Chrome Extension Privacy Policy
The extension keeps to itself.
This policy covers the eZacto extension for Chrome, made by CONFLICT LLC. It is separate from the privacy policy for the mobile app and the privacy policy for the ezacto.com website. The short version: the extension sends nothing to us, keeps what it needs in your own browser profile, and talks only to the eZacto instance you sign in to.
What the extension collects
We collect nothing. There is no eZacto account behind this extension and no server of ours in the middle. It contains no advertising SDKs, no analytics, and no usage trackers. We cannot see your time entries, the sites you visit, or that you installed it.
What it stores in your browser
Two things, in chrome.storage.local, which belongs to
your Chrome profile on that computer and is not synced to other
devices:
- The address of the eZacto instance you signed in to.
- The API token you issued in that instance, and your user id on it.
No password ever enters the extension. The token is one you created in your instance under Settings, it is limited to reading and writing time entries and reading projects, and you can revoke it there at any time, which stops the extension immediately.
Why it asks for each permission
- Storage keeps the instance address and token described above.
- Alarms repaints the toolbar badge once a minute so the running timer stays current.
- Active tab reads the title and address of the tab you are on, and only at the moment you click the eZacto button, so it can name a time entry after the page or issue you are working on. That text goes into the time entry you create and travels only to your instance. It is never sent to us and never stored anywhere else.
- Access to one site is requested when you sign in, for the single address of your eZacto instance. Chrome shows you that address before granting it. The extension asks for nothing at install time.
The extension declares no access to any third-party site. It has no permission for GitHub, Jira, Asana, Trello, ClickUp, Basecamp or anywhere else, and it runs no code inside the pages you visit.
The instance you connect to
Everything the extension shows is read live from your eZacto instance, and everything you start, stop or log is written to it. That instance is run by you or by your organisation, and its own privacy practices govern the data in it. If you use the public demo instance, treat it as public: it is rebuilt from invented data every night.
Children
The extension is a tool for work and is not directed at children under 13, and we do not knowingly collect data from them. We do not collect data from anyone.
Security
The extension will only connect to an instance served over HTTPS. The token is stored by Chrome in your profile, with the protections Chrome gives extension storage. Anyone with access to your unlocked computer profile could use it, which is the same exposure as staying signed in to the web app, and is why the token is revocable.
Deleting your data
Signing out inside the extension erases the stored address and token. Uninstalling it removes its storage entirely. Neither reaches your time entries, which live in your instance: delete those there. To be certain a token can never be used again, revoke it in your instance under Settings.
Changes and contact
If this policy changes in a way that matters, the updated date above changes with it and the new version is published here before the change ships. Questions about this policy, or about what the extension does, go to privacy@ezacto.com.