Policy
Privacy
Effective [PLACEHOLDER: Effective date]
This policy covers the Typist Chrome extension and this website.
Typist is operated by [PLACEHOLDER: Developer or company name]. For any privacy question, or to ask for your data to be deleted, write to hamptonyeh@gmail.com. This site is published at [PLACEHOLDER: Deployed site URL, e.g. https://typist.example].
The short version
- The text you type or paste into Typist stays in your browser. It is never sent to our server, with one exception you control: snippets you deliberately save.
- When you press Start, the server is told how many words the run needs and is given a random id for that run. Never the words themselves.
- We keep a small record of each run — counts, dates, times and that random id. No text, no page address, no page title.
- We do not sell data, we do not run ad targeting, and we do not collect your browsing history.
What stays on your device
- The text you are typing
- Whatever is in the side panel's text box lives in your browser and is sent to the page you are typing into. It is not transmitted to our server, and it is not sent anywhere else.
- A fingerprint of the text
- When you press Start, the panel stores a SHA-256 digest of the text — a one-way fingerprint, a fixed string of hex worked out from the text rather than the text itself. It is there so a reservation you have already been charged for can be matched back to the text it was made for: press Start again on the same text, even after the panel has been closed and reopened, and the server recognises the same run instead of charging your allowance twice. The fingerprint is kept in the browser's local extension storage and is never sent to our server — a reservation carries the word count and the random run id, nothing else. It is replaced when you press Start on different text, and cleared when the run starts, when the reservation turns out to be for no words, when your account becomes Pro, and when you sign out. A fingerprint is not the text and the text cannot be read back out of it, but it is worked out from the text: anyone holding both the fingerprint and a guess at a short text could check one against the other.
- The page you are on
- Our server never receives the address of the page, its contents, or the fact that you used Typist on it. The extension works on the tab you are looking at only while a run is happening.
- Your settings
- Words per minute and the other panel settings are stored locally by the browser.
- Your clipboard
- The panel's paste button reads the clipboard at the moment you click it, and puts what it finds into the text box on your screen. Nothing is transmitted.
What the server receives and stores
- Your Google account email and account identifier
- When you sign in with Google, we ask for the narrowest sign-in permission there is: enough to learn Google's subject identifier for the account and the verified email address on it. That is all Google sends us. We do not receive your name, your profile photo, or anything else from your Google profile. We do not receive your Google password, and we do not request access to any other Google service. We use the identifier and the email to identify your account, to keep your snippets attached to it, and to know which plan you are on.
- A word count and a run id
- When you press Start, the extension sends the number of words the run needs and a random id it generates for that run. The count is there so the daily allowance can be counted; the id is there so a Start retried after a dropped connection is not charged twice. The words themselves are not sent, and the run id is a fresh random string with nothing in it.
- One record per run
- A run that is granted words leaves a row on our server: the run id, how many words were granted, the UTC date, which allowance the run counted against, and the time the row was written. So this is a timestamped record of when you pressed Start and how large the run was, not a daily figure alone — the daily total the panel shows is added up from these rows. The row holds no text, no page address, and no page title. A run that is granted no words leaves nothing behind.
- Snippets you save
- If you press save on a snippet, its title and text are stored on our server so the snippet appears on your other signed-in devices. This is the only way your text reaches us, and it only happens when you ask for it. Deleting a snippet in the panel deletes it from the server.
- Subscription state
- If you subscribe, we store the customer and subscription identifiers Stripe gives us, the status of the subscription, and when the current period ends.
- A sign-in token
- Signing in creates a session token which the extension keeps in Chrome's local extension storage and sends back with each request. It is not a cookie, and this website does not set cookies of any kind.
Payments
Payments are processed by Stripe. Card numbers, billing details, and anything else you type into Stripe's checkout go to Stripe, not to us — we never see or store card details. Stripe tells our server whether a subscription is active, and that is what grants Pro. Stripe handles that data under its own privacy policy.
What we do not do
- We do not sell or rent your data to anyone.
- We do not use your data for advertising or ad targeting.
- We do not collect your browsing history or a list of sites you visit.
- We run no analytics, trackers, or third-party scripts — not in the extension and not on this site. This site loads nothing from anywhere but its own domain.
How long we keep things
Account details, snippets, and subscription state are kept while your account exists. The per-run records described above, and the daily totals derived from them, are kept for [PLACEHOLDER: Retention period for usage records, e.g. 90 days] from the day of the run, after which the rows for that day are removed. Ask us to delete your account at hamptonyeh@gmail.com and we will remove your account, snippets, daily totals, and every per-run record within [PLACEHOLDER: Deletion turnaround, e.g. 30 days]. Stripe keeps its own payment records for as long as its obligations require.
Your choices
You can delete any snippet from the side panel, sign out to remove the session from that browser, uninstall the extension at any time, and email us to delete the account altogether. If your local law gives you rights to access, correct, export, or erase your data, write to the address above and we will act on it.
Changes
If this policy changes, the effective date at the top changes with it, and material changes will be noted on this page.
Contact
[PLACEHOLDER: Developer or company name] · hamptonyeh@gmail.com · [PLACEHOLDER: Postal address, if your jurisdiction requires one]