Privacy Policy — Text Expander by ByteForth
Effective September 22, 2026. Publisher: ByteForth. Contact: hello@byteforth.com.
Snippets and settings
The extension stores your shortcuts, names, snippet content, folders, preferences, and paused website hostnames in Chrome extension storage. It uses Chrome Sync storage, which Google may synchronize through your Chrome profile when Sync is enabled. It also keeps a local recovery mirror. If Sync fails or exceeds its quota, the library stays in local storage on that device. ByteForth receives saved snippet content only when you explicitly use the optional Cloud Vault backup described below.
Chrome extension storage is not a password vault. Do not store passwords, payment credentials, or other secrets in snippets. Templates may contain personal information you choose to save.
Website interaction
On HTTP and HTTPS pages where Chrome allows the extension to run, a content script observes input in supported editable fields to recognize your shortcuts, read the text near the insertion point, and replace it with your chosen snippet. This processing happens in your browser. Ordinary expansion does not transmit typed text, page content, browsing history, or snippets to ByteForth. Password fields and recognizable payment and one-time-code fields are excluded.
The right-click “Save selection” command stores the text you explicitly select as a local draft until the editor opens. The popup reads the active page’s hostname to show site availability and offer pause/resume. Paused hostnames are saved as a preference.
Clipboard
Copy actions write a selected template to your clipboard. Reading the clipboard is optional and requires you to grant Chrome’s clipboard permission in Settings. Clipboard text is read only when expanding a template using {clipboard}, including a nested template that uses it. It is inserted into the destination field; the extension does not retain or send that clipboard text to ByteForth. You may remove clipboard access from Settings at any time.
Local usage
The extension keeps expansion counts by day and snippet, plus an estimated number of characters saved, locally on this device. It keeps up to 366 days of daily counters. It does not record the text you typed, pages where you expanded snippets, or destination field content in these counters. These statistics are not sent to ByteForth or an analytics provider.
Optional Pro billing
Free features do not require an account, payment, or a connection to ByteForth. When billing is enabled and you choose Pro, Chrome asks for access to the configured ByteForth billing service. The production service is https://text-expander.byteforth.com. Releases with billing disabled make no billing requests.
Payment takes place on a separate secure web page using Whop. Whop provides hosted checkout, payment processing and subscription management under its own privacy policy. ByteForth receives checkout, payment and membership identifiers, plan, Whop user identifier, and status from Whop. ByteForth may access customer billing information in its Whop merchant account for order support and applicable recordkeeping; card details are not stored in the extension.
The extension sends a random license credential to ByteForth’s service to start checkout, verify Pro access, or request a customer portal link. The service stores only a hash of that credential, checkout/payment/user/membership identifiers, plan, timestamps, checkout URL, and revocation status. The recovery credential is not included in checkout URLs or Whop metadata. The credential itself and an expiring entitlement are stored locally in the extension; they are not synced through Chrome Sync and are not exposed to website content scripts. Existing verified access can remain available offline for up to 24 hours, or until the paid period ends, whichever is sooner.
The billing service is designed to run on Cloudflare Workers and D1. Cloudflare and Whop process network requests and may process technical data such as IP addresses as their services require. The billing application uses a hashed IP-based rate-limit bucket retained for approximately two minutes; it does not intentionally log raw license credentials or payment details. Billing database records and webhook event identifiers are retained for subscription operation and support until deleted according to the publisher’s account-retention process and applicable recordkeeping obligations. Contact ByteForth to request access or deletion; payment records held by Whop may have separate retention requirements.
Google sign-in
You can sign in from Settings or the Pro page without purchasing. Google sign-in is required before starting a new Pro subscription; free text expansion does not require an account. The extension uses Chrome Identity to obtain a Google access token and sends it to ByteForth for verification with Google. ByteForth uses the verified Google subject identifier to associate your subscription, cloud backup, and AI allowance with your account. Your email and basic profile may be stored for display and support. The token and displayed profile are kept locally in the extension, not in Chrome Sync; signing out removes them and your local Pro session. Tokens are used only for identity verification, not to access your Gmail, Drive, or browsing history. Signing out does not delete your snippets or cancel your subscription.
Optional Cloud Vault and AI templates
Cloud Vault uploads the saved snippets you choose to back up, including their names, bodies, shortcut metadata, and usage counts, to ByteForth’s service on Cloudflare D1. This is a manual backup and restore feature. The service stores one current backup per authenticated account and replaces it on each backup. Data travels over HTTPS. The application does not provide end-to-end encryption; ByteForth’s authorized service operators can access stored backups. Do not back up sensitive secrets. Use the cloud-backup deletion control or contact support to remove a stored backup. Deleting local extension data or uninstalling does not delete the cloud backup.
When you request an AI template, the prompt you enter is sent to ByteForth and Cloudflare Workers AI for inference. The feature does not automatically upload your snippet library, clipboard, or the website you are editing. Review generated text before using it. The billing database stores your account’s monthly request count to enforce the 100-generation allowance; it does not store AI prompts or responses. Cloudflare processes the request under its own service privacy practices. The generated text is saved in your library only when you save the snippet.
Website links and support
Links to ByteForth are optional. Opening a link visits an external website governed by that site’s privacy practices. Some links include fixed campaign parameters identifying the extension as the source; they do not include a user identifier or snippet data. If you email support or submit a form on ByteForth’s site, you choose what information to provide. The extension itself does not submit leads or send messages on your behalf.
Your controls
You can edit or delete snippets, export JSON/CSV, pause expansion globally or per site, revoke optional permissions, and delete extension data in Settings. Deleting extension data removes the extension’s library, recovery copies, settings, drafts, usage counters, and locally saved license from this browser, and requests removal of library data from Chrome Sync. If storage deletion fails, the extension reports an error. Chrome’s synchronization and other devices may affect when a deletion reaches all devices.
Uninstalling removes this extension’s local browser storage. Exported backup files remain where you saved them. Removing a license, resetting, or uninstalling does not cancel a paid subscription or erase billing records: use the Whop customer portal or contact support.
Limited use and sharing
The extension does not sell user data, show ads, or transmit analytics. Information received from Google APIs is used in accordance with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only for the disclosed extension functionality, billing, security, and user-requested support; it is not used for advertising, creditworthiness, or unrelated profiling.
Changes
We will update this policy when data practices change. Material changes will also be disclosed in the extension or store listing as appropriate. For privacy questions, contact hello@byteforth.com.
