security Privacy & Security

Privacy Policy

Effective date: August 1, 2026

verified_user

Extension data stays local by default

CookieSwapper saves and switches website sessions on the user's device. Saved sessions are not synchronized to a CookieSwapper account or cloud service.

1. Overview

CookieSwapper is a Chrome extension for saving and switching website sessions on the user's device. This policy explains what data the extension handles and why.

2. Data handled by the extension

When the user saves a session, CookieSwapper stores cookies and their browser attributes for the selected website; localStorage and sessionStorage key-value data for the selected origin; the website hostname and origin, a user-provided session label, and timestamps; and extension preferences such as language, theme, save mode, and onboarding state.

This information can contain authentication tokens and other sensitive account data. CookieSwapper handles it only to save, identify, restore, export, import, or delete sessions at the user's request.

3. Local storage and retention

Saved sessions are stored locally in the user's Chrome profile using IndexedDB, with chrome.storage.local as a recovery copy. Short-lived restoration payloads are stored in chrome.storage.session and are removed after delivery or when they expire. CookieSwapper does not synchronize saved sessions to a CookieSwapper account or cloud service.

Saved sessions remain until the user deletes them, clears the extension's data, or uninstalls the extension. Exported backups are created only at the user's request and are controlled by the user after download.

4. Site issue reports

CookieSwapper makes no network request for analytics, advertising, or tracking. When the user explicitly submits a site issue, the extension sends only the current website hostname and the optional note entered in the report form to the CookieSwapper report service over HTTPS. Session cookies, storage snapshots, and saved-session labels are not included in that report.

The report service stores submitted hostnames, notes, and submission timestamps until they are manually deleted by the CookieSwapper operator. The service is protected and delivered through Cloudflare, which may process standard connection and security metadata such as the IP address, user agent, and request timestamp. This metadata is not added to saved CookieSwapper sessions.

5. Sharing and sale of data

CookieSwapper does not sell personal or sensitive data. It does not share session data with advertisers, data brokers, analytics providers, or unrelated third parties. A site issue report is transmitted only to the report service used to receive and investigate that user-requested report and to Cloudflare as the infrastructure provider securing that transmission.

6. Limited Use compliance

CookieSwapper's use of information received from Chrome and Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide or improve CookieSwapper's disclosed session management purpose. It is not used for advertising, credit decisions, unrelated profiling, or sale. Humans cannot read saved session data because it is not sent to CookieSwapper. A person may read only the hostname and note that a user explicitly chooses to submit for support through the site issue report.

7. Permissions

CookieSwapper requests access to cookies, storage, browsing data, scripting, and websites the user visits. These permissions are used to detect the current site; capture, clear, and restore its session data; navigate or reload the selected tab; and keep local session backups reliable. Incognito use is disabled.

8. Security and user choices

CookieSwapper limits restoration payloads to the tab that requested them and does not load remote executable code. Users can delete individual sessions, clear the extension's data through Chrome, or uninstall the extension at any time. Exported backup files contain sensitive account data and should be protected like passwords.

9. Changes and contact

Material changes to this policy will be reflected in this document with an updated effective date. Questions, privacy requests, and requests to delete a submitted site issue report can be sent to [email protected].