Legal

ClipDesk Privacy Policy

Effective date: 2026-06-26. ClipDesk is a local-first Chrome extension, and this public policy explains how local data, optional account features, sync, billing, diagnostics, retention, and user controls work.

Policy overview

Public privacy policy for ClipDesk at https://clipdesk.io/privacy.

Support and privacy contact: clipdesksupport@gmail.com

This page is intended to be publicly accessible without login, Clerk auth, extension installation, or dashboard access.

Summary of data practices

What ClipDesk handles, where it is stored, why it is used, and when it is shared.

Data categoryCollected/handled?Where storedWhy usedShared with whom
Webpage or PDF content selected or captured by the userYes, when the user captures itLocal browser profile storage, including IndexedDB and extension-managed storage; optional ClipDesk backend sync storage only if sync is enabled for the relevant scopeSave research, display clips, search, export, and optional syncNot shared by default; shared with ClipDesk backend services only for user-enabled sync scopes
Clip titles, source URLs, metadata, notes, tags, collections, favorites, saved filtersYesLocal browser profile storage; optional ClipDesk backend sync storage only if the user enables relevant sync scopesOrganize, search, export, restore, and optionally sync the libraryNot shared by default; shared with ClipDesk backend services only for user-enabled sync scopes
Local settings and export preferencesYesLocal browser profile storage; optional backend sync if the user enables settings syncPreserve preferences, defaults, onboarding state, and export behaviorNot shared by default; shared with ClipDesk backend services only for user-enabled sync scopes
Account identity dataYes, only if the user signs inClerk systems and ClipDesk backend account recordsAuthenticate the user and show account-linked featuresClerk and ClipDesk backend services
Device, session, and account connection dataYes, for account-connected featuresLocal extension state, Clerk systems, and ClipDesk backend recordsMaintain sign-in state, entitlement checks, connected-device views, and account securityClerk and ClipDesk backend services
Optional sync dataYes, only if the user enables syncClipDesk backend sync storage plus local queue/stateSynchronize selected scopes across the user's eligible devicesClipDesk backend services and the infrastructure providers used to operate them
Billing and subscription statusYes, for paid plansClipDesk backend billing records and Stripe systemsManage entitlement status, checkout handoff, billing portal access, and subscription stateStripe and ClipDesk backend services
Support requestsYes, if the user contacts supportSupport mailbox and support handling systemsRespond to questions, troubleshoot issues, and process privacy requestsEmail and support providers used to receive the request
Safe diagnosticsYes, if the user copies or submits themLocal browser profile storage until cleared; shared externally only if the user voluntarily sends themTroubleshooting and supportNot shared by default; may be shared with ClipDesk support if the user sends them
Cookies or auth session dataYes, for optional sign-in flowsClerk session systems, browser cookies, and local extension session summariesSign-in, sign-out, session continuity, and account securityClerk and ClipDesk backend services as needed for account exchange
Payment card dataNo, not collected or stored by ClipDeskProcessed on Stripe-hosted pagesComplete payment processing outside the extensionStripe processes payment details on Stripe-hosted pages; ClipDesk does not collect or store card numbers
Analytics, advertising, or tracking dataNo analytics or advertising trackers are included in the current buildNot applicableNot applicableNo analytics provider or ad network is used in the current build

1. Introduction

ClipDesk is a local-first Chrome extension for clipping, organizing, searching, and exporting research from webpages and PDFs.

Developer and support contact: clipdesksupport@gmail.com

ClipDesk is designed so the signed-out local core works on the user's device. Local capture, local library, local notes, local tags, local search, local exports, local settings, and local diagnostics can all work without an account. Optional account, sync, billing, and support features may involve ClipDesk backend services and named third-party providers.

Account features are optional. Local ClipDesk capture, save, search, backup, and export workflows still work without an account. The extension does not silently upload the existing local library after sign-in. Sync is opt-in, off by default, and requires a signed-in Clerk/ClipDesk account plus a backend-confirmed entitlement. Clip content sync requires separate explicit consent.

ClipDesk's use of information received from Chrome extension APIs and Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

3. Data ClipDesk Handles

ClipDesk may handle the following data depending on which features the user chooses to use:

  • User-created research content: clipped webpage text, selected text, PDF text extracted from user-selected text PDFs, clip titles, source URLs, page titles, timestamps, notes, tags, collections, favorites, saved filters, and export metadata.
  • Browser and local extension data: extension settings, onboarding state, local database records, export preferences, local diagnostics summaries, permission state, sync queue state, and local error or status codes.
  • Account data: email address, account ID, profile name or label, authentication state, session status, subscription plan, entitlement status, and connected-device metadata shown by account features.
  • Optional sync data: sync manifests, object metadata, clip metadata, selected sync scopes, cursors, conflict records, and synced clip content only if the user separately enables the relevant clip-content sync scope.
  • Billing data: Stripe customer ID, subscription ID and status, plan or tier, billing interval, price ID, entitlement status, checkout or billing-portal status, and related billing metadata needed to provide paid features. ClipDesk does not collect or store full card numbers, CVC values, or raw card data.
  • Support data: user-submitted support request content, contact email, issue category, safe diagnostic summaries, app version, browser version information, and non-secret technical metadata needed to investigate a report.

4. Local Storage

ClipDesk stores the local library in the user's Chrome or browser profile using browser-managed storage such as IndexedDB and extension storage.

Saved clips, notes, tags, settings, collections, favorites, saved filters, onboarding state, local diagnostics, and export preferences remain on the user's device unless the user takes an action that moves them, such as exporting, copying, enabling sync, requesting support, or using another connected feature.

Uninstalling the extension or clearing browser data may delete local data depending on Chrome or browser behavior.

Users can export or back up data through ClipDesk's local export and backup controls that exist in the current build.

5. Optional Account and Authentication

Users can use the local-first core without signing in.

Signing in is optional for account-based features such as entitlement display, connected-device views, billing status, cloud deletion requests, and sync eligibility.

ClipDesk uses Clerk for authentication and account identity. Clerk may process account identity and session data needed for sign-in, sign-out, and session handling.

Signing in does not automatically upload an existing local library.

Account features may include account profile information, entitlement summaries, connected-device state, billing status, and sync eligibility.

6. Optional Sync

Sync is optional and user-controlled.

Sync is off by default.

Sync requires a signed-in account and backend-confirmed entitlement.

If the user enables sync, ClipDesk may transmit selected data to ClipDesk backend services only for the scopes the user enables. Current sync scope language in this project includes settings, collections, saved filters, clip metadata, and optional clip content.

Clip content sync requires separate explicit confirmation.

Existing local clips are not uploaded automatically on sign-in.

ClipDesk uses HTTPS for backend communications. ClipDesk does not claim end-to-end encryption for synced content in 1.0.0-beta, and this policy does not promise end-to-end encryption unless that is actually implemented and documented separately.

7. Billing and Payments

ClipDesk uses Stripe for checkout, billing portal, subscription management, and payment processing.

Billing is handled by Stripe on Stripe-hosted pages. The extension opens backend-created Stripe Checkout or billing portal URLs in a browser tab. The extension does not store card numbers, CVC values, or other payment form data. The extension does not embed card or payment collection inside the extension UI.

ClipDesk backend services may store Stripe customer IDs, subscription IDs, plan or tier information, billing interval, subscription status, entitlement status, and related billing metadata needed to provide paid features.

8. Support and Diagnostics

Users may voluntarily submit support requests.

Support requests may include contact details, issue descriptions, ClipDesk version information, browser version information, and safe diagnostics.

Safe diagnostics are designed to exclude private clip bodies, note contents, raw PDF text, sanitized HTML bodies, full backup payloads, API keys, tokens, secrets, and payment card data.

If a user manually pastes private content into a support request, ClipDesk may receive what the user voluntarily submits.

9. Data Sharing

ClipDesk shares data only as needed to provide user-requested features, operate the service, process billing, respond to support requests, comply with law, or protect users and service security.

Third-party categories used by ClipDesk include:

  • Clerk: authentication, account identity, and session handling. Shared data may include account identity details, auth state, session identifiers, and related account-connection information needed for sign-in.
  • Stripe: checkout, billing portal, subscription handling, and payment processing. Shared data may include customer, subscription, checkout, and billing metadata. Payment card details are processed by Stripe on Stripe-hosted pages, not stored by ClipDesk.
  • Hosting, backend, and database providers used to operate ClipDesk account, sync, deletion, and billing-support services: shared data may include account records, sync payloads for enabled scopes, billing metadata, and deletion or operational records needed to run those features.
  • Chrome, Google, and browser platform services: extension distribution, browser-managed storage, extension runtime, and Chrome extension APIs used for user-triggered capture and local operation.
  • Email and support providers: if a user emails clipdesksupport@gmail.com or otherwise contacts support, the request may pass through the user's email provider and the providers used to receive and process the support mailbox.

ClipDesk does not sell user data.

ClipDesk does not share clipped research content with advertisers.

ClipDesk does not use user data for unrelated advertising or behavioral ad targeting.

10. Data Retention

Local data remains in the user's browser profile until the user deletes clips, resets ClipDesk data, clears diagnostics, replaces data through import, uninstalls the extension, or clears browser data.

Account and backend records may be retained while the account, subscription, sync, or support relationship exists and afterward as needed for legal, billing, security, fraud-prevention, operational, and compliance purposes.

Synced data, if enabled, remains until the user disables sync, deletes cloud data, deletes the account if that workflow is supported, or requests deletion through available account or support channels.

Billing records may be retained as required for accounting, tax, fraud prevention, legal, and compliance obligations.

11. User Controls

Users can:

  • export, copy, or download clips locally;
  • use local backup export and import controls that exist in the current build;
  • delete individual clips or reset local data;
  • clear local diagnostics;
  • disable sync;
  • request cloud data deletion for backend-stored sync data where supported;
  • manage billing through Stripe-hosted billing controls where supported;
  • contact support for privacy, access, export, or deletion requests; and
  • uninstall the extension or clear browser data through browser-level controls.

Cloud deletion does not automatically delete local data.

12. Security

ClipDesk uses HTTPS for backend communications.

The extension is designed so secret keys are not stored in source code or client bundles shipped to users.

Payment details are handled by Stripe-hosted pages rather than inside the extension UI.

Diagnostics are designed to exclude private content and secrets.

No method of storage, software, or transmission is absolutely secure, and ClipDesk does not promise absolute security.

13. Extension Permission Mapping

ClipDesk's privacy behavior is tied to the extension permissions declared in manifest.json:

  • activeTab: used so ClipDesk can read the current user-focused page only when the user triggers capture.
  • contextMenus: used for explicit right-click capture actions.
  • cookies: used for optional Clerk Chrome extension authentication flows and session continuity.
  • scripting: used to inject the packaged capture code into the page at user request.
  • storage: used for local settings, session-safe state, diagnostics summaries, and local data coordination.
  • sidePanel: used because the primary ClipDesk UI runs in the Chrome side panel.
  • host_permissions: production host permissions are limited to https://clipdesk.io/* and https://clerk.clipdesk.io/* for account-connected website and auth flows.
  • optional_host_permissions: http://*/* and https://*/* are optional so ClipDesk can capture user-selected webpages and PDFs across arbitrary sites only after the user grants site access.
  • externally_connectable: limited to https://clipdesk.io/* and https://www.clipdesk.io/* so the ClipDesk website can complete approved account-connection flows.

ClipDesk does not request Chrome identity or identity.email in the current build.

14. Children

ClipDesk is not intended for children under 13 or for users below the minimum age required in their jurisdiction. ClipDesk does not knowingly collect children's personal information. If a parent or guardian believes a child provided personal information, they can contact clipdesksupport@gmail.com.

15. International Users

Data may be processed in the United States or other countries where ClipDesk or its service providers operate.

Depending on the user's location, the user may have rights such as access, correction, export, deletion, or objection or restriction rights. Users can contact support to make a request, and ClipDesk will review the request in light of applicable law and technical or legal obligations.

16. Changes to This Policy

ClipDesk may update this policy from time to time. When material updates are made, the effective date will be changed. Users should review this policy when the extension or connected services change.

17. Contact

For support, privacy, export, deletion, or data-handling questions, contact clipdesksupport@gmail.com.