匣藏 隐私政策
生效日期:2026-09-05 · 上次更新:2026-09-05 · 开发者联系:iclzh@gmail.com
一句话说明:匣藏只在你的电脑上运行。收藏和设置只保存在这台电脑的浏览器里。开发者没有服务器、没有账号系统、没有云同步,也不会把你的数据发到云端处理、出售或用于广告。
本政策适用于 Chrome 扩展「匣藏 - 跨平台收藏」(扩展 ID:jhhfpbbmjkneelmffnkghbjkkogmhclo)。名称里的「跨平台」是指你可以收藏任意网站上的内容,不是跨设备云同步。
本页同时提供完整中文和完整英文。Chrome Web Store 要求:凡处理用户数据的产品,隐私政策必须详细说明收集、处理、存储、共享,且不得省略任一部分。
1. 数据控制者
本扩展由独立开发者提供,不隶属任何公司云服务。开发者不运营后端、数据库或分析平台。联系邮箱:iclzh@gmail.com。
2. 收集(Collection)
扩展会在你主动收藏时,在本机读取并保存你选择保存的内容。这属于 Chrome Web Store 所称的「处理用户数据」(网站内容),因此必须公布本政策。开发者本人接收不到这些数据。
| 数据类型 | 来源 | 是否必须 |
|---|---|---|
| 网页标题、网址、简介、封面图地址、网站图标地址 | 你正在收藏的当前页的公开信息 | 收藏网页时需要 |
| 你选中的文字、你右键的图片地址或图片文件 | 你主动选择收藏的内容 | 收藏文本/图片时需要 |
| 标签、备注、所属收藏集、快捷键、置顶状态 | 你输入或整理时产生 | 可选 |
| 扩展设置(主题、默认收藏集、显示模式等) | 选项页 | 记住你的偏好 |
| 加密收藏集的密码派生材料 | 你为某个收藏集设置的密码 | 仅当你使用加密收藏集 |
扩展不收集:姓名、电子邮箱、电话、精确位置、支付信息、政府身份证件、健康信息、其它网站的 Cookie / 密码 / 登录态、完整浏览历史、通讯内容、广告标识符。不会在后台静默抓取你访问过的每一个网页。
内容脚本只在你打开的 http/https 页面上运行,用途仅限:显示收藏确认框、响应你自己设定的快捷键、在你点击收藏时读取当前页公开元数据。不会把页面全文发给任何人。
3. 处理(Processing)
所有处理都在你的浏览器进程里完成本地计算,不经过开发者服务器,也不调用第三方云 API 来整理收藏。
- 把你选择的标题、链接、摘录、图片写入本机收藏库
- 按收藏集、标签、流程规则在本机分类、搜索、排序、置顶
- 在本机渲染 Markdown 备注、生成二维码
- 对加密收藏集在本机做密码派生与加解锁(解锁状态只存在当前浏览器会话)
- 回收站在本机保留 15 天后自动删除
- 网站图标若没有来自原网页的地址,则在本机生成字母图标,不向 Google 或其它图标服务查询
处理目的只有一个:向你提供本机收藏功能。不用于广告、分析、画像、个性化推荐、信贷或放贷评估,也不用于改进开发者的其它产品。
本扩展遵守 Chrome Web Store User Data Policy(含 Limited Use):用户数据的使用仅限于已披露的单一用途。
4. 存储(Storage)
| 存什么 | 存在哪里 | 是否离开本机 | 保留多久 |
|---|---|---|---|
| 收藏条目、收藏集、流程、图片数据 | 本机 IndexedDB(数据库名 xiacang) | 否 | 直到你删除、清空回收站,或卸载扩展 |
| 扩展设置 | 本机 chrome.storage.local | 否 | 直到你更改或卸载 |
| 加密收藏集解锁状态 | 本机 chrome.storage.session | 否 | 关闭浏览器即失效 |
| 你导出的 JSON / 书签 / 文件夹备份 | 你在本机选择的路径 | 否(除非你自己把文件拷走) | 由你决定 |
不使用 chrome.storage.sync,因此数据不会通过 Google 账号同步到其它设备。开发者没有云盘或远程数据库。
卸载扩展后,Chrome 会删除该扩展的 IndexedDB 与 chrome.storage 数据。卸载前请先自行导出备份,否则无法恢复。
安全措施:数据只写在你控制的设备上;加密收藏集密码不上传;扩展包内不包含远程脚本。设备本身的安全(锁屏、系统账户)由你负责。
5. 共享(Sharing)
开发者不会把你的数据共享、出售、出租或转让给任何第三方。没有广告商、没有分析 SDK、没有崩溃统计、没有开发者自有服务器。
默认情况下,扩展不会为了提供收藏功能而把标题、网址、正文或图片发送给任何第三方。
只有在你自己操作时,浏览器才可能向其它网站发请求(这与点击一个普通书签相同),这些请求不是开发者收集数据:
| 情形 | 可能接触数据的一方 | 发送什么 | 是否默认发生 |
|---|---|---|---|
| 你打开已收藏的链接 | 该网站 | 普通网页访问 | 否,需你点击 |
| 你在收藏库里播放已收藏的视频 | YouTube / 哔哩哔哩 / 优酷等视频平台 | 该视频的嵌入播放请求 | 否,需你点击播放 |
| 某条收藏保存了远程封面图或原站图标地址 | 该图片所在的原网站 | 浏览器加载该图片 | 仅当该条收藏本身带有远程图片地址 |
| 你把备份文件发给别人或传到网盘 | 你选择的接收方 | 你导出的文件 | 否 |
扩展内嵌播放 YouTube 时,仅为扩展自己发起的嵌入请求补上 YouTube 需要的 Referer,不修改你日常上网的其它请求。
法律要求、保护用户免受欺诈/恶意软件,或经你明确同意的资产转让,属于 Chrome Web Store Limited Use 允许的例外;除此之外禁止转让用户数据。
6. 权限为什么需要
storage/unlimitedStorage:在本机保存设置和收藏(含图片)。activeTab/tabs/scripting:只在你收藏时读取当前页标题、链接、封面,并显示确认框。contextMenus:右键收藏网页、链接、图片、选中文字。sidePanel:在侧边栏打开本机收藏库。declarativeNetRequestWithHostAccess:仅为扩展内嵌 YouTube 播放补 Referer。- 访问所有网址:因为你可以收藏任意网站;不是为了监控你的上网,也不会把页面发给开发者。
7. 你的控制权
- 随时编辑或删除单条收藏;删除后进入回收站,15 天后自动清除,也可立即彻底删除。
- 选项页可导出 / 导入 JSON 备份,或备份到本地文件夹。
- 卸载扩展即删除本机扩展数据。
- 隐私问题或删除协助:iclzh@gmail.com。
8. 儿童
本扩展不面向 13 岁以下儿童,不故意收集儿童的个人数据。
9. 政策变更
若数据处理方式发生变化,我们会更新本页日期并在扩展更新说明中提示。继续使用更新后的扩展即表示你知悉更新后的政策。重大变更会尽量通过扩展内说明提示。
10. 联系
隐私问题请发邮件至 iclzh@gmail.com。
本政策公开地址(请填写在 Chrome 网上应用店「隐私政策」栏,不要只写在描述里):https://canyonsfr.github.io/xiacang-privacy/
XiaCang Privacy Policy
Effective: 2026-09-05 · Last updated: 2026-09-05 · Contact: iclzh@gmail.com
Summary: XiaCang (“匣藏”) runs only on your device. Saved items and settings stay in your local browser. The developer operates no servers, accounts, or cloud sync, and does not send your data to the cloud for processing, sale, advertising, or analytics.
This policy applies to the Chrome extension “匣藏 - 跨平台收藏” (ID jhhfpbbmjkneelmffnkghbjkkogmhclo). “Cross-platform” means you may save content from any website. It does not mean cloud sync across devices.
Chrome Web Store policy: if a product handles user data, the privacy policy must comprehensively disclose collection, processing, storage, and sharing, including every party with whom data is shared. This English section is complete, not a summary.
1. Data controller
The extension is provided by an independent developer. There is no company backend, hosted database, or analytics platform. Contact: iclzh@gmail.com.
2. Collection
When you choose to save an item, the extension reads and stores the content you selected, on your device. That is “handling user data” (website content) under Chrome Web Store rules, so this policy is required. The developer does not receive this data.
| Data | Source | Required? |
|---|---|---|
| Page title, URL, description, cover image URL, site icon URL | Public metadata of the page you are saving | When saving a page |
| Selected text; image URL or image file you chose | Content you explicitly save | When saving text/images |
| Tags, notes, collection, shortcut, pin state | Your input and organization | Optional |
| Settings (theme, default collection, view mode) | Options page | To remember preferences |
| Password-derived material for locked collections | A password you set | Only if you use locked collections |
We do not collect: name, email address, phone number, precise location, payment data, government IDs, health data, cookies / passwords / sessions of other sites, full browsing history, communications, or advertising IDs. The extension does not silently scrape every page you visit.
Content scripts run on http/https pages only to show the save confirmation, honor shortcuts you configured, and read public metadata when you save. Page content is not sent to anyone.
3. Processing
All processing is local computation inside your browser. Nothing is sent to a developer server or to a third-party cloud API to organize your library.
- Write the title, URL, excerpt, and images you chose into the local library
- Organize, search, sort, and pin items locally by collections, tags, and rules
- Render Markdown notes and generate QR codes locally
- Derive and verify lock passwords locally (unlock state lives only in the current browser session)
- Keep deleted items in a local trash for 15 days, then delete them
- If a site icon URL is missing, generate a letter icon locally — no Google (or other) favicon service is queried
The only purpose is the disclosed single purpose: local bookmarking. Data is not used for ads, analytics, profiling, personalization, credit, lending, or other products.
Use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
4. Storage
| What | Where | Leaves the device? | Retention |
|---|---|---|---|
| Items, collections, rules, image data | IndexedDB on this device (database name xiacang) | No | Until you delete it, empty trash, or uninstall |
| Settings | chrome.storage.local | No | Until you change it or uninstall |
| Unlock state for locked collections | chrome.storage.session | No | Ends when the browser session ends |
| JSON / bookmark / folder backups you export | A path you choose on this device | No, unless you copy the file yourself | You decide |
The extension does not use chrome.storage.sync, so data is not synced to other devices through a Google Account. The developer has no cloud drive or remote database.
Uninstalling the extension deletes its IndexedDB and chrome.storage data. Export a backup first if you want to keep your library.
Security: data stays on a device you control; lock passwords are not uploaded; the store package contains no remote code. Device security (lock screen, OS account) is your responsibility.
5. Sharing
The developer does not share, sell, rent, or transfer your data to any third party. There are no advertisers, analytics SDKs, crash reporters, or developer-operated servers.
By default, the extension does not send titles, URLs, body text, or images to any third party in order to provide bookmarking.
The browser may contact other websites only when you take an action (the same as opening a normal bookmark). Those requests are not developer collection:
| Action | Party | What is sent | Default? |
|---|---|---|---|
| You open a saved link | That website | A normal page visit | No — you click |
| You play a saved video in the library | YouTube / Bilibili / Youku, etc. | The embed request for that video | No — you click play |
| An item already stores a remote cover or original-site icon URL | The site that hosts that image | The browser loads the image | Only if that item has a remote image URL |
| You send an exported backup to someone else | The recipient you chose | The file you exported | No |
For in-library YouTube playback, the extension only adds the Referer YouTube requires on embed requests initiated by the extension. It does not rewrite your ordinary browsing.
Transfers required by law, to protect against malware/fraud, or as part of a sale of assets with your explicit prior consent, are the Limited Use exceptions. All other transfers are prohibited.
6. Why permissions are used
storage/unlimitedStorage: save settings and items (including images) on device.activeTab/tabs/scripting: read title, URL, and cover of the page you are saving, and show the confirmation UI.contextMenus: right-click to save a page, link, image, or selection.sidePanel: open the local library in the side panel.declarativeNetRequestWithHostAccess: set Referer only for extension-initiated YouTube embeds.- Host access to all URLs: you may save from any site. This is not browsing surveillance and page content is not sent to the developer.
7. Your controls
- Edit or delete any item. Deleted items go to Trash for 15 days, or you can delete them immediately.
- Export / import JSON backups, or write a backup to a local folder, from Options.
- Uninstalling removes the extension’s local data.
- Privacy requests: iclzh@gmail.com.
8. Children
The extension is not directed at children under 13 and does not knowingly collect their personal data.
9. Changes
If data practices change, this page and its date will be updated, and the extension changelog will note the change. Using an updated version means you have been informed of the updated policy. Material changes will also be described in-product when practical.
10. Contact
Email iclzh@gmail.com.
Public URL (must be entered in the Chrome Web Store Privacy Policy field, not only in the description): https://canyonsfr.github.io/xiacang-privacy/