Privacy Policy

Chrome Sync

Effective Date: July 23, 2026

1. Overview

Chrome Sync is a private, production-ready browser extension and sync server designed for syncing bookmarks, open tabs, and installed extension lists across Chromium browser profiles.

Privacy is guaranteed by design through client-side end-to-end encryption (E2EE). The sync server acts strictly as an opaque storage relay and cannot read your bookmark titles, tab URLs, extension lists, or profile names.

2. Information Handled & Encryption Matrix

The table below summarizes all data types processed by Chrome Sync and how they are secured:

Data Category Content Details Client Storage Server Storage State
Tab Snapshots Open tab titles, URLs, favicons, pinned state Local Extension State AES-GCM Encrypted
Extension List Installed extension names, IDs, versions, status Local Extension State AES-GCM Encrypted
Bookmark Data Bookmark titles, URLs, and folder structures Local Chrome Storage AES-GCM Encrypted
Profile Names Custom browser profile labels (e.g. Work/Personal) Local Settings AES-GCM Encrypted
Access Token Authentication credential (`cs_...`) Local Extension Storage SHA-256 Hashed Only
Sync Passphrase Master secret key for encryption Local Extension Storage Never Sent to Server

3. End-to-End Encryption Architecture

Before any sync payload leaves your browser, Chrome Sync encrypts it locally using your secret passphrase:

Because encryption occurs exclusively on your device, server operators cannot decrypt your data. If you lose your sync passphrase, server data cannot be recovered by anyone.

4. Data Retention & Automatic Cleanup

Chrome Sync implements strict data minimization:

5. Third-Party Sharing & Compliance

6. Contact & Support

For privacy inquiries, security concerns, or account deletion requests, please contact the Chrome Sync maintainer via affan.dev.