optional weekly email digests use Resend when enabled. These website services are separate from the extension's local-only mode.

Your Choices and Deletion

You can use the extension without signing in, hide the pet on selected sites, reset a site's position, and revoke optional permissions in Chrome. Signing out stops account sync but does not delete cloud records or disable diagnostics.

Deleting a link, note or named session creates a local recovery copy and queues its cloud deletion when applicable. Restoring creates a new copy; recovery is not synced between devices. Capacity limits are shown instead of silently removing older saved items.

The web app's Delete cloud data action removes synced content and preferences, not your sign-in account or Plus purchase. Copies on devices remain and can sync back, so sign out of the extension before deleting cloud data. Full account closure is a support request from your account email. Removing the extension removes its local data, but does not delete a cloud account or purchase records.

For questions about retained service logs or deletion requests, contact the developer. This policy does not promise that provider backups or operational logs disappear immediately.

Children's Privacy

Pocket Pet is not intended to collect children's personal information. Contact the developer if you believe a child has supplied personal information so it can be reviewed and addressed.

Changes and Contact

This policy describes the current extension and website. We will update the date when it changes. Privacy questions: aniketmishra717@gmail.com, or the contact page at https://getpocketpet.com/contact.html.