ClipDesk Privacy Policy
Effective date: 2026-06-26. ClipDesk is a local-first Chrome extension, and this public policy explains how local data, optional account features, sync, billing, diagnostics, retention, and user controls work.
Policy overview
Public privacy policy for ClipDesk at https://clipdesk.io/privacy.
Support and privacy contact: clipdesksupport@gmail.com
This page is intended to be publicly accessible without login, Clerk auth, extension installation, or dashboard access.
Summary of data practices
What ClipDesk handles, where it is stored, why it is used, and when it is shared.
| Data category | Collected/handled? | Where stored | Why used | Shared with whom |
|---|---|---|---|---|
| Webpage or PDF content selected or captured by the user | Yes, when the user captures it | Local browser profile storage, including IndexedDB and extension-managed storage; optional ClipDesk backend sync storage only if sync is enabled for the relevant scope | Save research, display clips, search, export, and optional sync | Not shared by default; shared with ClipDesk backend services only for user-enabled sync scopes |
| Clip titles, source URLs, metadata, notes, tags, collections, favorites, saved filters | Yes | Local browser profile storage; optional ClipDesk backend sync storage only if the user enables relevant sync scopes | Organize, search, export, restore, and optionally sync the library | Not shared by default; shared with ClipDesk backend services only for user-enabled sync scopes |
| Local settings and export preferences | Yes | Local browser profile storage; optional backend sync if the user enables settings sync | Preserve preferences, defaults, onboarding state, and export behavior | Not shared by default; shared with ClipDesk backend services only for user-enabled sync scopes |
| Account identity data | Yes, only if the user signs in | Clerk systems and ClipDesk backend account records | Authenticate the user and show account-linked features | Clerk and ClipDesk backend services |
| Device, session, and account connection data | Yes, for account-connected features | Local extension state, Clerk systems, and ClipDesk backend records | Maintain sign-in state, entitlement checks, connected-device views, and account security | Clerk and ClipDesk backend services |
| Optional sync data | Yes, only if the user enables sync | ClipDesk backend sync storage plus local queue/state | Synchronize selected scopes across the user's eligible devices | ClipDesk backend services and the infrastructure providers used to operate them |
| Billing and subscription status | Yes, for paid plans | ClipDesk backend billing records and Stripe systems | Manage entitlement status, checkout handoff, billing portal access, and subscription state | Stripe and ClipDesk backend services |
| Support requests | Yes, if the user contacts support | Support mailbox and support handling systems | Respond to questions, troubleshoot issues, and process privacy requests | Email and support providers used to receive the request |
| Safe diagnostics | Yes, if the user copies or submits them | Local browser profile storage until cleared; shared externally only if the user voluntarily sends them | Troubleshooting and support | Not shared by default; may be shared with ClipDesk support if the user sends them |
| Cookies or auth session data | Yes, for optional sign-in flows | Clerk session systems, browser cookies, and local extension session summaries | Sign-in, sign-out, session continuity, and account security | Clerk and ClipDesk backend services as needed for account exchange |
| Payment card data | No, not collected or stored by ClipDesk | Processed on Stripe-hosted pages | Complete payment processing outside the extension | Stripe processes payment details on Stripe-hosted pages; ClipDesk does not collect or store card numbers |
| Analytics, advertising, or tracking data | No analytics or advertising trackers are included in the current build | Not applicable | Not applicable | No analytics provider or ad network is used in the current build |
1. Introduction
ClipDesk is a local-first Chrome extension for clipping, organizing, searching, and exporting research from webpages and PDFs.
Developer and support contact: clipdesksupport@gmail.com
ClipDesk is designed so the signed-out local core works on the user's device. Local capture, local library, local notes, local tags, local search, local exports, local settings, and local diagnostics can all work without an account. Optional account, sync, billing, and support features may involve ClipDesk backend services and named third-party providers.
Account features are optional. Local ClipDesk capture, save, search, backup, and export workflows still work without an account. The extension does not silently upload the existing local library after sign-in. Sync is opt-in, off by default, and requires a signed-in Clerk/ClipDesk account plus a backend-confirmed entitlement. Clip content sync requires separate explicit consent.
ClipDesk's use of information received from Chrome extension APIs and Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
3. Data ClipDesk Handles
ClipDesk may handle the following data depending on which features the user chooses to use:
- User-created research content: clipped webpage text, selected text, PDF text extracted from user-selected text PDFs, clip titles, source URLs, page titles, timestamps, notes, tags, collections, favorites, saved filters, and export metadata.
- Browser and local extension data: extension settings, onboarding state, local database records, export preferences, local diagnostics summaries, permission state, sync queue state, and local error or status codes.
- Account data: email address, account ID, profile name or label, authentication state, session status, subscription plan, entitlement status, and connected-device metadata shown by account features.
- Optional sync data: sync manifests, object metadata, clip metadata, selected sync scopes, cursors, conflict records, and synced clip content only if the user separately enables the relevant clip-content sync scope.
- Billing data: Stripe customer ID, subscription ID and status, plan or tier, billing interval, price ID, entitlement status, checkout or billing-portal status, and related billing metadata needed to provide paid features. ClipDesk does not collect or store full card numbers, CVC values, or raw card data.
- Support data: user-submitted support request content, contact email, issue category, safe diagnostic summaries, app version, browser version information, and non-secret technical metadata needed to investigate a report.
4. Local Storage
ClipDesk stores the local library in the user's Chrome or browser profile using browser-managed storage such as IndexedDB and extension storage.
Saved clips, notes, tags, settings, collections, favorites, saved filters, onboarding state, local diagnostics, and export preferences remain on the user's device unless the user takes an action that moves them, such as exporting, copying, enabling sync, requesting support, or using another connected feature.
Uninstalling the extension or clearing browser data may delete local data depending on Chrome or browser behavior.
Users can export or back up data through ClipDesk's local export and backup controls that exist in the current build.
5. Optional Account and Authentication
Users can use the local-first core without signing in.
Signing in is optional for account-based features such as entitlement display, connected-device views, billing status, cloud deletion requests, and sync eligibility.
ClipDesk uses Clerk for authentication and account identity. Clerk may process account identity and session data needed for sign-in, sign-out, and session handling.
Signing in does not automatically upload an existing local library.
Account features may include account profile information, entitlement summaries, connected-device state, billing status, and sync eligibility.
6. Optional Sync
Sync is optional and user-controlled.
Sync is off by default.
Sync requires a signed-in account and backend-confirmed entitlement.
If the user enables sync, ClipDesk may transmit selected data to ClipDesk backend services only for the scopes the user enables. Current sync scope language in this project includes settings, collections, saved filters, clip metadata, and optional clip content.
Clip content sync requires separate explicit confirmation.
Existing local clips are not uploaded automatically on sign-in.
ClipDesk uses HTTPS for backend communications. ClipDesk does not claim end-to-end encryption for synced content in 1.0.0-beta, and this policy does not promise end-to-end encryption unless that is actually implemented and documented separately.
7. Billing and Payments
ClipDesk uses Stripe for checkout, billing portal, subscription management, and payment processing.
Billing is handled by Stripe on Stripe-hosted pages. The extension opens backend-created Stripe Checkout or billing portal URLs in a browser tab. The extension does not store card numbers, CVC values, or other payment form data. The extension does not embed card or payment collection inside the extension UI.
ClipDesk backend services may store Stripe customer IDs, subscription IDs, plan or tier information, billing interval, subscription status, entitlement status, and related billing metadata needed to provide paid features.
8. Support and Diagnostics
Users may voluntarily submit support requests.
Support requests may include contact details, issue descriptions, ClipDesk version information, browser version information, and safe diagnostics.
Safe diagnostics are designed to exclude private clip bodies, note contents, raw PDF text, sanitized HTML bodies, full backup payloads, API keys, tokens, secrets, and payment card data.
If a user manually pastes private content into a support request, ClipDesk may receive what the user voluntarily submits.
9. Data Sharing
ClipDesk shares data only as needed to provide user-requested features, operate the service, process billing, respond to support requests, comply with law, or protect users and service security.
Third-party categories used by ClipDesk include:
- Clerk: authentication, account identity, and session handling. Shared data may include account identity details, auth state, session identifiers, and related account-connection information needed for sign-in.
- Stripe: checkout, billing portal, subscription handling, and payment processing. Shared data may include customer, subscription, checkout, and billing metadata. Payment card details are processed by Stripe on Stripe-hosted pages, not stored by ClipDesk.
- Hosting, backend, and database providers used to operate ClipDesk account, sync, deletion, and billing-support services: shared data may include account records, sync payloads for enabled scopes, billing metadata, and deletion or operational records needed to run those features.
- Chrome, Google, and browser platform services: extension distribution, browser-managed storage, extension runtime, and Chrome extension APIs used for user-triggered capture and local operation.
- Email and support providers: if a user emails clipdesksupport@gmail.com or otherwise contacts support, the request may pass through the user's email provider and the providers used to receive and process the support mailbox.
ClipDesk does not sell user data.
ClipDesk does not share clipped research content with advertisers.
ClipDesk does not use user data for unrelated advertising or behavioral ad targeting.
10. Data Retention
Local data remains in the user's browser profile until the user deletes clips, resets ClipDesk data, clears diagnostics, replaces data through import, uninstalls the extension, or clears browser data.
Account and backend records may be retained while the account, subscription, sync, or support relationship exists and afterward as needed for legal, billing, security, fraud-prevention, operational, and compliance purposes.
Synced data, if enabled, remains until the user disables sync, deletes cloud data, deletes the account if that workflow is supported, or requests deletion through available account or support channels.
Billing records may be retained as required for accounting, tax, fraud prevention, legal, and compliance obligations.
11. User Controls
Users can:
- export, copy, or download clips locally;
- use local backup export and import controls that exist in the current build;
- delete individual clips or reset local data;
- clear local diagnostics;
- disable sync;
- request cloud data deletion for backend-stored sync data where supported;
- manage billing through Stripe-hosted billing controls where supported;
- contact support for privacy, access, export, or deletion requests; and
- uninstall the extension or clear browser data through browser-level controls.
Cloud deletion does not automatically delete local data.
12. Security
ClipDesk uses HTTPS for backend communications.
The extension is designed so secret keys are not stored in source code or client bundles shipped to users.
Payment details are handled by Stripe-hosted pages rather than inside the extension UI.
Diagnostics are designed to exclude private content and secrets.
No method of storage, software, or transmission is absolutely secure, and ClipDesk does not promise absolute security.
13. Extension Permission Mapping
ClipDesk's privacy behavior is tied to the extension permissions declared in manifest.json:
- activeTab: used so ClipDesk can read the current user-focused page only when the user triggers capture.
- contextMenus: used for explicit right-click capture actions.
- cookies: used for optional Clerk Chrome extension authentication flows and session continuity.
- scripting: used to inject the packaged capture code into the page at user request.
- storage: used for local settings, session-safe state, diagnostics summaries, and local data coordination.
- sidePanel: used because the primary ClipDesk UI runs in the Chrome side panel.
- host_permissions: production host permissions are limited to https://clipdesk.io/* and https://clerk.clipdesk.io/* for account-connected website and auth flows.
- optional_host_permissions: http://*/* and https://*/* are optional so ClipDesk can capture user-selected webpages and PDFs across arbitrary sites only after the user grants site access.
- externally_connectable: limited to https://clipdesk.io/* and https://www.clipdesk.io/* so the ClipDesk website can complete approved account-connection flows.
ClipDesk does not request Chrome identity or identity.email in the current build.
14. Children
ClipDesk is not intended for children under 13 or for users below the minimum age required in their jurisdiction. ClipDesk does not knowingly collect children's personal information. If a parent or guardian believes a child provided personal information, they can contact clipdesksupport@gmail.com.
15. International Users
Data may be processed in the United States or other countries where ClipDesk or its service providers operate.
Depending on the user's location, the user may have rights such as access, correction, export, deletion, or objection or restriction rights. Users can contact support to make a request, and ClipDesk will review the request in light of applicable law and technical or legal obligations.
16. Changes to This Policy
ClipDesk may update this policy from time to time. When material updates are made, the effective date will be changed. Users should review this policy when the extension or connected services change.
17. Contact
For support, privacy, export, deletion, or data-handling questions, contact clipdesksupport@gmail.com.