Privacy policy for Yasumaro - AI Browsing Logger
Yasumaro - AI Browsing Logger by ar-
Privacy policy for Yasumaro - AI Browsing Logger
URL: https://armaniacs.github.io/yasumaro/PRIVACY.md
Yasumaro ("the Extension") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
The Extension collects the following data locally on your device:
- Browsing history data (URLs, titles, duration, scroll depth, content)
- Configuration data (API keys, connection settings)
- Browsing history data is stored in SQLite DB on OPFS (Origin Private File System) on your device.
- All configuration data is stored in Chrome's local storage on your device.
- Browsing history entries are also saved to your local Obsidian vault.
- Data Retention Policy: By default, browsing history is retained indefinitely (no automatic deletion). You can optionally configure a retention period (30–365 days) and/or a maximum record count (1,000–100,000) in the settings under "History Retention Policy". When either setting is configured, an automatic purge runs every 24 hours.
- Automatic Deletion Mechanism: Non-starred entries older than the configured retention period are physically deleted. If the total count exceeds the configured maximum, the oldest non-starred entries are additionally removed. Starred entries are exempt from automatic deletion. A "Purge now" button is also available for immediate manual purge.
- PII Sanitization: Fetched page content is processed through a PII (Personally Identifiable Information) sanitizer before storage. Email addresses, credit card numbers, phone numbers (Japan, US, China, Korea), My Number (Japan), SSN (US Social Security Numbers), and other PII patterns are automatically masked.
- Migration from older versions: Data migration from older versions is performed against the SQLite DB on OPFS. After migration is complete, data in the old storage is deleted.
- No data is stored on our servers.
Data handling for the
Dashboard → Archive panel:
- Export: An archive file (
yasumaro_archive_<date>.db) is created only by an explicit user action and saved to the browser's download folder. It is a plaintext standard SQLite file with no encryption or signing. Storage, moving, and deletion of the file after export are the user's responsibility. - Deletion from the main database: The phase-2 deletion is cross-checked against the file exported in phase 1, and records added after phase 1 are protected.
- Restore: The archive file selected by the user is merged into the main SQLite DB (duplicates skipped). The file's contents are not sent anywhere.
- Open temporarily: You can open an archive file without importing it, to search and edit titles. Edits are written back only to the selected archive file and do not affect the main DB.
- All archive processing is completed on-device; nothing is sent to our servers.
- Page content: Sent to the AI provider API selected by the user (Google Gemini, OpenAI-compatible APIs, etc.) to generate summaries. The AI provider is the one you choose in the settings; their data usage policy applies. Please review the privacy policy of your chosen provider. If you select browser Built-in AI (Chrome's Gemini Nano / Edge's Phi-mini), inference runs on-device and page content is not sent outside the device.
- Browsing history: Stored in the SQLite DB on OPFS and can be viewed and managed in the extension's Dashboard (SQLite History panel). If you enable Obsidian integration (optional), data is also sent to your Obsidian vault via the Obsidian Local REST API. In that case, data handling is subject to the policies of Obsidian and the Local REST API plugin.
- Settings: Used to connect to Obsidian and the AI provider API.
You can encrypt exported settings files with a master password.
- How to enable: Dashboard → Privacy tab → Enable "Master Password Protection" and set a password
- Encryption: AES-GCM (industry standard) + PBKDF2 key derivation (100,000 iterations)
- Scope: All settings in the exported JSON file, including API keys
- Note: If you forget your password, encrypted export files cannot be decrypted
When you export browsing logs as JSON, the file is HMAC-signed. On import the signature is verified, and unsigned or tampered files are rejected. The signing key is generated locally per browser profile and is never transmitted.
- Scope: JSON-format log export/import
- Note: Log JSON files exported by an older (unsigned) version cannot be re-imported. Re-export them from the latest version if needed
.db-format exports are not affected
On first launch, a consent prompt appears for data collection. If you decline, the extension operates in restricted mode and no recording takes place. After 3 consecutive declines, the prompt is suppressed for 30 days. After 30 days, the consent prompt reappears (GDPR Article 7 "Right to Re-consent" compliance).
Withdrawing Consent: You may withdraw your consent at any time. Withdrawing consent shows a confirmation dialog that makes clear this will also permanently delete your recorded browsing history (SQLite). Because this action cannot be undone, confirmation is required before it is executed.
For regular use (storing API keys within the extension), a separate auto-encryption mechanism is used that requires no user action.
Under normal use, API keys are automatically encrypted before being stored. No master password is required; AES-GCM encryption is applied in the background without any user action.
However, when no master password is set, the encryption key itself is stored in plaintext within
chrome.storage.local. While Chrome extension storage is scoped to the extension and cannot be read directly by other extensions, it is accessible from within this extension. In this state, encryption prevents external read access, but does not prevent access from within the extension itself.Setting a master password changes this behavior: the encryption key is derived from the master password via PBKDF2, providing protection beyond the extension's own storage boundary.
v4.2.1 introduces the following privacy features:
- "Record without AI" Button: Skip AI processing and record directly to Obsidian
- Available when attempting manual recording without page content from the dashboard
- Completely bypasses AI provider data transmission
- All privacy checks (private page detection) still apply
- Automatic Content Fetching (Disabled by Default):
- When page content is empty during manual recording, a background tab opens to fetch content
- This feature is disabled by default (requires explicit opt-in)
- To enable:
- Dashboard → Privacy tab → Enable "Auto Content Fetch"
- Behavior when enabled:
- Background tab loads the page and extracts text (up to 10,000 characters)
- Extracted content may be used for AI summarization
- Tab automatically closes after processing
- Important: With disabled (default) setting, no background tabs are opened
- URL Logging:
- Recording operation logs may contain URLs (retained for up to 7 days)
- URLs are logged as domain names only (path information excluded); full URLs are not recorded
- These logs are for debugging purposes only and can be viewed or deleted from the dashboard
- AI Provider (User-Selected): Used to generate summaries. The following options are available:
- Google Gemini API: Data is processed according to Google's privacy policy.
- OpenAI-Compatible APIs (Groq, OpenAI, Anthropic, etc.): Data is processed according to each provider's policy.
- Local LLMs (Ollama, LM Studio, etc.): Data is processed entirely within your local environment.
- Your Local Obsidian Instance: Used to save history. This is your own local server.
- Tranco List (Trusted Domain List): Used for domain trust verification. The following operations are performed:
- Automatic Tranco Top 1000 List Updates: The extension periodically automatically updates the Tranco Top 1000 domain list
- Data Source: Domain list is retrieved from the Tranco project's public API (https://tranco-list.eu/)
- Data Retrieved: Domain names only (e.g., google.com, amazon.co.jp). No personally identifiable information is included
- Storage Location: Retrieved domain lists are stored in Chrome local storage
- Purpose: To determine whether visited domains are trustworthy (domains included in Tranco Top 1000 are considered trusted)
- Privacy Impact: Since only domain names are retrieved and stored, your browsing history or personally identifiable information is not sent to Tranco
- GitHub (Bug Reporting, User-Initiated Only): The Diagnostics panel includes a "Report a Bug" button. This sends no data automatically:
- Trigger: Only activated when you click the button and then confirm the preview
- Data Included: Extension version, browser user agent, debug mode flag, SQLite initialization status, AI provider type name only, Obsidian connection protocol/port only, and recent error code names with counts
- Data Excluded: API keys, base URLs, your Obsidian daily note path, and log message contents are never included
- Confirmation Step: You can review the exact text before a new GitHub tab opens; closing the preview sends nothing
The extension analyzes the following HTTP headers to automatically detect private pages:
-
Cache-Control: private header-
Cache-Control: no-store + Set-Cookie header combination-
Set-Cookie + Vary: Cookie header combination-
Authorization header[!NOTE]Cache-Control: no-cacheis not included in the detection criteria. This directive is commonly used on news sites and does not necessarily indicate private content.
The following status codes are assigned when private pages are detected:
| Code | Description | Detection Target |
|------|-------------|------------------|
| PSH-1001 |
Cache-Control: private or no-store + Set-Cookie detected | HTTP response header || PSH-2001 |
Set-Cookie + Vary: Cookie detected | HTTP response header || PSH-3001 |
Authorization header detected | HTTP request header || PSH-9001 | Unknown reason | Other private detection |
[!NOTE]
PSH-1001 detectsCache-Control: privatestandalone, orCache-Control: no-storecombined withSet-Cookie.no-storealone does not trigger private detection.
Detected pages are protected as follows:
- Manual Recording:
- A confirmation dialog is displayed with the following options:
- Cancel
- Save once (force save)
- Save and allow entire domain (add to whitelist)
- Save and allow this path only (add path to whitelist)
- Auto Recording:
- Private pages are temporarily saved as "Pending Pages"
- Later you can batch-process from the popup UI:
- Save selected pages
- Add selected domains to whitelist and save
- Discard selected pages
- Pending pages automatically expire after 24 hours
The following data is temporarily stored locally for pages detected as private:
- Page URL
- Page title
- Detection reason (cache-control / set-cookie / authorization)
- Detected header value (up to 1024 characters)
- Timestamp
- Expiration time (24 hours later)
This extension requires the following permissions:
- Content Script Page Access:
- Required to extract content from visited pages as specified in
content_scripts - Collects page titles, URLs, and body text
- Data is used solely for AI summarization and saving to Obsidian
- Whether page body text is stored locally is configurable in the settings (default: off). Change it under Dashboard → Settings → Content Retention Settings
- Browsing history can be exported outside the device as a standard SQLite file (archive). Archive files are plaintext (no encryption or signing); their storage and deletion are managed by the user
- Web Request Monitoring (
webRequest): - Required to analyze HTTP response headers for automatic private page detection
- Detects
Cache-Control: no-store,Set-Cookie, andAuthorizationheaders - Used to prevent accidental recording of private pages (banking, email, etc.)
- Important: Does not modify or block requests (read-only)
- Network Connection Permissions (
connect-src): - Connection to Obsidian Local REST API (local server)
- Connection to user-selected AI provider APIs (Google Gemini, OpenAI-compatible APIs, etc.)
- Connection to user-specified custom API endpoints
- Declarative Net Request Permission (
declarativeNetRequest): - Used only to remove the
Originheader from requests to the Ollama server the user has configured - Works around Ollama's default CORS rejection; scoped strictly to the configured Ollama host
- Does not inspect request content or change the destination (header removal only)
Important: All data processing is based on your explicit configuration. The developer does not collect any data.
Dashboard → Privacy Settings → "Data Management" section → "Delete All Data" button
Individual browsing history entries are physically deleted from the database (GDPR Art.17 compliance). WAL checkpoint ensures disk space is released after deletion.
All data is stored locally and can be deleted by uninstalling the extension or manually deleting notes in Obsidian.