Privacy policy — Refract SEO
Effective: 8 October 2026 · Extension version: 0.4.0 · Owner: Sharaj Rewoo
The short version
Refract SEO has no account, no analytics, no server and no user database. We do not collect, transmit or store your browsing data, and there is no mechanism in the extension by which we could — there is nowhere for it to go.
Version 0.4 adds optional connectors, each off until you turn it on:
- Google: Search Console, Analytics 4, Sheets and Docs export, PageSpeed Insights, Chrome UX Report History, the Google Search Status feed, and extra Google accounts.
- Paid data: DataForSEO, and Refract Credits for using it without your own key.
- AI models you choose: Anthropic, OpenAI, Gemini, OpenRouter, Portkey, any OpenAI-compatible endpoint, or a model on this computer (Chrome's built-in model, Ollama, LM Studio). Models on this computer send nothing anywhere.
- Answer engines for AI citation tracking: Anthropic, Perplexity, OpenAI and Gemini.
- Everything else: Bing Webmaster Tools, Microsoft Clarity, Slack/Teams webhooks, SEO news feeds, Jira/Linear/GitHub for tickets, and WordPress/Shopify/Webflow for applying fixes.
Each connector talks only to the service it names, and each says on its settings card exactly what it sends. Every one of them can be switched off at once, by you or by your organisation's policy, with local-only mode.
A default audit makes zero network requests. You can verify that yourself: open DevTools, switch to the Network panel, and run an audit.
Everything below exists because "we don't collect data" is a claim that needs an itemised list behind it, including the parts that are inconvenient for us.
Every network request this extension can make
There are four without connectors, plus one row per connector you choose to connect. They are all listed here, and every one except the uninstall page only happens because you asked for something specific. Nothing on this list sends your data to us, and none of them goes to an AI provider — the generative features run on your own machine and there is no longer any way to configure otherwise.
| When | Where the request goes | What it contains | Who sees it |
|---|---|---|---|
| You grant site access and run an audit | The site you are auditing | A request for that page as each of six crawler user-agents, plus its robots.txt, llms.txt, sitemap.xml, indexnow.txt, and a HEAD request for its headers. Sent with no cookies. | The site you were already visiting |
| You press Crawl this site | The site you are auditing | Its sitemap.xml, then up to 300 page requests — same origin only, obeying that site's robots.txt, four at a time, twenty per minute, stopping if the site asks us to | Same site |
| You connect Google Search Console (optional) | Google (www.googleapis.com, searchconsole.googleapis.com) | Your Google sign-in token; then the list of your Search Console properties; once a day while Chrome is open, your property's daily totals and per-page totals; when you open In Google, the URL of the page you are auditing; when you press Check index state, that URL | Google, which already holds this data. Results are stored only on your machine |
| You track a site (Monitor, daily while Chrome is open, only for sites you granted access to) | The site you track | Its home page and the key pages you list, fetched as Googlebot would (no cookies), plus robots.txt and sitemap.xml | The site you track |
| You start a Site audit or List mode in the Workspace | The site you audit, or the URLs you pasted | Same as Crawl this site: obeys robots.txt and Retry-After, one request a second (up to five for a site Search Console says you own), no cookies, capped at 25,000 pages | Those sites |
| You open Core Web Vitals or a tracked project's weekly check runs | Google PageSpeed Insights (www.googleapis.com) | The public URL of the page, and your API key if you added one | Google, which then loads that public URL to test it |
| You connect Google Analytics 4 (optional) | Google (analyticsadmin.googleapis.com, analyticsdata.googleapis.com) | Your sign-in token; the list of your GA4 properties; then the chosen property id and a date range, for organic sessions and key events by landing page | Google, which already holds this data |
| You press Export to Sheets (optional) | Google Sheets (sheets.googleapis.com) | The rows of the table you exported, into a new spreadsheet in your Drive, using the drive.file scope (Refract sees only the files it creates) | Google, as a file in your Drive |
| You press Export to Google Docs on a brief (optional) | Google Drive (www.googleapis.com) | The brief as you edited it (headings, questions, terms, notes) and its title, converted to a new Google Doc, same drive.file scope | Google, as a file in your Drive |
| You add a Slack or Teams webhook (optional) | Slack or Microsoft (hooks.slack.com, *.webhook.office.com, *.logic.azure.com) | Alert text written by Refract: the kind of alert, a URL and numbers. Never page content or queries | Your Slack or Teams channel |
| Once a day while Chrome is open, unless local-only mode is on | Google Search Status (status.search.google.com) | A plain request for the public incident list; nothing about you or your sites | Google, as an ordinary page view |
| You add SEO news feeds (optional), then once a day while Chrome is open | The sites publishing those feeds (each asked for when you add it) | A plain request for the feed; nothing about you or your sites | Those sites |
| You switch on a remote AI model for a task (optional, per task; see also the provider rows below) | Anthropic (api.anthropic.com) with your key, or Refract Credits (credits.refract.seo) | The task's prompt and only the facts it needs (for example a query list and numbers, or headings from the pages a brief compares) — never cookies, never your other browsing. The cost is shown first | Anthropic, or the Credits relay, which forwards it to Anthropic and logs counts only, never content |
| You use Refract Credits (optional) | Refract Credits relay (credits.refract.seo) | Your account token, and the request you asked for (AI or DataForSEO) | Refract: request counts and credit balance only; the relay does not store prompts or results |
| You run keyword research, enrichment or paid Rankings (optional, cost shown first) | DataForSEO (api.dataforseo.com) | Your keywords and seed terms, your market, and competitor domains you track | DataForSEO |
| You connect Bing Webmaster Tools (optional) | Microsoft (ssl.bing.com) | Your API key and site URL | Microsoft, which already holds this data |
| You push a ticket (optional) | Jira (your *.atlassian.net site), Linear (api.linear.app) or GitHub (api.github.com) | The ticket: title, why it matters, measured numbers, the page URL and any fix snippet | Your tracker |
| You press SERP Lens on a Google results tab you opened | Nothing is sent: the panel reads the page already in your tab | — | — |
| You build a brief, content gap or quality check | The sites ranking in the results you captured (organic results only) | A plain request for each page, no cookies, obeying their robots.txt and the same rate limits as a crawl; cached for 24 hours on this machine | Those sites |
| You track competitors (optional) | Your competitors' sites (each asked for when you add it) | Their home page, the pages you list and their sitemap, as Googlebot would request them, obeying their robots.txt, once a day while Chrome is open | Those sites |
| You add a second Google account (optional) | Google (accounts.google.com, oauth2.googleapis.com) | A sign-in window for the account you choose; then the short-lived token, to confirm it was issued to Refract and to learn the account's email and granted permissions. Before that account's scheduled jobs, a silent re-sign-in (no window) | Google. Refract keeps the email and permissions on this machine; tokens stay in memory and are never written to disk or exported |
| You use GA4 full or scheduled reports (optional) | Google (analyticsdata.googleapis.com) with the project's Google account | The property id and date ranges, for sessions, engaged sessions, key events and revenue by landing page and by channel | Google, which already holds this data. Reports are stored on this machine (last 12 per project) |
| A scheduled report's AI executive summary (optional, per task) | Anthropic or Refract Credits, as for any remote AI task | The report's measured numbers only; nothing is exported until you approve the summary | As for remote AI |
| You import a backlink CSV or check a disavow file | Nothing is sent: read and written on this machine | — | — |
| You press Pull Bing inbound links, or weekly once Bing is connected | Microsoft (ssl.bing.com) | Your API key, your site URL and the URLs of your top linked pages | Microsoft, which already holds this data |
| You opt in and press Pull DataForSEO backlinks (cost shown first) | DataForSEO (api.dataforseo.com) or the Credits relay | Your domain or a competitor domain you saved, and a row limit | DataForSEO |
| You press Re-check on backlink-loss alerts, or Check URLs in Broken links | The linking pages' sites, or competitor and industry sites in your link data (asked for on the click) | A plain request (HEAD, or GET if refused) for up to 50 linking pages or 200 URLs, no cookies | Those sites |
| You analyse a server log | Nothing about the log is sent: it is read on this machine and only totals are kept. After you press Fetch crawler IP lists, at most weekly: Google (developers.google.com) and Microsoft (www.bing.com) | A plain request for their public crawler IP lists | Google and Microsoft, as ordinary page views |
| You schedule or run a GEO prompt set (optional, price shown first) | Anthropic (api.anthropic.com), Perplexity (api.perplexity.ai), OpenAI (api.openai.com, with store: false) or Google Gemini (generativelanguage.googleapis.com), with your key | The prompts in that set, verbatim | Each provider, under its API data policy. Refract keeps the answer text (first 2,000 characters) and cited URLs, last 12 runs |
| You add a CrUX API key (optional), then weekly | Google (chromeuxreport.googleapis.com) | Your key, your project's origins and up to 10 key page URLs | Google, which publishes this data |
| You connect a CMS and apply a fix (optional, one approved change per click) | Your WordPress site (/wp-json), Shopify (<shop>.myshopify.com) or Webflow (api.webflow.com) | Your credentials for that CMS, the page or product identifier, and the new title, meta description or alt text you approved | Your CMS. Credentials are stored on this machine per project, never exported or logged |
| You Verify a CMS change | Your own site | One request for the changed page with a cache-busting parameter, no cookies | Your site |
| You press Rendered sample in Site audit | Your own site (a project you crawled) | Up to 60 of its pages (3 per template), each loaded in a background tab with your normal browser session, one at a time at the project's crawl rate, then closed | Your site. Refract keeps only the compared facts (title, canonical, robots, H1, link and word counts), never the HTML |
| You use a remote AI model for a task (optional, per task; price shown first) | The provider your route picks: Anthropic, OpenAI (api.openai.com), Google Gemini (generativelanguage.googleapis.com), OpenRouter (openrouter.ai, then the model provider it routes to), Portkey (api.portkey.ai or your https gateway, then its provider), an https OpenAI-compatible endpoint you added, or Refract Credits | The task's prompt and only the facts it needs; your key for that provider; OpenRouter also receives X-Title: Refract SEO, never a user id | That provider (and, through a gateway, the model provider it routes to) under its API data policy. Refract keeps the answer and its cost on this machine |
| You press Test connection on an AI provider, or open Settings → AI (at most once a day) | That provider's model list (GET /models) | Your key for that provider | That provider |
| A task runs on a local model or Chrome's built-in model | Nothing leaves this computer: a server on localhost, 127.0.0.1 or [::1], or Chrome itself | — | — |
| You look for unlinked brand mentions (Outreach) | The pages in your search results (≤ 50 per click, asked for in one prompt), or DataForSEO if you use its search (price shown first) | A plain page request with no cookies; for DataForSEO, the search text and your market | Those sites, as page views; DataForSEO. Refract keeps only the pages you add as prospects (URL, title, a short snippet) |
| You press Draft now on an outreach prospect (optional, price shown first) | The AI provider your route picks, as above | The prospect page's URL, title and mention snippet, your page's URL and title, your project name. Never an email address | As for remote AI. Refract never sends the email: you copy it or open your mail app |
| You press Re-check for the link on a won prospect | That prospect's site | A plain page request with no cookies | That site |
| You turn on hourly key-page checks (optional, per project) | Your own site | The home page and up to 20 key pages, no cookies, through the same rate limiter as Monitor, hourly while Chrome is open | Your site |
| You connect Microsoft Clarity (optional, per project), then once a day | Microsoft (www.clarity.ms) | Your Clarity Data Export token, asking for the last day of UX metrics by page | Microsoft, which already holds this data. Refract keeps 28 days of per-page counts on this machine |
| You uninstall the extension | refract.seo/uninstall | Nothing we attach. Chrome opens a page, so our web host sees a normal web visit: an IP address, a timestamp and a user-agent | Us, as ordinary web-server logs |
That last row is the one worth reading twice. chrome.runtime.setUninstallURL opens a web page when you remove the extension, which means our web server logs a visit the way any web server does. It is the only signal we ever receive about anyone, we cannot connect it to anything you did, and it is not tied to an identifier. If you would rather not send it, close the tab before it loads — or disable the extension instead of uninstalling it. We are telling you because a policy that omitted this would be inaccurate.
AI runs on your machine unless you choose otherwise. Chrome's built-in model is the default. A remote model (your own Anthropic key, or Refract Credits) is off for every task until you switch it on for that task, shows its estimated cost first, and every number in its answer is checked against the data it was given before you see it. If your hardware cannot run the built-in model, the extension keeps working: every finding, every measurement and every mechanical fix is deterministic and needs no model at all.
Google API Services User Data Policy — Limited Use
This applies to every Google API Refract can use (Search Console, Analytics, Sheets, Docs export, PageSpeed Insights). Refract SEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Search Console data is read with the read-only scope webmasters.readonly, used only to show you your own data and to rank findings by the traffic they affect, stored only on your machine, never transferred to anyone, never used for advertising, and never read by a human at Refract. Disconnect in Settings, or delete it with Delete v4 data.
Local-only mode
One switch in Settings (or your organisation's policy) stops every connector and every request Refract would make without you asking: Search Console, Analytics, PageSpeed, Sheets, webhooks, the status feed, Monitor's daily checks and v3's scheduled Watch. Audits and crawls you start yourself still run, exactly as before.
What is stored, where, and for how long
All of it is in your browser profile, on your machine. None of it is synchronised to any account — we deliberately use chrome.storage.local and never chrome.storage.sync, because sync would replicate your data through Google's servers.
| What | Where | Contains | Removing it |
|---|---|---|---|
| Audit history | IndexedDB, last 20 route templates | Rule IDs, a date, an origin and a route shape. Never page content, never a URL with a query string. | Settings → Clear history, or clear site data |
| Framework overrides | chrome.storage.local | Origin → framework name | Clear site data |
| Muted rules | chrome.storage.local | Rule IDs you chose to silence | Settings → Unmute |
| Usage counters | chrome.storage.local | Counts of things you did. Never transmitted | Settings → Reset |
| A site crawl | chrome.storage.local, per origin, expires after 7 days | Only if you pressed Crawl: for each page reached, its URL, title, description, canonical, robots directive, outgoing internal links and declared hreflang alternates. Never page content. | Settings → Forget per site, or Forget every crawl |
The site crawl, specifically
This is the one feature that stores anything beyond the page in front of you, so it deserves saying plainly.
Nothing is stored unless you press Crawl. An earlier version of this extension kept a per-origin model of every site you browsed, growing with each audit — that is a private analytics store, it is a different product from an audit tool, and it was removed. There is no consent list to maintain now because there is nothing accumulating to consent to.
One press produces one crawl of one origin. It is replaced by the next press, deleted on request, and expires by itself after seven days — a month-old crawl answers questions about a site that has since changed, with the confidence of a fresh measurement.
The crawl exists because the questions people actually ask — is anything unreachable, do two pages share a title, do my hreflang tags point back — are questions about a set of pages. A single page cannot answer them, and neither can a sample: sampling five pages of four hundred finds a duplicate pair almost never and then reports that there are none. When a crawl stops early, every answer that depends on having seen the whole set is withheld rather than guessed.
Files you export — the baseline, the report, a ticket — are written by your browser to your downloads folder. They are never uploaded. The extension does not hold the downloads permission; it hands your browser a local file the same way any web page offers a download. The baseline deliberately contains rule IDs and digests only, because it is designed to be committed to a shared repository.
What v4 adds on this machine (IndexedDB database refract-v4)
| What | Kept for |
|---|---|
| Projects (origins, Search Console property, segments, brand terms, key pages, keywords, crawl settings) | Until you delete the project |
| Search Console daily totals per property | Indefinitely, so your history outgrows Google's 16 months; deleted with Delete v4 data |
| Search Console per-page totals and the CTR curve | Replaced by each daily sync |
| Cached Search Console responses | Removed after a day |
| Site audit v2 crawls (per-page facts: status, title, canonical, links, word count — never page text) | Until you delete them or Delete v4 data |
| Latest audit findings per page (rule ids, messages, measured values) | Replaced by the next audit; at most 200 pages per site |
| Events, alerts, annotations, investigations, the fix ledger, job log | Investigations: last 30; job log: last 200; the rest until Delete v4 data |
| API keys and webhook URLs you add | Until you remove them; never logged, never exported |
What we never do
- We never send your page content, HTML, cookies, form data, storage or credentials anywhere.
- We never write to your filesystem or your repository. The extension emits code for you to apply.
- We never use an analytics SDK, a tag manager, a session recorder or an error-reporting service.
- We never sell, rent, share or transfer data, because we do not have any to transfer.
- We never load a script, font, stylesheet or image from a remote server. A build check fails the release if a remote reference appears in any surface, because a third-party request on every panel open would falsify the promise at the top of this page.
Permissions, and why each one exists
Chrome shows you a permission list. Here is what each entry is actually for.
| Permission | Why |
|---|---|
activeTab | Read the page you invoked Refract on. Granted per click, not standing. |
scripting | Inject the page reader into that tab on demand, rather than running on every page you visit |
storage | The settings and history above |
sidePanel | The panel is the product's interface |
offscreen | Measure text width on a canvas, and host the on-device model session |
declarativeNetRequestWithHostAccess | Set a crawler user-agent on our own request while checking what a crawler receives. Scoped to one URL, for one request, then removed |
tabs | Know which tab the panel belongs to, and clear its audit when it closes |
| Site access (optional) | Requested only when you use a crawler check. Decline it and everything else still works — those checks report as not evaluated rather than counted as passing |
unlimitedStorage | Your Search Console history and projects, kept on your machine, can outgrow the default local storage quota. No warning is shown for it and it grants no access to anything |
identity (optional) | Requested only when you press Connect Search Console, to sign in with your Chrome profile's Google account. Never requested at install |
notifications (optional) | Requested only if you switch on Tell me when something breaks. Never requested at install. Decline it and the toolbar badge still shows the count |
We do not request the debugger permission, and we do not request standing access to all sites.
We also do not request downloads, which an earlier version did. It bought a "save as" dialog and cost a permission a reviewer has to be talked through; an ordinary link does the same job with no permission at all. A permission that is merely convenient is one we should not be asking for.
Children
Refract SEO is a developer tool. It is not directed at children and collects no personal information from anyone, of any age.
Your rights
Because we hold no data about you, there is nothing for us to disclose, correct, export or delete on your behalf — the delete controls are in the extension, and they operate on your own machine. If you are exercising a right under GDPR, the CCPA or a comparable law and want that confirmed in writing, contact us below and we will confirm it.
Third parties
None, unless you connect one. API keys and webhook URLs you add are stored only in this browser's extension storage, are never logged, and are sent only to the service they belong to. No AI provider, no analytics vendor, no CDN, no error reporter, no font host. Without connectors, the only servers this extension talks to are the site you are auditing and, once, our own uninstall page. If you connect Search Console, Google is a third party for that connector only, as listed in the table above.
An earlier version supported bringing your own AI provider key, and this section described that relationship. That tier was removed, so the section describes nothing.
Changes
Material changes are announced in the extension's changelog and this page's effective date is updated. If a change ever introduced data collection, it would be opt-in and announced before it shipped, not buried here.
Who is responsible
A privacy policy with no named accountable owner is not a policy, and the store listing links to this page.
- Data controller: Sharaj Rewoo
- Contact: sharaj.rewoo@mindtickle.com
- Security reports: sharaj.rewoo@mindtickle.com
- Jurisdiction: India
The rule catalogue has its own named owner, recorded in rules/OWNER in the repository, because a dated "last verified" on every rule is a claim somebody has to keep true.