Chrome Web Store disclosure template · Effective August 7, 2026
Extension privacy
Template requiring professional legal review and Chrome Web Store review. The final disclosure and Developer Dashboard answers must exactly match the released extension package.
Single purpose
The single purpose of the Scrollsmith extension is to let users change the appearance of native website scrollbars and save related appearance preferences. It does not replace native scrolling or provide unrelated advertising, search, content analysis, or page-modification features.
Data handled by the extension
- Appearance settings: theme, width, radius, colors, opacity, glow, motion, enabled state, and reduced-motion choices.
- Hostname settings: the hostname currently shown in the active tab when you open the popup, hostnames you disable, and per-site presets you deliberately save.
- Account data: user ID, email address, current plan, allowed feature and theme IDs, and opaque short-lived or rotating session credentials.
- Operational status: whether entitlement verification succeeded, expired, is offline, or is unavailable.
Data the extension is designed not to collect
- Webpage text, images, forms, messages, or other page content.
- General browsing history or a server-side log of sites visited.
- Passwords, keystrokes, clipboard contents, or third-party authentication tokens.
- Payment-card numbers, card security codes, or bank credentials.
- Location, health, financial-credit, or advertising-profile information.
Local versus transmitted information
Appearance settings, disabled hostnames, and per-site presets are stored locally in Chrome extension storage. The current implementation does not transmit those hostnames to usescrollsmith.com. Account login, session refresh, and entitlement requests are transmitted to the official usescrollsmith.com API over HTTPS. Those requests contain account credentials issued for the extension and the extension ID, not webpage content.
Permissions
| Permission | Reason |
|---|---|
| storage | Remember scrollbar settings and securely maintain the opaque extension account session between browser sessions. |
| identity | Open the official website sign-in flow and return a short-lived login code to the extension. |
| alarms | Periodically refresh entitlement status without continuous background activity. |
| HTTP/HTTPS site access | Apply packaged scrollbar styles to ordinary webpages and identify the current hostname locally for user-controlled exclusions and presets. The content script does not read or transmit page content. |
| https://usescrollsmith.com/* | Authenticate the account, verify entitlements, and open official account and billing pages. |
Premium verification
Premium themes unlock only after the official server confirms an authenticated user's current entitlement. Offline, expired, canceled, malformed, or unavailable responses fail closed to the three Free themes. The extension does not trust a success page or local Premium flag.
Sharing and sale
We do not sell extension data, use it for personalized advertising, or transfer it to data brokers. Account information may be processed by Supabase and hosting providers to operate authentication and entitlement services. Billing occurs on Stripe-controlled pages; the extension does not collect card information.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is limited to the extension's disclosed single purpose, related security, account access, reliability, and legal obligations.
Disclosure before sign-in
Before optional sign-in begins, the extension explains that it will send its extension ID and a one-time sign-in proof to usescrollsmith.com. After sign-in, the extension stores the account ID, email address, and opaque session credentials in protected extension storage to maintain the session and verify Premium access. Appearance settings, disabled hostnames, and per-site presets remain local and are not transmitted to Scrollsmith.
Security and code
Operational JavaScript and CSS are packaged with the Manifest V3 extension. The extension does not download or execute remote JavaScript, use eval, or request history, cookie, webRequest, or payment permissions. No security system is perfect; users should keep Chrome and the extension updated and protect access to their device and email account.
Deletion
Use Reset to clear appearance settings, remove individual website presets, sign out to revoke the account session, or uninstall the extension to remove its local installation data. Deleting local extension data does not automatically delete the website account or Stripe records. See Data Deletion Instructions.
Contact
Extension privacy questions: hello@usescrollsmith.com
Individual owner of Scrollsmith · usescrollsmith.com