◆ refract seo

Ships inside the extension and works offline. Help

Privacy policy — Refract SEO

Effective: 8 October 2026 · Extension version: 0.4.0 · Owner: Sharaj Rewoo

The short version

Refract SEO has no account, no analytics, no server and no user database. We do not collect, transmit or store your browsing data, and there is no mechanism in the extension by which we could — there is nowhere for it to go.

Version 0.4 adds optional connectors, each off until you turn it on:

Each connector talks only to the service it names, and each says on its settings card exactly what it sends. Every one of them can be switched off at once, by you or by your organisation's policy, with local-only mode.

A default audit makes zero network requests. You can verify that yourself: open DevTools, switch to the Network panel, and run an audit.

Everything below exists because "we don't collect data" is a claim that needs an itemised list behind it, including the parts that are inconvenient for us.

Every network request this extension can make

There are four without connectors, plus one row per connector you choose to connect. They are all listed here, and every one except the uninstall page only happens because you asked for something specific. Nothing on this list sends your data to us, and none of them goes to an AI provider — the generative features run on your own machine and there is no longer any way to configure otherwise.

WhenWhere the request goesWhat it containsWho sees it
You grant site access and run an auditThe site you are auditingA request for that page as each of six crawler user-agents, plus its robots.txt, llms.txt, sitemap.xml, indexnow.txt, and a HEAD request for its headers. Sent with no cookies.The site you were already visiting
You press Crawl this siteThe site you are auditingIts sitemap.xml, then up to 300 page requests — same origin only, obeying that site's robots.txt, four at a time, twenty per minute, stopping if the site asks us toSame site
You connect Google Search Console (optional)Google (www.googleapis.com, searchconsole.googleapis.com)Your Google sign-in token; then the list of your Search Console properties; once a day while Chrome is open, your property's daily totals and per-page totals; when you open In Google, the URL of the page you are auditing; when you press Check index state, that URLGoogle, which already holds this data. Results are stored only on your machine
You track a site (Monitor, daily while Chrome is open, only for sites you granted access to)The site you trackIts home page and the key pages you list, fetched as Googlebot would (no cookies), plus robots.txt and sitemap.xmlThe site you track
You start a Site audit or List mode in the WorkspaceThe site you audit, or the URLs you pastedSame as Crawl this site: obeys robots.txt and Retry-After, one request a second (up to five for a site Search Console says you own), no cookies, capped at 25,000 pagesThose sites
You open Core Web Vitals or a tracked project's weekly check runsGoogle PageSpeed Insights (www.googleapis.com)The public URL of the page, and your API key if you added oneGoogle, which then loads that public URL to test it
You connect Google Analytics 4 (optional)Google (analyticsadmin.googleapis.com, analyticsdata.googleapis.com)Your sign-in token; the list of your GA4 properties; then the chosen property id and a date range, for organic sessions and key events by landing pageGoogle, which already holds this data
You press Export to Sheets (optional)Google Sheets (sheets.googleapis.com)The rows of the table you exported, into a new spreadsheet in your Drive, using the drive.file scope (Refract sees only the files it creates)Google, as a file in your Drive
You press Export to Google Docs on a brief (optional)Google Drive (www.googleapis.com)The brief as you edited it (headings, questions, terms, notes) and its title, converted to a new Google Doc, same drive.file scopeGoogle, as a file in your Drive
You add a Slack or Teams webhook (optional)Slack or Microsoft (hooks.slack.com, *.webhook.office.com, *.logic.azure.com)Alert text written by Refract: the kind of alert, a URL and numbers. Never page content or queriesYour Slack or Teams channel
Once a day while Chrome is open, unless local-only mode is onGoogle Search Status (status.search.google.com)A plain request for the public incident list; nothing about you or your sitesGoogle, as an ordinary page view
You add SEO news feeds (optional), then once a day while Chrome is openThe sites publishing those feeds (each asked for when you add it)A plain request for the feed; nothing about you or your sitesThose sites
You switch on a remote AI model for a task (optional, per task; see also the provider rows below)Anthropic (api.anthropic.com) with your key, or Refract Credits (credits.refract.seo)The task's prompt and only the facts it needs (for example a query list and numbers, or headings from the pages a brief compares) — never cookies, never your other browsing. The cost is shown firstAnthropic, or the Credits relay, which forwards it to Anthropic and logs counts only, never content
You use Refract Credits (optional)Refract Credits relay (credits.refract.seo)Your account token, and the request you asked for (AI or DataForSEO)Refract: request counts and credit balance only; the relay does not store prompts or results
You run keyword research, enrichment or paid Rankings (optional, cost shown first)DataForSEO (api.dataforseo.com)Your keywords and seed terms, your market, and competitor domains you trackDataForSEO
You connect Bing Webmaster Tools (optional)Microsoft (ssl.bing.com)Your API key and site URLMicrosoft, which already holds this data
You push a ticket (optional)Jira (your *.atlassian.net site), Linear (api.linear.app) or GitHub (api.github.com)The ticket: title, why it matters, measured numbers, the page URL and any fix snippetYour tracker
You press SERP Lens on a Google results tab you openedNothing is sent: the panel reads the page already in your tab——
You build a brief, content gap or quality checkThe sites ranking in the results you captured (organic results only)A plain request for each page, no cookies, obeying their robots.txt and the same rate limits as a crawl; cached for 24 hours on this machineThose sites
You track competitors (optional)Your competitors' sites (each asked for when you add it)Their home page, the pages you list and their sitemap, as Googlebot would request them, obeying their robots.txt, once a day while Chrome is openThose sites
You add a second Google account (optional)Google (accounts.google.com, oauth2.googleapis.com)A sign-in window for the account you choose; then the short-lived token, to confirm it was issued to Refract and to learn the account's email and granted permissions. Before that account's scheduled jobs, a silent re-sign-in (no window)Google. Refract keeps the email and permissions on this machine; tokens stay in memory and are never written to disk or exported
You use GA4 full or scheduled reports (optional)Google (analyticsdata.googleapis.com) with the project's Google accountThe property id and date ranges, for sessions, engaged sessions, key events and revenue by landing page and by channelGoogle, which already holds this data. Reports are stored on this machine (last 12 per project)
A scheduled report's AI executive summary (optional, per task)Anthropic or Refract Credits, as for any remote AI taskThe report's measured numbers only; nothing is exported until you approve the summaryAs for remote AI
You import a backlink CSV or check a disavow fileNothing is sent: read and written on this machine——
You press Pull Bing inbound links, or weekly once Bing is connectedMicrosoft (ssl.bing.com)Your API key, your site URL and the URLs of your top linked pagesMicrosoft, which already holds this data
You opt in and press Pull DataForSEO backlinks (cost shown first)DataForSEO (api.dataforseo.com) or the Credits relayYour domain or a competitor domain you saved, and a row limitDataForSEO
You press Re-check on backlink-loss alerts, or Check URLs in Broken linksThe linking pages' sites, or competitor and industry sites in your link data (asked for on the click)A plain request (HEAD, or GET if refused) for up to 50 linking pages or 200 URLs, no cookiesThose sites
You analyse a server logNothing about the log is sent: it is read on this machine and only totals are kept. After you press Fetch crawler IP lists, at most weekly: Google (developers.google.com) and Microsoft (www.bing.com)A plain request for their public crawler IP listsGoogle and Microsoft, as ordinary page views
You schedule or run a GEO prompt set (optional, price shown first)Anthropic (api.anthropic.com), Perplexity (api.perplexity.ai), OpenAI (api.openai.com, with store: false) or Google Gemini (generativelanguage.googleapis.com), with your keyThe prompts in that set, verbatimEach provider, under its API data policy. Refract keeps the answer text (first 2,000 characters) and cited URLs, last 12 runs
You add a CrUX API key (optional), then weeklyGoogle (chromeuxreport.googleapis.com)Your key, your project's origins and up to 10 key page URLsGoogle, which publishes this data
You connect a CMS and apply a fix (optional, one approved change per click)Your WordPress site (/wp-json), Shopify (<shop>.myshopify.com) or Webflow (api.webflow.com)Your credentials for that CMS, the page or product identifier, and the new title, meta description or alt text you approvedYour CMS. Credentials are stored on this machine per project, never exported or logged
You Verify a CMS changeYour own siteOne request for the changed page with a cache-busting parameter, no cookiesYour site
You press Rendered sample in Site auditYour own site (a project you crawled)Up to 60 of its pages (3 per template), each loaded in a background tab with your normal browser session, one at a time at the project's crawl rate, then closedYour site. Refract keeps only the compared facts (title, canonical, robots, H1, link and word counts), never the HTML
You use a remote AI model for a task (optional, per task; price shown first)The provider your route picks: Anthropic, OpenAI (api.openai.com), Google Gemini (generativelanguage.googleapis.com), OpenRouter (openrouter.ai, then the model provider it routes to), Portkey (api.portkey.ai or your https gateway, then its provider), an https OpenAI-compatible endpoint you added, or Refract CreditsThe task's prompt and only the facts it needs; your key for that provider; OpenRouter also receives X-Title: Refract SEO, never a user idThat provider (and, through a gateway, the model provider it routes to) under its API data policy. Refract keeps the answer and its cost on this machine
You press Test connection on an AI provider, or open Settings → AI (at most once a day)That provider's model list (GET /models)Your key for that providerThat provider
A task runs on a local model or Chrome's built-in modelNothing leaves this computer: a server on localhost, 127.0.0.1 or [::1], or Chrome itself——
You look for unlinked brand mentions (Outreach)The pages in your search results (≤ 50 per click, asked for in one prompt), or DataForSEO if you use its search (price shown first)A plain page request with no cookies; for DataForSEO, the search text and your marketThose sites, as page views; DataForSEO. Refract keeps only the pages you add as prospects (URL, title, a short snippet)
You press Draft now on an outreach prospect (optional, price shown first)The AI provider your route picks, as aboveThe prospect page's URL, title and mention snippet, your page's URL and title, your project name. Never an email addressAs for remote AI. Refract never sends the email: you copy it or open your mail app
You press Re-check for the link on a won prospectThat prospect's siteA plain page request with no cookiesThat site
You turn on hourly key-page checks (optional, per project)Your own siteThe home page and up to 20 key pages, no cookies, through the same rate limiter as Monitor, hourly while Chrome is openYour site
You connect Microsoft Clarity (optional, per project), then once a dayMicrosoft (www.clarity.ms)Your Clarity Data Export token, asking for the last day of UX metrics by pageMicrosoft, which already holds this data. Refract keeps 28 days of per-page counts on this machine
You uninstall the extensionrefract.seo/uninstallNothing we attach. Chrome opens a page, so our web host sees a normal web visit: an IP address, a timestamp and a user-agentUs, as ordinary web-server logs

That last row is the one worth reading twice. chrome.runtime.setUninstallURL opens a web page when you remove the extension, which means our web server logs a visit the way any web server does. It is the only signal we ever receive about anyone, we cannot connect it to anything you did, and it is not tied to an identifier. If you would rather not send it, close the tab before it loads — or disable the extension instead of uninstalling it. We are telling you because a policy that omitted this would be inaccurate.

AI runs on your machine unless you choose otherwise. Chrome's built-in model is the default. A remote model (your own Anthropic key, or Refract Credits) is off for every task until you switch it on for that task, shows its estimated cost first, and every number in its answer is checked against the data it was given before you see it. If your hardware cannot run the built-in model, the extension keeps working: every finding, every measurement and every mechanical fix is deterministic and needs no model at all.

Google API Services User Data Policy — Limited Use

This applies to every Google API Refract can use (Search Console, Analytics, Sheets, Docs export, PageSpeed Insights). Refract SEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Search Console data is read with the read-only scope webmasters.readonly, used only to show you your own data and to rank findings by the traffic they affect, stored only on your machine, never transferred to anyone, never used for advertising, and never read by a human at Refract. Disconnect in Settings, or delete it with Delete v4 data.

Local-only mode

One switch in Settings (or your organisation's policy) stops every connector and every request Refract would make without you asking: Search Console, Analytics, PageSpeed, Sheets, webhooks, the status feed, Monitor's daily checks and v3's scheduled Watch. Audits and crawls you start yourself still run, exactly as before.

What is stored, where, and for how long

All of it is in your browser profile, on your machine. None of it is synchronised to any account — we deliberately use chrome.storage.local and never chrome.storage.sync, because sync would replicate your data through Google's servers.

WhatWhereContainsRemoving it
Audit historyIndexedDB, last 20 route templatesRule IDs, a date, an origin and a route shape. Never page content, never a URL with a query string.Settings → Clear history, or clear site data
Framework overrideschrome.storage.localOrigin → framework nameClear site data
Muted ruleschrome.storage.localRule IDs you chose to silenceSettings → Unmute
Usage counterschrome.storage.localCounts of things you did. Never transmittedSettings → Reset
A site crawlchrome.storage.local, per origin, expires after 7 daysOnly if you pressed Crawl: for each page reached, its URL, title, description, canonical, robots directive, outgoing internal links and declared hreflang alternates. Never page content.Settings → Forget per site, or Forget every crawl

The site crawl, specifically

This is the one feature that stores anything beyond the page in front of you, so it deserves saying plainly.

Nothing is stored unless you press Crawl. An earlier version of this extension kept a per-origin model of every site you browsed, growing with each audit — that is a private analytics store, it is a different product from an audit tool, and it was removed. There is no consent list to maintain now because there is nothing accumulating to consent to.

One press produces one crawl of one origin. It is replaced by the next press, deleted on request, and expires by itself after seven days — a month-old crawl answers questions about a site that has since changed, with the confidence of a fresh measurement.

The crawl exists because the questions people actually ask — is anything unreachable, do two pages share a title, do my hreflang tags point back — are questions about a set of pages. A single page cannot answer them, and neither can a sample: sampling five pages of four hundred finds a duplicate pair almost never and then reports that there are none. When a crawl stops early, every answer that depends on having seen the whole set is withheld rather than guessed.

Files you export — the baseline, the report, a ticket — are written by your browser to your downloads folder. They are never uploaded. The extension does not hold the downloads permission; it hands your browser a local file the same way any web page offers a download. The baseline deliberately contains rule IDs and digests only, because it is designed to be committed to a shared repository.

What v4 adds on this machine (IndexedDB database refract-v4)

WhatKept for
Projects (origins, Search Console property, segments, brand terms, key pages, keywords, crawl settings)Until you delete the project
Search Console daily totals per propertyIndefinitely, so your history outgrows Google's 16 months; deleted with Delete v4 data
Search Console per-page totals and the CTR curveReplaced by each daily sync
Cached Search Console responsesRemoved after a day
Site audit v2 crawls (per-page facts: status, title, canonical, links, word count — never page text)Until you delete them or Delete v4 data
Latest audit findings per page (rule ids, messages, measured values)Replaced by the next audit; at most 200 pages per site
Events, alerts, annotations, investigations, the fix ledger, job logInvestigations: last 30; job log: last 200; the rest until Delete v4 data
API keys and webhook URLs you addUntil you remove them; never logged, never exported

What we never do

Permissions, and why each one exists

Chrome shows you a permission list. Here is what each entry is actually for.

PermissionWhy
activeTabRead the page you invoked Refract on. Granted per click, not standing.
scriptingInject the page reader into that tab on demand, rather than running on every page you visit
storageThe settings and history above
sidePanelThe panel is the product's interface
offscreenMeasure text width on a canvas, and host the on-device model session
declarativeNetRequestWithHostAccessSet a crawler user-agent on our own request while checking what a crawler receives. Scoped to one URL, for one request, then removed
tabsKnow which tab the panel belongs to, and clear its audit when it closes
Site access (optional)Requested only when you use a crawler check. Decline it and everything else still works — those checks report as not evaluated rather than counted as passing
unlimitedStorageYour Search Console history and projects, kept on your machine, can outgrow the default local storage quota. No warning is shown for it and it grants no access to anything
identity (optional)Requested only when you press Connect Search Console, to sign in with your Chrome profile's Google account. Never requested at install
notifications (optional)Requested only if you switch on Tell me when something breaks. Never requested at install. Decline it and the toolbar badge still shows the count

We do not request the debugger permission, and we do not request standing access to all sites.

We also do not request downloads, which an earlier version did. It bought a "save as" dialog and cost a permission a reviewer has to be talked through; an ordinary link does the same job with no permission at all. A permission that is merely convenient is one we should not be asking for.

Children

Refract SEO is a developer tool. It is not directed at children and collects no personal information from anyone, of any age.

Your rights

Because we hold no data about you, there is nothing for us to disclose, correct, export or delete on your behalf — the delete controls are in the extension, and they operate on your own machine. If you are exercising a right under GDPR, the CCPA or a comparable law and want that confirmed in writing, contact us below and we will confirm it.

Third parties

None, unless you connect one. API keys and webhook URLs you add are stored only in this browser's extension storage, are never logged, and are sent only to the service they belong to. No AI provider, no analytics vendor, no CDN, no error reporter, no font host. Without connectors, the only servers this extension talks to are the site you are auditing and, once, our own uninstall page. If you connect Search Console, Google is a third party for that connector only, as listed in the table above.

An earlier version supported bringing your own AI provider key, and this section described that relationship. That tier was removed, so the section describes nothing.

Changes

Material changes are announced in the extension's changelog and this page's effective date is updated. If a change ever introduced data collection, it would be opt-in and announced before it shipped, not buried here.

Who is responsible

A privacy policy with no named accountable owner is not a policy, and the store listing links to this page.

The rule catalogue has its own named owner, recorded in rules/OWNER in the repository, because a dated "last verified" on every rule is a claim somebody has to keep true.