Privacy Policy

This Privacy Policy explains what personal data we process in connection with the AdTab Killer browser extension (the Extension), the website at adtabkiller.htmyname.dev (the Website) and the account and licensing service behind them, together the Service. It sets out what we collect, the purposes for which we process it, who else receives it and how long we retain it. It applies to the Website and to the Extension as published on the Chrome Web Store, Microsoft Edge Add-ons and Firefox Browser Add-ons.

In summary: we process the data required to operate a paid license, together with a limited record of security events. We do not operate advertising, we do not use analytics, and we do not sell or rent personal data.

1. Data handled on your device

Your settings, your allowed and blocked lists and the activity log of the Extension are stored locally in your browser. Neither your browsing history nor that activity log is transmitted to our servers.

In the absence of a license, the Extension makes no network requests: it contacts no server operated by us and no third party, and it contains no analytics or telemetry.

License validation is the exception. In order to confirm that a license is valid and to identify the installation using it, the Extension contacts our servers, as would any paid feature requiring a server. Those requests carry the credentials of your account and the identifier we issued for that installation. They contain nothing describing the pages you visit or the tabs the Extension has closed. In response we update a usage counter and a last seen date for that installation.

Cloud sync is the only paid feature that transmits your settings and lists to our servers, and it operates only where you enable it. It is disabled until you enable it, the Extension is fully functional without it, and enabling it removes nothing from your browser: the copy held on our servers exists so that your other browsers can obtain a change, and each of your browsers retains its own copy.

The data stored in this way is encrypted and we are unable to read it. Values are encrypted on your device with a key held only by your browsers, and the address of a site in a list reaches us only as a one-way hash, so that we can determine how many sites a list contains but not which sites they are. The key itself is stored only in a form that your password unlocks, and your password is never available to us. What this does not conceal is the number of entries you synchronise and the times at which they change. The scope of this is set out in Section 2 and Section 7.

2. Data we process

Account data. Your email address, which constitutes the account, and your password, stored only as a cryptographic hash. An account created by a purchase holds no password until you set one.

Purchase data. The date, the amount, the email address used at checkout and the payment reference issued by our payment processor. Card details are never received or stored by us.

License and device data. Your license, its support reference, its status and its expiry date where applicable, a usage counter and, for each linked installation, an identifier issued by our servers, an optional label chosen by you, the date on which it was linked and the date on which it was last seen. A license covers up to 10 linked installations.

Session data. Sign-in sessions are stored as hashes so that they can be revoked. Access credentials issued to the Extension expire after one hour; long-lived session records expire after thirty days or upon revocation.

Security and audit data. We maintain a record of events relevant to the security of an account: successful and failed sign-in attempts, requests refused for exceeding a rate limit, password changes, requests for a password link, devices unlinked, and changes to the status of an account or of its license. An entry may record the event, its date and time, the originating IP address and the email address submitted with the request. A failed sign-in records the address submitted, which may correspond to no account. Retention periods are set out in Section 7.

Synced settings and lists. Processed only where you enable cloud sync. For each setting or site synchronised we store a single entry comprising an identifier, the time at which it last changed and the value, encrypted with a key we do not hold. For a setting the identifier names it in plain text; for a site in one of your lists it contains a one-way hash of the address in place of the address. We also store the encrypted key, which only your password unlocks, and a counter by which your browsers determine what has changed since they last connected. Where you remove a site, we retain a dated marker recording the removal, so that a browser that was offline does not restore it.

Server logs. Our hosting provider and our application generate technical logs of errors and requests, which may include IP addresses.

Uninstall feedback. On uninstalling the Extension, your browser opens a page inviting you to state why. A response is optional. Where you respond, we store the reason selected, any text you enter, the version of the Extension, the language in which you used it, whether a paid license was held, an approximate range for the period it had been installed (such as "first week" or "over a year", never an exact date) and the date of the response. No identifying data is stored with it: no account, no email address and no IP address, so that a response cannot be attributed to a person or linked to any other data we hold. Personal details should not be entered in that field.

3. Purposes and legal bases

We process this data on the basis that it is necessary for the performance of the contract between us, for compliance with our legal obligations, and for our legitimate interest in maintaining the security and availability of the Service.

4. Recipients and processors

Stripe processes payments. Card details are transmitted to Stripe and do not reach us; we receive confirmation of the purchase and the email address used for it. See the Stripe Privacy Policy.

Cloudflare provides the anti-bot verification presented on our sign-in and password forms. When such a page loads, your browser contacts Cloudflare, which receives your IP address and technical signals relating to your browser in order to determine whether the request is automated. See the Cloudflare Privacy Policy.

Our hosting and email provider stores the database and delivers the messages described in Section 6 on our behalf.

These providers act on our instructions and may process data outside your country. Save as set out above, we disclose personal data only where required by law. We do not sell or share personal data for advertising purposes.

The pages of the Website load no third-party fonts, trackers or analytics. The only third-party request made by a page is the anti-bot verification described above, which appears solely on the sign-in and password forms.

5. Cookies

The account portal sets a session cookie in order to keep you signed in and uses tokens in its forms to prevent cross-site request forgery. The cookie is restricted to our own site and is not readable by scripts. No advertising or analytics cookies are used, and cookies are not used to track you across other websites.

6. Communications

We send transactional messages only: confirmation of a purchase, and the one-time link used to set or reset a password. We send no newsletters and no marketing, and there is no mailing list.

7. Retention periods

8. Your rights

Depending on your place of residence, you may have the right to obtain access to the personal data we hold about you, to have it rectified or erased, to restrict or object to its processing, to receive it in a portable form, and to lodge a complaint with your data protection authority.

You may delete your account yourself, without contacting us, from your account pages. Deletion removes the account, its licenses, its linked devices and anything you had synchronised. Two categories of data survive it, both described in Section 7 and both retained for the periods stated there: purchase records, which are required in order to answer a refund or a chargeback and to comply with accounting rules, and security records, which exist so that an incident affecting an account remains capable of investigation.

To exercise any other right, contact us as described in Section 11. We will ask you to confirm control of the email address of the account, as that address is what identifies an account and we have no other means of verifying such a request.

Deletion of an account removes the account, its licenses, its linked devices, its sessions, its password links and its synced settings. As stated in Section 7, the record of a purchase is retained.

9. Security

Passwords are stored as hashes, and session tokens and password links are stored as hashes rather than in a form capable of reuse. Traffic to the Website is served over HTTPS. Sign-in attempts and password changes are rate limited. Access to personal data is restricted to what is necessary to operate the Service.

Data you synchronise is encrypted on your device before transmission, with a key we do not hold: it is stored only in a form that your password unlocks, and your password does not reach us in a readable form either. Two consequences follow, and both are intended: a copy of our database is of no use to whoever obtains it, and we are unable to recover your synced data on your behalf under any circumstances.

No method of storage or transmission is entirely secure, and we cannot guarantee absolute security.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data relating to them. If you believe that a child has provided us with personal data, contact us and we will delete it.

11. Contact

AdTab Killer is a fictitious name registered in the State of Florida and is operated as a sole proprietorship by Handrit Trimino.

A request concerning your data should be sent from the email address of the account to which it relates: that address is what identifies an account, and we have no other means of verifying the request.

12. Changes to this policy

We may update this policy. The date shown at the top is amended accordingly, and substantial changes are announced on the What's new page. Continued use of the Service after a change constitutes acceptance of the updated policy.