Backs

Your information and your choices

Privacy Policy

Effective date:

This policy explains how Backs handles information in the Backs browser extension and on backs-extension.com. Features available to you depend on your extension version, plan and the tools you enable.

We use information to provide your new-tab dashboard and its tools, manage accounts and subscriptions, answer support requests, prevent abuse, and understand and improve the service. We do not sell personal information or use extension data for personalized advertising.

1. Accounts and saved content

If you create an account, Firebase Authentication processes your email address, display name, account identifier and authentication information, including Google Sign-In when you choose it. Firebase handles passwords; Backs does not store readable account passwords.

The extension stores your Spaces, widget layouts and settings, tasks, notes, focus information, backgrounds, attachments, shortcuts and saved tabs in your browser profile. Saved links and tabs can include page addresses, titles and icons. These are the contents you save to use the dashboard.

When you use account synchronization, the supported content and preferences are sent to Firebase to make them available across your signed-in devices. This can include Space names and layouts, note and task content, saved tabs, shortcut and Block List settings, focus summaries and background selections. Background synchronization can upload your selected personal images. Premium image attachments and saved screenshots are uploaded to private account storage even if the surrounding layout has not yet synchronized.

Sharing a Space creates a public screenshot and a separate layout snapshot on our servers. Review the screenshot before creating the link: anyone with the link can see the visible content, including notes, tasks, links, calendar details, attachments or personal photos shown in the image. The screenshot may also appear in previews when the link is posted elsewhere. Importing a shared Space copies only widget types and positions, colors, appearance and an eligible Unsplash background. It does not copy the screenshot into the Space or import personal note and task text, saved tabs, shortcut destinations, calendar data, private attachments or uploaded personal backgrounds. Public shares are separate from your account's private synchronized content.

2. Tools that interact with websites

  • Tab Time: when enabled with browser permissions, it measures time on the active website while the browser is focused and you are active. It stores domain names and time totals locally, excluding incognito tabs. The history is not sent to Backs analytics or account synchronization. You can pause tracking, exclude sites, or delete the history. Older daily entries are pruned as the tool runs, using a 35-day window.
  • Website blocking: the ordinary Block List checks site addresses against your chosen rules locally. Saved rules can be included in synchronized widget settings. The browsing checks themselves are not a browsing-history analytics feed.
  • Premium smart focus: when enabled for a connected Focus Backon, this feature sends a limited page context through our Firebase backend to OpenAI to assess relevance to your focus. It can include your focus statement, attached task and calendar event titles, the page address without its query string or fragment, page title and description, up to six headings, a short visible-text excerpt of up to 240 words, and the page language. The result is cached briefly on your device. The backend does not write the raw context to its database or application logs and requests the provider's response-storage option to be off; this does not mean that the provider has no operational or security retention.
  • Page links and screenshots: an action you invoke can read the current page address and title or capture a selected area of the visible page for a task or note. Screenshot drafts stay in browser-session storage until you save them; saving an image attachment uploads it to private Firebase storage. Saved page links and task or note content can also synchronize with your account.
  • Search and clipboard search: when you run a search, Backs opens your selected search provider with the query. A clipboard-search action reads clipboard text when invoked and sends it as that search query. Depending on your choice, the destination is Google, DuckDuckGo, Bing or YouTube. Search queries and clipboard text are not included in Backs usage analytics.

You can manage optional permissions in your browser's extension settings. Removing a permission stops the related access; it does not necessarily erase information already saved.

3. Google Calendar

Connecting Google Calendar is optional and requests read-only access. Backs uses an authorization token to request today's events from your primary calendar directly from Google. It does not create, edit or delete calendar events.

For the calendar display, meeting links and connected focus tools, Backs keeps a local cache containing event identifiers, titles, start and end times, all-day status, locations, calendar links and video-meeting links, together with the time of the last fetch. This cache is refreshed when you fetch events; there is no separate automatic age-based cache deletion. It is excluded from ordinary account synchronization and usage analytics. Event titles can be transmitted for Premium smart focus as described above.

You can revoke Backs' Calendar access through your Google Account permissions. Revoking access does not itself clear the existing local cache; remove the relevant local Space data or clear the extension's local storage if you also want to remove that copy.

4. Weather and location

Weather uses latitude and longitude obtained with your browser's location permission. Backs saves those coordinates in local Space storage and reuses them for future forecasts. They are excluded from account synchronization and are not automatically erased after a forecast request.

Forecast requests send the saved coordinates and language through our authenticated Firebase backend to Google Weather. Forecasts and the location used for them are cached locally to reduce repeated requests. The backend also processes your account and request information for access checks and rate limits. Saved coordinates remain until replaced or the relevant local data is removed; provider request records follow the provider's retention practices.

5. Payments and subscriptions

Stripe collects payment-card details directly through its checkout and billing services. Backs does not collect or store your full card number or card security code.

We process more than subscription status: account-to-customer links, Stripe customer and subscription identifiers, checkout records, selected plans, entitlement and payment status, trial eligibility and dates, renewal and cancellation information, invoice identifiers, and payment or refund records. Stripe records may also contain your billing email, name, address, currency, amounts and limited payment-method details.

Our backend uses the records needed to manage billing and access. Stripe billing records are also imported into our private PostHog reporting workspace for subscription, trial, invoice, payment and revenue analysis. When usage analytics is enabled for a linked account, a random analytics account identifier can connect billing outcomes to product activity. Turning analytics off removes the current optional Stripe analytics link after the preference reaches the server; it does not erase historical records or stop necessary billing processing.

6. Usage analytics and controls

Usage analytics is enabled by default. It helps us understand installation and onboarding, feature use, reliability, return visits, and how campaigns and shared Spaces lead people to Backs.

Extension events include an action and time, a random installation identifier, app version, browser and major version, installation source, broad sign-in and plan categories, allowed feature properties and focused, visible dashboard time. Examples include creating a Space, saving a note, completing a task or opening a shortcut. Signed-in free and paid accounts can have a separate random analytics account identifier across profiles. These identifiers are pseudonymous, not anonymous; guest activity is not guessed or merged into an account.

Product usage events exclude note and task text, shortcut destinations, search queries, browsing history, private Space contents, screenshots, passwords and authorization tokens. We do not use session recordings. These limits apply to product events; they do not describe the separate saved content, smart-focus requests, billing or email records covered elsewhere in this policy.

Measurements are validated and stored in Firebase, with product and limited service-event exports to PostHog in the EU and Google BigQuery in the EU. Google Analytics 4 (GA4) supports website and extension reporting, including earlier extension measurement. GA4 exports also contribute to reporting in BigQuery. First-party campaign and sharing records can retain private attribution links that are removed from product-event exports.

On the website, measurement covers public page visits, Chrome Web Store clicks, campaigns and sharing actions. When enabled, GA4 uses browser identifiers and cookies. Measured page addresses and referral sources are restricted to public values; private link details and search terms are excluded. Website measurement is separate from the extension's Tab Time history.

  • Extension: turn off usage analytics in Account and settings. This stops new collection and clears pending events on that device. For a linked account, the server also suppresses account-linked measurements from other profiles once it receives your choice.
  • Website: use Usage analytics & preferences to change the preference for that browser profile. Supported Do Not Track and Global Privacy Control signals also disable website analytics. The extension can pass its disabled preference to the website.

An offline preference change may reach the server later, and accepted or already-in-flight requests may finish delivery in the meantime. Opting out stops future optional measurement; it does not erase received history, required account operations, or separate Stripe and Resend reporting imports. The analytics preferences page and this privacy page do not load analytics.

7. Email and delivery reporting

We use Resend for transactional messages such as verification, password reset, account changes, subscription and trial notices, and account-deletion notices. Resend processes the recipient address, subject, message content and delivery information needed to send these messages. Security messages can include account-action links. Support messages sent to our contact address are forwarded by ImprovMX to our Gmail inbox.

Our private PostHog workspace also imports broader Resend provider records, which can include recipient and sender addresses, subjects, contact names, audience or subscription information, message identifiers, timestamps and delivery status. This reporting import is separate from content-limited product analytics. The current import does not fetch message HTML or text bodies or password-reset action links.

Separate delivery events record template or message identifiers, outcomes and times in Firebase, PostHog and BigQuery, without recipients, subjects, bodies or action links. We do not use email opens or clicks as product engagement measures. Turning optional usage analytics off does not stop necessary account emails or remove provider reporting history.

8. Website features and providers

The website uses Firebase Hosting and, for account and community features, Firebase Authentication, Firestore and Cloud Functions. Roadmap ideas and comments are public with a shortened author name; likes are associated with accounts. Support correspondence is processed to respond to you. Do not include private information in a public roadmap post.

If you submit voluntary uninstall feedback, we privately store your selected reason, optional comment, extension version and submission time until manually deleted. We do not attach your account or installation identifier or send that feedback to analytics services. A hashed network address is used separately for spam protection.

Our service providers process information for the features described in this policy:

  • Firebase and Google Cloud: authentication, account and saved-content storage, private images, hosting, backend requests and operational logs. Google Calendar and Google Weather provide the optional extension features described above.
  • Stripe: checkout, billing, subscriptions, trials and payment records.
  • Resend, ImprovMX and Gmail: transactional email delivery and support correspondence.
  • PostHog, GA4 and BigQuery: the separate usage, operational and provider-reporting flows described above. Native Stripe and Resend imports are held in PostHog's reporting workspace; they are not automatically copied into our product-event BigQuery archive.
  • OpenAI: relevance checks for the extension's enabled Premium smart-focus feature.
  • Unsplash: background photos, photo requests and download reporting in the extension and on the website. Loading a photo contacts its image service. Some website pages also load fonts from Google Fonts.
  • Google and DuckDuckGo favicon services: extension icon lookups can transmit the saved site's origin or hostname to retrieve an icon. Google, DuckDuckGo, Bing and YouTube: receive searches you choose to run. Opening saved links or externally hosted images also contacts their respective sites.

Providers receiving network requests can process technical information such as IP addresses, request times and browser or connection details. They may process data outside your country under their applicable terms and privacy practices. Specifying an EU analytics destination does not mean all Backs processing takes place in the EU.

Website visits do not by themselves grant access to your extension's local notes, saved tabs, calendar cache, weather coordinates or Tab Time history. The extension and website have different processing described above, although signed-in services can use the same Backs account.

9. Retention and deletion

Saved local content generally remains in your browser profile until you remove it, clear the relevant extension data or uninstall the extension. Clearing a local copy does not automatically erase synchronized cloud content, public shares or provider records. We keep account and synchronized content to provide the service until you remove it through supported controls or complete account deletion; there is no single automatic expiry period for all saved content. Some temporary caches, delivery queues, security records and expiring account links have their own bounded lifetimes.

Account deletion has a 14-day cancellation window. Request deletion in the account settings. You can cancel before the scheduled deletion time. After that window, scheduled cleanup removes your Firebase account and account documents, private task images and synchronized background files, and cancels applicable subscriptions. Cleanup may retry if a service is unavailable. The account and subscription can remain active during the window; manage your subscription separately in the billing portal if you need to stop renewal sooner.

Roadmap ideas and comments are retained with the author changed to “Deleted user” and the account link removed; the account's like receipts are removed. Public shared Space snapshots are separate and are not automatically removed with an account. Contact us with the share URL to request removal. Copies already imported by other people or saved elsewhere cannot be recalled by deleting the original link.

Stripe customer, invoice, payment and related billing records are not automatically erased by Backs account deletion. Billing and operational records may be retained for accounting, legal obligations, security, dispute handling and service administration, subject to the relevant provider's practices. A plan's access or grace-period deadline is not a promise that stored content is automatically erased on that date.

Historical analytics and provider reporting require separate handling. We currently retain analytics history for launch comparisons, feature trends, reliability and return analysis without an automatic age-based purge of the Backs analytics archive. We review whether that history remains needed and handle cleanup manually. Provider limits and retention settings also apply; a provider's reporting window is not a guarantee of physical deletion. Preference-suppression records are retained so old identifiers cannot resume collection.

To request access, correction or deletion, email hello@backs-extension.com. Tell us which account and data the request concerns, including a share URL if relevant. We may need to verify ownership and clarify the records involved. We review the applicable Firebase, analytics, email and billing destinations and explain any information that must be retained. Deleting an account, opting out and requesting erasure of historical analytics are distinct actions; none promises immediate removal of all information from every provider.

10. Chrome Web Store Limited Use

Backs handles user data, including information received from Google APIs, in compliance with the Chrome Web Store User Data Policy and its Limited Use requirements.

We limit use and transfer of extension data to providing and improving Backs' disclosed functionality and related operations, security and legal requirements. Browsing activity is used only where needed for the described user-facing tools. We do not sell extension user data, use it for personalized advertising, transfer it to data brokers, or use it to determine creditworthiness or lending eligibility. Human access is limited to the circumstances allowed by that policy, such as your specific consent, security or legal needs, or aggregated and anonymized internal operations.

11. Changes and contact

We may revise this policy as Backs changes. The effective date above identifies this version. We will provide additional notice of material changes where required.

For privacy questions, support or data requests, contact hello@backs-extension.com.