Privacy policy
Last updated: 21 August 2026.
This privacy policy applies to the Lord Of The Scrappers Chrome extension (the “Extension”). The Extension extracts structured data from web pages you choose and shows it in a side panel and tables on your computer. Licensing uses Google sign-in and our license API.
Chrome Web Store Limited Use: The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
1. Data We Collect or Access
A. Accessed and processed on your device (not sent to our license API as scrape content)
- Website content and page resources: With your host access and scripting permissions, the Extension can read the DOM and related content of pages you open or queue for extraction (for example titles, prices, emails, images, links, and other fields you select).
- Tab URLs and tab metadata: Used to run extraction jobs, open result pages, and wait for navigation.
- Extracted tables and job records: Rows, columns, automation/job metadata, and exported file contents created by your extractions.
- Extension settings: Preferences such as queue settings, list-wait options, and anti-bot options stored locally.
- Optional clipboard write: When you copy extracted rows, table cells, or a local authenticator secret.
- Optional cookies: When a feature requests cookie permission for a site you are extracting (for example logged-in pages) or for an extension cookie used by table features in the vendor UI.
B. Collected by our license API when you sign in or use a licensed install
The Extension sends requests over HTTPS to https://lots-extension-api.lots-scrappers.workers.dev. That API may collect:
- Google account email and Google subject id (sub), obtained by verifying a Google OAuth access token (Chrome Identity; scopes include openid, email, and profile). We store email and sub; we do not receive your Google password.
- Session token: issued after sign-in; the raw token is stored in the Extension’s local storage; the server stores a hash of the token.
- Device / install identifiers: a random device id created on the install, the Chrome extension id, and the extension version.
- License and quota data: license plan/status, device limits, and a daily count of URLs processed for quota (counts only; not the page HTML or extracted row contents).
- Operational event records: event type (for example sign-in or protected-operation), optional JSON payload such as a URL count, timestamp, and a SHA-256 hash of the connecting IP used for rate limiting and abuse prevention.
The license API does not receive scraped page HTML, extracted tables, exported CSV contents, or a full browsing history.
2. How We Use Data
- Website content / extracted tables: to provide extraction, live results, jobs list, and export (CSV and similar) on your computer.
- Tab URLs: to navigate and scrape only jobs you start.
- Google email and sub: to check that the signed-in account is allowed to use the Extension and to attach a license.
- Session, device id, extension id, version: to keep a signed-in install authorized, enforce device limits, and support heartbeat / revoke flows.
- Daily URL counts: to enforce the license quota.
- IP hash and event logs: to rate-limit the API and investigate abuse.
- Clipboard / cookies (optional): only for the copy or site-access features described above when you use them.
- Google Sheets export (optional UI action): when you choose that export path in the table UI, the Extension copies data to the clipboard and can open Google Sheets in a new tab so you can paste. That flow does not upload the table to our license API.
We do not use this data for advertising, ad targeting, or selling user profiles. There is no separate analytics or telemetry SDK in the Extension.
3. Data Storage and Handling
- Local storage (your computer):
chrome.storage.local/ session keys for license session and settings; IndexedDB databases used for scrape tables and result files (including databases named for historical vendor schema); exported files written via the Chrome downloads API when you save/export. - Server storage: Cloudflare Worker + Cloudflare D1 hold users, licenses, devices, sessions (token hashes), daily usage counters, rate-limit buckets, feature flags/config, and event logs as described above.
- Temporary processing: Google access tokens are verified with Google’s tokeninfo endpoint during sign-in; page content is processed in the browser for extraction.
- Transmission: license API traffic uses HTTPS.
4. Data Sharing
We do not sell personal data. Data is shared only with the parties below, for the purposes stated.
- Google LLC: Chrome Identity / OAuth sign-in. Google receives the OAuth request and returns identity fields (we use email and sub). If you use export-to-Sheets, you interact with Google Sheets in your browser after a local clipboard copy.
- Cloudflare, Inc.: hosts our Worker and D1 database. License, device, session, usage, and event data above are stored/processed on Cloudflare. Cloudflare’s network may process connection metadata (including IP addresses) as part of hosting.
- No other third-party recipients: we do not send Extension user data to analytics vendors, ad networks, or data brokers.
- Legal / safety: we may disclose information if required by law or to address abuse, fraud, or security threats.
5. Third-Party Services
External services contacted by the Extension or license backend, as implemented in this project:
- Google OAuth / Chrome Identity and
https://oauth2.googleapis.com/tokeninfo(token verification on the Worker). - Lord Of The Scrappers license API at
https://lots-extension-api.lots-scrappers.workers.dev(Cloudflare Workers + D1). - Websites you choose to extract (via host permissions / scripting) — content stays in your browser unless you export or share it yourself.
- Google Sheets (docs.google.com) only if you use the optional export UI that opens Sheets for pasting.
6. Data Retention
- Local finished result files: the Extension’s result-file store retains finished files for 10 days from creation, then removes those entries (and related scrape table data when cleaned up).
- License sessions on the server: session records expire after 7 days from issuance (unless revoked earlier).
- Other server records (user, license, device, usage counters, events): kept while needed to operate licensing, quotas, and abuse prevention. The product does not auto-delete these on a published calendar schedule beyond session expiry and admin revoke flows.
- Local settings / device id: remain until you clear Extension storage or uninstall.
7. Data Deletion / User Controls
- Clear site data for the Extension in Chrome, or uninstall the Extension, to remove local storage and IndexedDB data on that computer.
- Revoke the Extension’s Google access from your Google Account permissions.
- Finished local jobs age out after 10 days as described above.
- To request deletion of server-side license account data (email, devices, sessions), email the contact below. We can revoke sessions/devices and remove or anonymize account records where reasonably possible. There is no in-product self-serve account-deletion button.
8. Security
License API requests use HTTPS. Session tokens are stored hashed on the server. Admin API routes require a server-side admin secret. The Extension does not load or execute remote JavaScript from the license API (JSON only). Scripts ship inside the Chrome Web Store package. Absolute security cannot be guaranteed.
9. Changes to the Privacy Policy
We may update this policy. The “Last updated” date above will change when we do. Material changes will be reflected at this same URL.
10. Contact Information
Developer: 0ne Systems
Email: abdullaharshadsiddiqui@gmail.com
Homepage: https://lots-extension-api.lots-scrappers.workers.dev/
This policy: https://lots-extension-api.lots-scrappers.workers.dev/privacy