Privacy

Privacy Policy

Last updated: August 4, 2026

miroodum is a browser extension for organizing links saved by the user. Its core features run locally in the browser. miroodum does not operate a developer-owned analytics, advertising, account, AI inference, or remote synchronization server.

Data miroodum handles

  • Chrome bookmarks and Reading List entries, including titles, URLs, folders, and dates
  • URLs and titles explicitly saved through miroodum
  • User-created notes, tags, lifecycle states, and local open counts
  • Optional encrypted Secret vault records and the password used to unlock them
  • Local AI analysis, queue status, and non-identifying performance diagnostics
  • Local safety recovery points created before cleanup, link-check updates, permanent deletion, or source moves
  • Extension settings and user-selected import or export files

miroodum does not read Chrome browsing history, page bodies, form data, cookies, personal communications, or account credentials.

How data is used

Data is used to display, search, sort, tag, deduplicate, move, back up, restore, and delete saved links. Optional browser-managed on-device AI can suggest tags and lifecycle information or answer questions using a limited set of public saved-link metadata. Secret vault and trash records are excluded from AI chat.

Storage and encryption

Public link metadata is stored in Chrome local extension storage. A small allowlist of UI preferences can use Chrome Sync only when the user explicitly enables that option. Link data, notes, tags, AI records, and Secret vault settings are not placed in the settings-sync object.

Secret vault URLs, titles, notes, and tags are encrypted at rest with WebCrypto AES-GCM and remain encrypted inside safety recovery points. Public recovery copies have the same local-storage protection as other public miroodum data and are not sent to Chrome Sync or a remote server.

If the user connects a Documents folder, miroodum also writes backup-compatible JSON below miroodum/SafetyBackups. Public records in those files are readable; Secret records remain encrypted. A forgotten Secret vault password cannot be recovered. User-requested plaintext exports are no longer encrypted and must be protected by the user.

Network activity and sharing

miroodum does not send saved links or user content to a miroodum or developer server.

  • Link Check sends direct HEAD or GET requests only to selected addresses after the user starts it and grants site access. Those sites may receive ordinary request metadata.
  • Optional AI and translation use browser-managed on-device APIs. miroodum does not operate the browser vendor's model infrastructure.
  • Chrome Sync receives only disclosed allowlisted UI preferences when the user enables settings sync.
  • Import and export happen only with files selected or created by the user.

miroodum does not sell user data, use it for advertising or credit decisions, or allow the developer or other humans to read it.

Retention and deletion

Data remains in the browser profile until the user edits or deletes it, restores a backup over it, clears extension data, or uninstalls the extension. Public deleted items may remain in local trash under the selected manual, 7-day, or 30-day policy. Secret items are deleted from the active vault immediately without trash.

Verified safety recovery points expire after 7 days during idle maintenance. If a Documents folder is connected and write permission remains granted, its matching file is deleted at the same time. Points with excess item loss, partial failure, or interrupted verification do not expire automatically and remain until the user restores or deletes them. Disconnecting the folder leaves existing files for the user to manage manually. If a required point cannot be stored or a connected recovery folder cannot be written, the risky operation is blocked.

Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. miroodum uses user data only to provide or improve its disclosed single purpose.

Changes and contact

Material changes to data handling will be disclosed in the extension before the changed practice begins, and this policy will be updated. Submit support requests through the public support page.