skip to content
dy .

legal · privacy · Grimoire

Grimoire Privacy Policy

Chrome Extension · effective September 7, 2026 · updated September 7, 2026

Grimoire Privacy Policy

Last Updated: September 2026

Overview

Grimoire is a Chrome extension that saves the web page you are currently viewing to your own self-hosted Grimoire server, where it is archived, tagged and made searchable. This privacy policy explains how the extension handles your information.

The Short Version

The developer receives none of your data. When you save a page, the extension sends it only to the Grimoire server address that you configure, authenticated by your own API key. That server is yours. The Service Provider (Dogu Yilmaz) operates no server, receives no page content, and runs no analytics. Everything else stays on your device.

Information the Developer Collects

None. The extension has no backend belonging to the developer. It transmits nothing to the Service Provider or to any third party, and it contains no analytics, telemetry, crash reporting or tracking of any kind.

Data You Send, and Where It Goes

The extension exists to send data to one place: your own Grimoire server.

  • What is sent: the URL and the rendered content (the HTML your browser has already displayed) of a page, and only at the moment you explicitly save it.
  • Where it is sent: exclusively to the server address you entered in the extension’s options, over HTTPS, with the API key you provided. You choose and control that destination.
  • When it is sent: only when you trigger a save (the toolbar button, the keyboard shortcut, or the right-click menu). The extension does not read or transmit pages in the background.
  • Who else sees it: no one. Nothing is routed through the developer or any intermediary.

Because the destination is a server you run, the handling of the saved content once it arrives is governed by your own server, not by this extension.

Local Data Storage

The extension stores a small amount of data locally on your device using Chrome’s storage API:

  • Your Grimoire server URL: so you do not re-enter it each time
  • Your API key: the credential used to authenticate to your own server
  • Theme preference: your Auto, Light, or Dark choice for the extension’s own screens

Important Notes

  • This data is stored in local extension storage on this machine only
  • The API key is never synced through your browser account
  • None of it is transmitted to the developer or to any third party
  • You can clear all of it by uninstalling the extension

Permissions Explained

The extension requests four permissions and no host permissions:

activeTab

  • Purpose: to read the current tab’s URL and content so the page can be archived
  • Usage: granted only at the moment you trigger a save
  • Limitation: one-time access to the active tab; no standing access to your tabs and nothing on pages you do not save

scripting

  • Purpose: to run a capture script in the active tab that serializes the already-rendered page, so content behind a login is saved exactly as you see it
  • Usage: only in response to your save action
  • Limitation: never runs automatically on any site

storage

  • Purpose: to keep your server URL, API key and theme preference locally
  • Usage: Chrome’s local storage
  • Limitation: the data never leaves your device and the API key is never synced

contextMenus

  • Purpose: to add a single right-click item, “Save to Grimoire”
  • Usage: an alternative way to trigger the same save action
  • Limitation: adds one menu item and nothing else

The extension does not request host permissions, so it holds no standing access to any website; it reaches a page only through activeTab at the moment you save.

How Grimoire Works

  1. You trigger a save on the page you are viewing.
  2. The extension captures that page’s URL and rendered content.
  3. It sends them to your server, the address you configured, over HTTPS with your API key.
  4. Your settings stay local; nothing about the save is retained on your device beyond your own preferences.

Remote Code

The extension uses no remote code. All of its JavaScript is bundled in the package. Its network requests go only to your configured Grimoire server and carry data, never executable code.

Third-Party Services

The extension uses no third-party services, analytics, or tracking tools.

Data Security

Data in transit travels only to your own server over HTTPS. Your API key is held in local extension storage and is never synced. Because the developer operates no server and receives no content, there is no developer-side store of your data to breach.

Children’s Privacy

The extension does not knowingly collect information from anyone, including children under the age of 13.

International Users

The extension works for users worldwide. Since the developer collects no data, no cross-border transfer to the developer occurs; any transfer is between your browser and the server you chose.

Your Rights

Because the developer holds none of your data, there is nothing on the developer’s side to access, correct, delete, restrict, or port. The saved content lives on your own Grimoire server, under your control, and your local settings are removed when you uninstall the extension.

Uninstalling Grimoire

To remove all traces of the extension:

  1. Go to chrome://extensions/
  2. Find Grimoire and click “Remove”
  3. All locally stored settings, including your API key, are deleted automatically

Contact Information

If you have questions about this privacy policy or the extension:

Changes to This Policy

If this privacy policy changes, the Service Provider will:

  • Update the “Last Updated” date above
  • Publish the updated policy at this address
  • Reflect the change through the Chrome Web Store update process

Compliance

This privacy policy is designed to comply with:

  • Chrome Web Store Developer Program Policies
  • General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • Children’s Online Privacy Protection Act (COPPA)

The developer processes no personal data, so no legal basis is required on the developer’s side. Any processing of the content you save takes place on your own Grimoire server, for which you are the controller.

Conclusion

Grimoire is built so that saving what you read never means handing your reading to anyone else. The pages you save go only to the server you run, and the developer is never in the path. If you have any questions about how the extension works, please get in touch.


Grimoire - Privacy by Design

This privacy policy is effective as of the date listed above and applies to all users of the Grimoire Chrome extension.