Privacy policy for Text Expander — SnippetForge
Text Expander — SnippetForge by Sapir
SnippetForge Privacy Policy
Last updated: August 21, 2026
The short version
SnippetForge runs entirely in your browser. Your snippets and everything you type stay on your machine. We collect no browsing data, no analytics, and no telemetry of any kind.
About keystrokes — the honest explanation
A text expander has to watch what you type. There is no way around that, so here is exactly what happens, and you can verify all of it in the extension's source code.
When you type in a text field, SnippetForge keeps a rolling buffer of only the last few characters — specifically, exactly as many characters as your longest snippet trigger. If your longest trigger is ;addr (5 characters), the extension holds at most the last 5 characters you typed in that field. It holds them only to check whether you just typed a trigger.
That buffer:
Lives only in memory, never written to disk, never persisted between page loads
Is discarded the moment a snippet expands, you click elsewhere, you move the caret with the arrow keys, Home or End, or you leave the field
Is kept separately per text field, and disappears when the page does
Is never transmitted anywhere — the extension's content script makes no network requests at all
Password fields are never touched. SnippetForge only activates in ordinary text inputs, search boxes, URL, telephone and email fields, textareas, and rich-text editors. Any input of type password is explicitly excluded, and no buffer is ever created for it.
What the extension stores
Your snippets (triggers and their expansion text), your settings, and your license status are stored locally in your browser using chrome.storage.local. They are never transmitted to us or anyone else. A count of expansions in your current browser session is kept in chrome.storage.session and disappears when you close the browser.
Clipboard access
Clipboard read is an optional permission — it is not requested when you install the extension. SnippetForge asks for it only if you are a Pro user and you save (or activate a license already holding) a snippet that uses the {clipboard} placeholder, which pastes your current clipboard contents into a snippet as it expands. If you decline, everything keeps working; {clipboard} just inserts literally.
Your clipboard is read only at the moment a snippet containing {clipboard} actually expands — not in the background, not continuously, and not at all unless you have granted the optional permission and have a snippet that uses it. The value is inserted into the text field you are typing in and is never stored or sent anywhere. You can revoke the permission at any time in your browser's add-on settings.
The only network request we ever make
If you choose to activate Pro, the extension sends your license key — once, when you click "Activate" in Settings — to Lemon Squeezy (our payment provider, lemonsqueezy.com) to verify it. This is the only outbound network request the extension makes, it happens only at your explicit action, and it never happens from the part of the extension that watches your typing. Your email address, if returned by Lemon Squeezy during validation, is stored locally to display your license status. The request goes to exactly one address, https://api.lemonsqueezy.com/v1/licenses/validate, and contains exactly one thing: the licence key you pasted. No page data, no identifiers, nothing about what you were doing. You can confirm this by searching the extension's source for fetch( — there is a single occurrence, in common.js.
What we never do
No logging, storing, or transmitting of what you type — beyond the few-character in-memory buffer described above
No reading of page content, form data, or anything you haven't typed as a trigger
No activity in password fields, ever
No browsing history collection
No analytics or usage tracking
No advertising or third-party trackers
No remotely hosted code — every line ships in the extension package and is reviewed by the add-on store you installed it from
No sale or sharing of any data, ever
Permissions
We want to be straightforward about this, because SnippetForge asks for more access than our other extensions do — and it should, because it does a fundamentally different job.
Access to all websites — a text expander has to work in every text field you use, so its script runs on every page. Firefox describes this as reading and changing data on all sites. What the script actually does is narrow: watch for your triggers in editable fields, and insert your own snippet text when one matches. It does not read page content, scrape data, or communicate with anything.
Clipboard read (optional) — not requested at install; asked for only when a Pro user first uses the {clipboard} placeholder, and used only at the moment of expansion. See above.
Storage — saves your snippets, settings and license status locally.
If broad page access is not something you're comfortable granting, that is a completely reasonable position — and our other extensions (Full Page Screenshot and HeaderForge) are built to avoid it. A text expander genuinely cannot be.
Contact
Questions: sapirsoftware@gmail.com
The current version of this policy is always at https://sapirsoftware.github.io/snippetforge-privacy.html