Skip to main content

Privacy Policy

Introduction​

This Privacy Policy describes how Tweak Technologies collects, uses, and protects your data when you use our Products. Your privacy matters to us. In this Privacy Policy:

  1. "Products" means our website https://tweak-extension.com, our browser extensions, and any other website or service we operate.
  2. "Browser extensions" means all of our browser extensions, currently available for Chrome, Microsoft Edge, and Firefox.

Collection of Information​

We use Google Analytics to collect information about how you use our Products. Google Analytics also collects information such as device type (mobile/desktop) and approximate geographic location. Our primary purpose in collecting analytics data is to track bugs and enhance the usability of our Products.

Analytics in our browser extensions​

Our browser extensions report usage events to Google Analytics. The following is the complete set of information they send, and it is deliberately short.

  • A pseudonymous identifier. A random identifier is generated on your device the first time the extension runs and is stored on your device. It is not derived from anything about you and cannot be used to identify you, but it does allow us to recognise that a series of events came from the same installation. Under the EU General Data Protection Regulation this makes the analytics stream personal data, which is why it is described here. Our legal basis is your consent, which you can withdraw at any time using the switches described below.
  • A non-reversible hash of your subscription identifier, sent only while you have an active paid Subscription, so that we can tell paid usage from free usage. This is a one-way SHA-256 digest: we send the digest and never the identifier itself. It stops being sent if your Subscription ends.
  • Your approximate country, derived on your device from your browser's time zone setting. We do not send your IP address for this purpose and Google Analytics does not derive your location from the request.
  • The extension version, your plan, and the events themselves: which features were used, and coarse size ranges (for example "5-11 rules") rather than exact figures. We do not send your browser's user-agent string.

No URL, request, response, or any other content from the traffic the extension intercepts is ever sent to us or to anyone else. Rules, mocks, payloads, headers, hooks and the addresses you match against stay on your device. Where the extension reports on a rule, it reports flags and fixed categories only (for example that a rule targeted a GraphQL endpoint, or that it used a response hook), never anything you typed.

You can turn this off. In the extension, open Settings > Privacy. "Share usage data" governs all usage reporting; "Report errors" governs error reports alone. Both are on by default and each can be turned off independently, at any time, without affecting any other functionality. Our Firefox extension contains no analytics code at all and reports nothing.

Data Security​

Our browser extensions do not store any application data (a.k.a. rules, a.k.a. mocks) on remote servers at any point in time. All such rules created by the user in our browser extensions are stored on the user's device only. We rely solely on the browser's storage capabilities to store your application data. We do not use storage.sync. All usage information that our Products collect is stored on Google's servers as part of Google Analytics.

Personal Information​

While using our Products, we may collect information that can be used to contact or identify you, as set out below.

Checkout. Your email address is collected during checkout. Payments are processed by our reseller partner Paddle, which acts as the merchant of record and processes payment data in accordance with its own privacy policy. We use your email address to verify with Paddle that you have an active Subscription, to send transactional messages relating to that Subscription, and to enable you to activate the Software on your device.

Sign-in. If you sign in using GitHub or Google, the relevant identity provider shares with us the email address associated with your account. We use it solely to authenticate you and to associate your sign-in with your active Subscription. We do not receive your password from these providers.

Fraud Prevention and License Enforcement​

To protect the integrity of our paid services and to enforce our Terms and Conditions, our End-User License Agreement, and our Acceptable Use Policy, we process a limited set of technical signals associated with your use of the Software and your Subscription. These signals may include:

  • IP Logging. IP addresses associated with your sessions and approximate geographic location derived from IP.
  • Device Fingerprinting. Device and browser type, version, and configuration signals that, taken together, form a non-unique fingerprint used to recognize repeat installations.
  • Session Telemetry. Login and session timestamps, the number and pattern of concurrent or sequential active sessions, and the number of distinct installations associated with a single license key or account.
  • Device Identifier. From 1st November 2026, a random identifier generated when you sign in to a paid Subscription, stored by the extension and linked to that Subscription. It is used to count the Devices on which your Subscription is active and how often it moves between them, as limited by our Terms and Conditions. It is separate from the pseudonymous analytics identifier described above and is never sent to Google Analytics.

We use this information solely to detect and prevent unauthorized sharing of account credentials or license keys, use of a single Subscription by more than one individual or on more than one Device, circumvention of seat, Device or licensing limits, and other forms of fraud, abuse, or breach of our terms. We do not use it for advertising, for behavioural profiling unrelated to license enforcement, or for sale to third parties.

Where we are subject to the EU General Data Protection Regulation or equivalent laws, the legal basis for this processing is, for users with an active Subscription, the performance of our contract with you (Article 6(1)(b) GDPR), specifically our right and obligation to enforce the terms of that Subscription. For users without an active Subscription, and to the extent processing goes beyond what is strictly necessary for contract performance, the legal basis is our legitimate interest in protecting our paid services, our customers, and our business from abuse and fraud (Article 6(1)(f) GDPR), balanced against your privacy rights. We retain this information only for as long as is necessary for these purposes. You may contact us at [email protected] to exercise any rights you may have over this data under applicable law.

Cookies​

Like many websites, we and our partners, affiliates, analytics, and service providers use "cookies" to collect information. A cookie is a small data file that we transfer to your computer's hard disk for record-keeping purposes. We use both persistent cookies that remain on your computer or similar device (such as Google Analytics related cookies) and session ID cookies, which expire at the end of your browser session (for example, to activate a Subscription in your current browser).

Embedded Scripts​

We and our partners, affiliates, analytics, and service providers may also employ software technology known as Embedded Scripts. An Embedded Script is code that is designed to collect information about your interactions with our Products, such as the links you click on. The code is temporarily downloaded onto your computer or other device and is deactivated or deleted when you disconnect from our Products.

Data Retention​

We retain personal information only for as long as necessary for the purposes for which it was collected. Subscription and account records are retained for the duration of your Subscription and for a reasonable period thereafter to comply with our legal, accounting, and tax obligations. Information collected for fraud prevention and abuse detection is retained for the period necessary to investigate, prevent, and act on abuse, and is deleted thereafter unless we are required to retain it longer by law.

Your Rights​

Depending on your jurisdiction, you may have rights in relation to your personal information, including the right to access, correct, delete, restrict, or object to processing, the right to data portability, and the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at [email protected]. We will respond within the time limits required by applicable law.

Changes and updates to this policy​

Tweak Technologies reserves the right to change this policy. If a change is material, Tweak Technologies will provide at least thirty (30) days' notice prior to the new policy taking effect, by in-app notification, by email to the address linked to your Subscription, or by a prominent notice on https://tweak-extension.com. Non-material changes (for example, formatting, typographical corrections, or clarifications that do not adversely affect your rights) may be made at any time. Each time this policy is changed we will revise the "Effective date" at the bottom of this page. Continued use of the Products after the effective date of any change constitutes your acceptance of the revised policy.

Contact​

If you have any further questions regarding this policy, you may contact us by sending an email to [email protected].


Effective date: 1st November 2026