Privacy Policy
Last updated: September 25, 2026
Who We Are
Webtracer is a Chrome extension operated by Algomittens LLC ("we", "us", "our"). You can reach us at support@algomittens.com.
Single Purpose
Webtracer's single purpose is to let you monitor specific webpages you choose for visible text changes and notify you when those changes occur. Webtracer does not monitor your general browsing activity. It only accesses webpages that you explicitly add as trackers.
1. What Data We Collect
Webtracer collects only what is necessary to provide the service:
- Account data: Email address and password (hashed before storage) when you create an account.
- Website content: When you add a URL as a tracker, the extension loads that page and extracts the visible text content matching the CSS selector you specify. This extracted text is stored locally on your device in IndexedDB. It reaches our servers only through the Pro features you turn on, described under "Pro feature data" below. The extension only accesses pages you explicitly add as trackers. It does not access, monitor, or record your general browsing activity.
- Tracker configuration: URLs, CSS selectors, tracker names, check intervals, notification rules, notes, and tags you set up.
- Subscription data: If you upgrade to a paid plan, Stripe processes your payment. We store your Stripe customer ID and subscription status, and never your card number or payment details.
- Notification credentials: Discord webhook URLs, Slack webhook URLs, Telegram bot tokens and chat IDs, and custom webhook URLs you configure for change alerts.
- Pro feature data: Only if you turn on the matching Pro feature:
- Status page: for each tracker you mark "Public", we store its tracker name, its latest status (the most recent text extracted from the page, up to 500 characters) and its last-checked time, plus the display name you set for the page. This is updated after each check while the tracker is public.
- Phone push: when you enable push on a device, we store that device's push endpoint and encryption keys, which your browser generates for Web Push.
- Email alerts: the content of email and digest alerts (described in Section 5) passes through our servers to our email provider. We do not store it.
- Usage-limit records: When you use a server feature (email, push, status page, billing or account management), we record your user ID, the action and the time so we can enforce rate limits. If a request is blocked as abusive or exceeds a limit, we also record a short security flag with the same details.
2. How We Use Your Data
Each type of data we collect serves a specific purpose:
- Account data is used to authenticate you, manage your session, and associate your subscription tier with your account.
- Website content is used to detect changes on the pages you monitor. The extension compares newly extracted text against previously stored text to determine if a change occurred.
- Tracker configuration is used to know which pages to check, how often to check them, and how to notify you when changes are detected.
- Subscription data is used to determine which features and limits apply to your account (e.g., number of trackers, history depth).
- Notification credentials are used solely to deliver change alerts to the services you configure. They are stored locally on your device and sent directly from your browser to the respective service when a change is detected.
- Pro feature data is used only to run the feature it belongs to: showing your public status page, delivering push notifications to your devices, and sending your email and digest alerts.
- Usage-limit records are used only to enforce rate limits and to protect the service from abuse.
3. How We Handle Your Data
We take the following measures to handle your data securely:
- Encryption in transit: All data transmitted between the extension and our servers uses HTTPS (TLS 1.2+). No user data is ever sent over unencrypted HTTP connections.
- Password security: Passwords are hashed by Supabase Auth before storage. We never store or transmit plaintext passwords.
- Local-first architecture: Tracker data, change history, notification logs, and settings are stored in your browser's IndexedDB and
chrome.storage.local. Only the items listed under "Pro feature data" and "Usage-limit records" in Section 1 reach our servers. Your tracker list, selectors, change history and settings are not synced or backed up to our servers. - Server-side data: Our servers store account data (email, hashed password), subscription status, usage-limit records, and the Pro feature data listed in Section 1 for the features you turn on: the status page entries for trackers you make public, your status page display name, and the push endpoint and keys of devices you enable for push.
- Public status page: Status page entries and your display name are public. Anyone with the link to your status page can see them. Unmark a tracker as "Public" or delete it, and its entry is removed from the page. To rate-limit anonymous visitors, we keep a salted hash of a visitor's IP address, which is not linked to any account.
- Relayed alerts: Email, digest and push alert content passes through our servers only to be handed to the delivery service. We do not store it.
- Webhook credentials: Discord, Slack, Telegram, and custom webhook URLs/tokens are stored locally in your browser's IndexedDB. When a notification is triggered, your browser sends the alert directly to the configured service. Our servers are not involved in this transmission.
- No analytics or tracking: Webtracer does not include any analytics libraries, telemetry, tracking pixels, or fingerprinting code.
No method of transmission or storage is perfectly secure. While we use reasonable measures to protect your data, we cannot guarantee absolute security.
4. Where Data Is Stored
- On your device: Trackers, extracted page content, change history, notification logs, settings, and webhook credentials are stored locally in your browser's IndexedDB and
chrome.storage.local. - Supabase (US-hosted): Account authentication tokens, email address, hashed password, subscription status, and usage-limit records (user ID, action, time, and any security flag) are stored in our Supabase-hosted PostgreSQL database. If you use the status page, it also stores the tracker name, latest status (up to 500 characters of extracted text) and last-checked time of each tracker you make public, and your display name. If you use phone push, it stores the push endpoint and encryption keys of each device you enable.
- Stripe: Payment method details and billing history are stored by Stripe. We do not have access to your full card number.
5. Who We Share Data With
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. Data is shared only with the following service providers, solely to operate Webtracer:
- Supabase handles account authentication, subscription management, and hosting of the Pro feature data and usage-limit records described in Section 4. Supabase Privacy Policy.
- Stripe handles payment processing for paid plans. Stripe Privacy Policy.
- Resend handles email delivery for change notifications (only if you enable email alerts). When an email alert is sent, Resend receives your email address, the tracker name, monitored URL, previous text, new text, and a timestamp. Digest emails contain your email address and, for each changed tracker, its name, its number of changes and its latest new text. Resend Privacy Policy.
- Your browser's push service (for example, Google's for Chrome) delivers phone push notifications (only if you enable push). Our servers send each alert to the push endpoint your browser registered. Change alerts contain the tracker name, the previous and new text, and the monitored page URL. Digest pushes contain only the number of changes and trackers and a link to webtracer.app.
When you configure third-party notification channels, change alerts are sent directly from your browser to:
- Discord, via your webhook URL. Discord Privacy Policy.
- Slack, via your webhook URL. Slack Privacy Policy.
- Telegram, via the Telegram Bot API. Telegram Privacy Policy.
- Custom webhooks, via any URL you provide. You are responsible for the privacy practices of custom webhook endpoints.
Notification payloads contain: tracker name, monitored URL, previous text, new text, and a timestamp. No account credentials or personal information beyond what is needed for the alert is included.
6. Host Permissions
Webtracer requests the <all_urls> host permission and the scripting permission because users can monitor any webpage of their choice. These permissions are used exclusively to:
- Open the specific URLs you add as trackers in a background tab.
- Inject a content script that extracts the visible text of the CSS selector you specified.
- Close the tab immediately after extraction.
Webtracer does not use host permissions to access, read, or monitor any page you have not explicitly added as a tracker.
7. Web Browsing Activity
Webtracer does not collect or use your web browsing activity except as necessary to provide its single purpose of monitoring the specific URLs you choose. Any browsing-related information handled by Webtracer is limited to the pages you explicitly configure for monitoring and is used only to provide the monitoring and notification features you requested. Webtracer does not collect your browsing history, track which websites you visit, or read content from your open tabs. The extracted text is stored in your browser's local IndexedDB. It reaches our servers only through the Pro features you turn on: the latest status of a tracker you make public on your status page, and the content of email, digest and push alerts, which is relayed and not stored (see Sections 1 and 5).
8. What We Don't Collect
- Browsing history or activity outside of URLs you explicitly add as trackers
- Cookies, form data, or login credentials from monitored pages
- Personal files, device identifiers, or hardware information
- Analytics, telemetry, advertising IDs, or tracking pixels
- Full credit card numbers (payment details are handled entirely by Stripe)
- Full HTML or DOM structure of monitored pages (only visible text from your specified selector)
9. Data Retention
- Local data (trackers, history, notifications, settings) is retained on your device until you delete it or uninstall the extension.
- Account data (email, hashed password, subscription status) and usage-limit records are retained on our servers until you delete your account.
- Status page entries are kept while the tracker is public and removed when you unmark or delete it. Your display name and push endpoints are kept until you delete your account. Status page entries, your display name and push endpoints are also removed when your Pro subscription ends, and a push endpoint is removed when the push service reports that it no longer exists.
- Email, digest and push alert content is not stored on our servers.
- Payment records are retained by Stripe per their retention policy.
10. Data Deletion
You can delete your data at any time:
- Local data: Uninstall the extension or clear your browser's site data for the extension.
- Individual trackers: Delete trackers from the dashboard to remove their stored content and history.
- Account and server-side data. Delete your account from Account (the person icon in the header). This removes your account, subscription record, status page entries and display name, push endpoints, and usage-limit records from our servers.
- Full deletion request: Email support@algomittens.com to request complete deletion of all data associated with your account.
11. Your Rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Export your data (use the Export feature in Settings)
- Object to or restrict processing of your data
- Withdraw consent at any time by deleting your account
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email support@algomittens.com.
12. Children's Privacy
Webtracer is not intended for use by anyone under the age of 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will promptly delete it.
13. Cookies
Webtracer does not use cookies. Authentication tokens are stored in chrome.storage.local, which is accessible only to the extension.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Continued use of Webtracer after changes constitutes acceptance of the updated policy.
15. Chrome Web Store User Data Policy Compliance
Webtracer's use of user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements:
- Webtracer only uses data in ways that are necessary to provide and improve the extension's single purpose of monitoring web pages for content changes and notifying you of those changes.
- Webtracer does not transfer user data to third parties except as necessary to provide the service (as described in Section 5), to comply with applicable laws, or to protect against malware, spam, phishing, or other fraud or abuse.
- Webtracer does not use or transfer user data for personalized advertisements.
- Webtracer does not sell user data to third parties, data brokers, or information resellers.
- Webtracer does not use or transfer user data to determine credit-worthiness or for lending purposes.
- No human reads your user data unless (a) you give explicit consent for a specific support request, (b) it is necessary for security purposes such as investigating abuse, or (c) it is required to comply with applicable law.
16. Financial & Authentication Data
Webtracer does not publicly disclose any financial or payment information. Credit card details are handled exclusively by Stripe and are never accessible to us. Authentication credentials (passwords, tokens, session data) are never publicly disclosed, logged in plaintext, or exposed to third parties. Webhook tokens and API keys you configure are stored only in your local browser storage.
17. Contact
Questions, concerns, or data requests? Email support@algomittens.com.