Extension privacy
The Display.dev browser extension reads the active page only after you open the extension on that page.
What the extension reads
The extension reads the rendered content of the active HTTP or HTTPS page so you can select text, preview a capture, and publish it. The capture includes the page origin and path plus its title. It omits the URL query and fragment.
The extension does not run scheduled captures, crawl other tabs, or keep an ongoing browsing history. It does not run on Chrome settings, the Chrome Web Store, or other protected pages.
What is sent to Display.dev
Preview remains in an extension-owned sandbox. The page capture, optional comments, and any specific-recipient email addresses you add are sent to Display.dev only after you choose Publish. Recipient addresses stay in the current page session before publishing and are not written to extension recovery or salvage storage.
The capture removes URL query parameters, HTTP subresources, form and authentication values, authored scripts, frames, and unsupported active content. It can copy pixels from eligible images or video frames already loaded on the page and can embed eligible loaded public WOFF2 font bytes. Canvas content and unsupported visuals become measured placeholders.
The published artifact and comments are available to the audience you select. People whose email addresses you add receive a one-time notification with a link to the artifact. Submitted recipient addresses remain in the artifact's access settings until they are removed or the artifact is deleted. Display.dev retains the artifact and comments until the artifact is deleted under the existing account and retention controls.
What is stored in Chrome
The extension stores your Display.dev OAuth refresh token in extension-only local storage. It stores bounded publish recovery data and unfinished comment text in browser-session storage. Browser-session data clears when Chrome exits.
Disconnecting the extension removes its local OAuth credential and browser-session recovery data. OAuth tokens are never exposed to the page.
Requests to other hosts
Preview or Publish can request a bounded copy of an eligible loaded public WOFF2 font from its original host. The request sends no page credentials or referrer and follows no redirect. The font host can observe your IP address and request time.
A capture can retain query-free public HTTPS resources. Your browser requests those resources from their original hosts when you open Preview, and a viewer's browser requests them when the published artifact is opened. Those hosts can observe the requester's IP address and request time.
How the data is used and shared
Display.dev uses page content, source identity, comments, specific-recipient email addresses, and authentication information only to provide and secure the extension's preview, publishing, sharing, comment, and recovery workflows. This data is not sold, used for advertising, used to determine creditworthiness, or transferred for a purpose unrelated to the extension.
The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
The Display.dev Privacy Policy explains the service's account data, service providers, retention, security, and privacy rights. Contact privacy@display.dev with a privacy question.