legal
Privacy Policy
Effective Date: July 25, 2026
Applies To: The Stenn Chrome Extension, version 0.7.0 and all subsequent versions (the "Extension")
1. Introduction
This Privacy Policy ("Policy") is issued by the developers of the Extension, operating as Cali Agency ("we," "us," "our," or the "Company"), and governs the collection, use, storage, and disclosure of information obtained from users of the Extension ("User," "you," or "your"). By installing, accessing, or using the Extension, you acknowledge that you have read and understood this Policy and consent to the data practices described herein.
This Policy is drafted to comply with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, the "DPA") and its Implementing Rules and Regulations, and to conform with the Google Chrome Web Store Developer Program Policies. Where a User is located in a jurisdiction with additional or differing statutory protections, nothing in this Policy shall be construed to limit those statutory rights.
2. Definitions
For purposes of this Policy:
- "Personal Data" means any information, whether recorded in material form or not, from which the identity of a User is apparent or can be reasonably and directly ascertained.
- "Processing" means any operation performed upon Personal Data, including collection, storage, use, transmission, and disclosure.
- "Snippet" means a User-defined shortcut and its associated expansion text, stored by the User within the Extension.
- "Workspace" means a shared collection of Snippets accessible to multiple Users under a common workspace identifier.
- "Vault" means the optional client-side encryption feature described in Section 4.2.
- "Sub-processor" means a third-party service engaged by the Company to Process Personal Data on the Company's behalf.
3. Scope of This Policy
This Policy describes the Company's data practices as implemented in the Extension as of the Effective Date. It applies exclusively to data Processed through the Extension and its associated backend infrastructure. It does not apply to third-party websites, services, or extensions that a User may access while the Extension is installed, including any Sub-processor's own service accessed independently of the Extension.
4. Information We Collect
The Company collects only the categories of Personal Data reasonably necessary to provide the Extension's functionality, as follows.
4.1 Account and Authentication Data
Authentication is performed via Google OAuth (using the chrome.identity.launchWebAuthFlow API), the output of which is exchanged for a session issued by the Company's backend authentication provider, Supabase. In the course of this process, the Company receives the User's Google account email address and such identifiers as are required by the authentication provider. Session credentials are held by the authentication provider and cached locally within the User's browser; the Company does not separately retain unencrypted session credentials.
4.2 Snippet Data
The Company collects the shortcut text and expansion text comprising each Snippet, together with any site-scoping metadata or Workspace association designated by the User.
- (a) Where a User has not enabled the Vault (which is disabled by default), Snippet content is stored in plaintext within the Company's database, subject to transport-layer encryption (TLS) and row-level access controls limiting each User's access to their own records. Snippet content stored in this manner is, as a technical matter, capable of being accessed by the Company's infrastructure.
- (b) Where a User has enabled the Vault, Snippet content is encrypted on the User's device using AES-256-GCM prior to transmission. The resulting encryption key is itself wrapped under a key derived from a User-supplied passphrase (via PBKDF2, applying 600,000 iterations) and, separately, under a recovery key disclosed to the User at the time of Vault setup. Neither the passphrase, the recovery key, nor the unwrapped encryption key is transmitted to or retained by the Company. The Company retains only the resulting ciphertext and a non-secret cryptographic salt. Consequently, where the Vault is enabled, the Company has no technical capacity to access Snippet content, and no technical capacity to restore such content in the event a User loses both the passphrase and the recovery key.
4.3 Workspace Data
For any Workspace a User creates or joins, the Company collects the Workspace name, its system-generated join code, and its membership roster.
4.4 Usage Aggregates
The Company collects two categories of aggregate, non-content usage data: (i) a per-day total of Snippet expansions and characters saved, used to support streak and gamification features; and (ii) a running use-count maintained per Snippet. Neither category constitutes a record of Snippet content, nor a per-event log correlating individual expansions with timestamps or the sites on which they occurred.
4.5 Uninstall Feedback
Where a User elects to complete the optional feedback form presented by the Chrome browser upon uninstallation, the Company receives the selected reason, any free-text message voluntarily provided, and an email address if voluntarily supplied for follow-up. Submission of this feedback is not contingent upon, or linked to, an authenticated Company account.
4.6 Technical and Diagnostic Data
As of the Effective Date, the Company does not collect browser, operating system, or device diagnostic data. Should this practice change in a future version of the Extension, this Policy will be amended in advance of such change, consistent with Section 15.
5. Information We Do Not Collect
Notwithstanding Section 4, the Company affirmatively does not collect the following:
- (a) Page content. The Extension's content script inspects only the text immediately preceding the User's cursor within a field the User is actively editing, limited to eighty (80) characters, and solely for the purpose of matching against the User's saved Snippets. No other content on any page is read, stored, or transmitted.
- (b) Keystroke logs. No record of User keystrokes is retained beyond the momentary, transient comparison described in Section 5(a), except insofar as a matched Snippet is expanded into the User's own field.
- (c) Browsing history or activity outside the Extension.
- (d) Data for advertising purposes. The Extension displays no advertisements and shares no data with advertising networks or data brokers.
- (e) Data used for artificial intelligence training or processing. As of the Effective Date, the Extension incorporates no artificial intelligence or third-party large language model integration. Should this change, this Policy will be amended in advance, and any such feature will be enabled only upon the User's affirmative opt-in.
6. Purpose and Legal Basis for Processing
The Company Processes Personal Data described in Section 4 solely for the following purposes: (i) to authenticate Users and provision the Extension's core functionality; (ii) to synchronize Snippet and Workspace data across a User's authenticated sessions and devices; (iii) to operate gamification and usage-aggregate features as described in Section 4.4; (iv) to respond to uninstall feedback and support inquiries; and (v) to maintain the security and integrity of the Extension and its backend infrastructure. The Company's basis for such Processing is the User's consent, given upon installation and continued use of the Extension, and, where applicable, the necessity of Processing to perform the Extension's core function at the User's request.
7. Permissions Requested by the Extension
The Extension requests the following browser permissions, each limited to the stated purpose:
storage— to cache the User's Snippet library locally, enabling instantaneous and offline expansion.identity— to effect Google OAuth authentication as described in Section 4.1.alarms— to schedule periodic background synchronization (at approximately two-minute intervals) and streak-reminder timing.notifications— to display a locally generated streak-reminder notification. Such notifications originate on the User's device and are not transmitted from any server.- Host permission for all URLs — required to enable the content script to detect editable fields and perform Snippet expansion on any site the User visits. Consistent with Section 5(a), this permission is not used to read page content beyond the limited, transient inspection described therein.
- Host permission for the Company's backend domain — to synchronize account, Snippet, and Workspace data as described in Section 4.
8. Sub-processors and Third-Party Disclosures
The Company engages the following Sub-processors, each bound by its own privacy and security terms:
- Supabase — provides database, authentication, and server-side function infrastructure, and Processes Personal Data solely on the Company's behalf and instruction.
- Google — provides OAuth authentication services only, as described in Section 4.1.
- Vercel — hosts the Company's administrative dashboard and the uninstall-feedback intake page referenced in Section 4.5.
- Ko-fi — an optional, User-initiated donation link presented within the Extension. Any interaction a User has with Ko-fi occurs on Ko-fi's own platform, subject to Ko-fi's own privacy policy; the Company does not receive payment or financial information from this interaction.
The Company does not sell, rent, license, or otherwise commercially exploit User Personal Data to or for the benefit of any third party.
9. Administrative Access
Aggregate usage data described in Section 4.4 and uninstall feedback described in Section 4.5 are accessible via an internal administrative dashboard, access to which is restricted to a single designated administrator account. Individual Snippet content is not surfaced within this dashboard.
10. Prohibited Categories of Data
The Extension is a general-purpose text-expansion utility. It is not designed, audited, or certified to Process regulated categories of sensitive data, and Users shall not store the following within a Snippet:
- (a) Customer Proprietary Network Information, as defined under 47 U.S.C. § 222;
- (b) Sensitive Personal Information as defined under the DPA, including but not limited to information concerning race, ethnicity, marital status, health, education, genetic or sexual life, government-issued identification numbers (including SSS, GSIS, PhilHealth, TIN, and passport numbers), and records of legal or administrative proceedings;
- (c) Protected health information within the meaning of the U.S. Health Insurance Portability and Accountability Act ("HIPAA"); and
- (d) Payment card data within the meaning of the Payment Card Industry Data Security Standard ("PCI-DSS").
Snippets associated with a Workspace are, by design, accessible to every member of that Workspace, and not solely to the Snippet's creator; accordingly, the storage of any category of data described in this Section within a Workspace Snippet multiplies the number of persons with access to such data and correspondingly increases the User's and the User's organization's compliance exposure. Users whose organizations are subject to any of the foregoing regulatory frameworks should consult their compliance function prior to using the Extension for any customer- or patient-related purpose. The Company disclaims all liability arising from a User's storage of data in violation of this Section.
11. Data Subject Rights
Consistent with the DPA and generally applicable data protection principles, Users may exercise the following rights with respect to their Personal Data, subject to verification of identity and any applicable statutory limitation:
- (a) Right to be informed — to be informed of the nature, purpose, and extent of Processing, as set forth in this Policy;
- (b) Right of access — to obtain a copy of the Personal Data the Company holds concerning the User;
- (c) Right to rectification — to require correction of inaccurate or incomplete Personal Data;
- (d) Right to erasure or blocking — to request deletion of Personal Data, subject to retention obligations imposed by applicable law or necessary for fraud prevention;
- (e) Right to object — to object to Processing of Personal Data undertaken on a legal basis other than the User's consent; and
- (f) Right to data portability — to obtain, in a structured format, Snippet data the User has provided to the Extension.
A User located in the Philippines who believes their rights under the DPA have been violated may additionally lodge a complaint with the National Privacy Commission. Requests under this Section should be directed to the contact address in Section 16.
12. Data Retention and Deletion
Personal Data described in Section 4 is retained for so long as the User maintains an active account, and thereafter for such period as is reasonably necessary to comply with legal obligations, resolve disputes, and enforce this Policy. Uninstallation of the Extension terminates all future synchronization; a User's local cache is removed upon clearing the browser's local storage for the Extension.
13. Children's Privacy
The Extension is not directed to, and is not knowingly used by, children under the age of thirteen (13). The Company does not knowingly collect Personal Data from any such person. A parent or guardian who believes a child has created an account in violation of this Section should contact the Company using the details in Section 16, and the Company will take reasonable steps to delete the relevant account and associated data.
14. Data Security
The Company implements administrative, technical, and organizational measures reasonably designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, including transport-layer encryption, row-level database access controls, and, for Users who enable the Vault, client-side encryption as described in Section 4.2. No method of electronic storage or transmission is completely secure, and the Company cannot guarantee absolute security.
15. Amendments to This Policy
The Company reserves the right to amend this Policy at its discretion. Amendments take effect upon publication of the revised Policy within the Extension or its associated repository. Material changes, meaning any change that expands the categories of data collected or the purposes for which such data is used, will be disclosed in advance within the Extension's release notes, in addition to being reflected in the revised Policy. Continued use of the Extension following the effective date of an amended Policy constitutes acceptance of the amendment.
16. Contact
Inquiries, Data Subject requests, or notices under this Policy should be directed to team.cali.dev@gmail.com, or through the support channel designated on the Extension's Chrome Web Store listing.
17. Governing Law
This Policy is governed by the laws of the Republic of the Philippines, without regard to conflict-of-law principles, without prejudice to any mandatory consumer or data protection law of a User's own jurisdiction that may additionally apply.