NoPaste is a Chrome productivity extension for finding and opening saved work URLs and optionally filling locally stored login fields on Test sites the user authorizes. This policy describes the data handled by the NoPaste extension and the getnopaste.com website.
Passwords and login data stay on your device — never uploaded to NoPaste servers. The extension does not phone home. The v1 release does not send product-usage events or create an analytics identifier.
Extension data processed locally
NoPaste stores workspace names, site names and URLs, tags, optional CSS selectors, usernames, settings, launch counts, recent-use timestamps, and onboarding state in chrome.storage.local. When you capture a window, the extension reads the titles and URLs of the tabs you select to create a local workspace. Omnibox searches use your locally stored data only.
Optional Test-site passwords are available only when you explicitly enable them. Encryption happens inside the NoPaste extension on your device; only ciphertext is written to persistent Chrome storage. Test passwords are stripped from exports and backups. The Extension does not store workspace data in chrome.storage.sync.
Workspace data, URLs, usernames, and Test password plaintext are not uploaded to NoPaste-operated servers.
What we do not collect
- No accounts — no developer-side user database.
- No ads — no injected ads or behavioral ad tracking.
- No external product analytics — v1 sends no usage events and creates no analytics identifier.
- No outbound product telemetry or credential sync — v1 makes no network requests to developer backends for analytics, sync, or license checks.
- No history / cookies / webRequest / bookmarks permissions.
- No credential uploads — passwords stay on this device.
Permissions and optional field fill
NoPaste uses Chrome's storage, tabs, scripting, activeTab, contextMenus, and favicon permissions to save local data, open tabs, provide user-invoked shortcuts, and support optional field fill. No site access is required at installation. Access to HTTP or HTTPS pages is requested per site and remains optional.
When you launch an authorized site, NoPaste may inject its packaged fill script into that page. If site permission is denied or revoked, the page can still open but no fill script is injected. Scripts only access authorized launched tabs for the requested fill workflow.
Sharing and limited use
NoPaste does not sell user data, use it for advertising or credit decisions, or allow people to read private extension data. Data is used only to provide the extension's disclosed single purpose. There is no routine third-party transfer of extension data in the v1 release. Information may be disclosed when legally required or necessary to protect users and the service.
Website data
Our website or hosting provider may receive standard technical information such as IP address, browser type, requested pages, and timestamps. It is used only for security, reliability, and aggregate site performance. The website does not receive data stored by the extension.
Your controls
You can edit or delete saved data in NoPaste, enable or disable optional Test passwords in Settings, revoke individual site permissions in Chrome's extension settings, clear extension storage, or uninstall the extension. You choose when to export or import data. Do not include real credentials in support requests.
Data retention and deletion
Local extension data remains until you delete it, clear browser storage, or uninstall NoPaste. Session-only data is cleared when the browser session ends. You may contact us to request deletion of support correspondence or other personal information we control.
Security
For optional Test-site passwords, encryption happens inside the NoPaste extension on your device, and NoPaste persists only the resulting ciphertext in Chrome storage. No storage or software system is completely secure; keep Chrome and your operating system updated and restrict access to your device.
Children
NoPaste is not directed to children under 13, and we do not knowingly collect children's personal information.
Changes
We may update this policy as NoPaste evolves. Material changes will be reflected on this page with a revised effective date and policy version.
Contact
Questions about privacy can be sent to [email protected]. Do not send real passwords or production credentials in support messages.