Overview
Pin Things is a browser extension for saving reusable text, links, and page references and inserting them into browser fields. The local-first product remains complete without an account or remote service. The invite-only V2 pilot adds optional per-browser synchronization, not a mandatory account.
Information Pin Things handles
Pin Things handles only the information needed to provide its user-facing features:
- Pins you create or capture, including their title, content, icon, type, status, and timestamps.
- Local preferences and onboarding status.
- Selected page text, clicked-link destinations, page URLs, and page titles only when you explicitly use a Pin Things capture action.
- Temporary routing information about the eligible browser field you most recently focused so Pin Things can insert the pin you choose.
- Backup files you explicitly choose to export or import.
- When you enroll a browser, active and archived pins can be synchronized with their identifier, title, content, type, icon, status, and creation, update, and archive timestamps.
- The pilot uses Clerk for sign-in and a verified account identity to scope the remote library.
- The pilot may record allowlisted, content-free reliability measurements for a maximum 30-day window.
Pin Things does not read, capture, or store the existing value of a password field. It only inserts content that you explicitly saved as a pin.
How information is used
Information is used to provide local Pin Things features and, only after explicit pilot consent, to synchronize the durable pin library and measure synchronization reliability. Pin Things does not use pin content for advertising, profiling, server-side search, content analysis, or unrelated analytics.
Local storage and security
Pins, preferences, and onboarding status are stored in your browser's local extension storage. Temporary field-routing information stays inside the extension and browser session. Local storage is not encrypted.
Do not store passwords, API keys, authentication tokens, or other secrets in Pin Things. Pin Things is not a password manager.
Export creates an independent Backup V2 JSON file locally on your device. It can preserve local pins, settings, and unresolved conflict proposals, but it excludes credentials, device IDs, remote cursors, outbox operations, pilot receipts, and API secrets. Import reads only the file you choose and validates it before updating local extension storage.
Optional sync and server readability
Sync is off by default and enabled separately on each browser. No pin data leaves the device before the enrollment disclosure is reviewed and explicit consent is given. The pilot uses Clerk for sign-in; the API derives ownership from the verified Clerk identity.
The service can process plaintext pins, and its configured database provider persists synchronized fields in a server-readable form. The pilot does not provide client-side end-to-end encryption. Locale, onboarding, shortcuts, focus state, device preferences, credentials, cursors, outbox entries, and measurement identifiers stay outside the durable pin payload.
Do not store passwords, API keys, authentication tokens, or other secrets as pins, especially when sync is enabled.
Content-free pilot measurement
Joining the invite-only pilot requires the disclosed reliability-measurement condition. Measurement is first-party, purpose-limited, and active for at most 30 days. Raw events expire no later than 30 days after collection or at the end of the participant window; only non-identifying daily aggregates may remain.
The allowlist contains a keyed participant pseudonym, random device and trace IDs, browser/app/protocol versions, operation category, client/server timestamps, bounded outcome counts, queue-depth buckets, a durable-library digest-match boolean, and normalized outcomes. It never contains pin IDs, titles, content, URLs, icons, Clerk subjects, bearer tokens, request bodies, or arbitrary diagnostics.
Sharing and external transmission
Local-only use makes no external data transmission. If you explicitly enroll in the pilot, synchronized pin fields and the allowlisted content-free receipts described above are sent to the configured Pin Things API. Pin Things does not sell, rent, or use this data for advertising, profiling, server-side search, content analysis, or unrelated analytics, and it does not add a third-party analytics provider.
Browser permissions
- Storage saves pins and local preferences.
- Context menus provide the three Pin Things capture actions.
- Access to ordinary HTTP and HTTPS pages lets Pin Things display its input-side control, remember the eligible field you selected, insert the pin you choose, and capture selected text, links, or page URLs when requested.
- Optional pilot requests are made by the background extension context to the configured HTTPS API only after consent; content scripts and visited pages do not receive Clerk tokens or account metadata.
Private or incognito operation is disabled.
Retention and deletion
Local data remains in browser extension storage until you edit or delete it, clear the extension's browser data, or uninstall Pin Things. Archived pins remain stored until you delete them. Clearing extension data or uninstalling can permanently remove local pins unless you exported a backup.
If you enroll, remote library data remains available until you disable sync, sign out, delete the remote library, or the service performs account-deletion cleanup. Staged enrollments expire after their bounded review window, and raw pilot events expire within the 30-day measurement window.
Delete remote library is separate from disabling or signing out. A recent single-use confirmation makes the active remote library unavailable, stops sync, removes its live service data and participant events, and preserves local pins and export. The pilot offers no in-product undo; a local copy or export is required for re-enrollment.
Your controls
You can decline enrollment and continue local use, export an independent Backup V2, disable sync, sign out, resolve conflicts, or delete the remote library. You can also edit, archive, restore, or permanently delete local pins, replace the local library through an explicit import, clear extension data through the browser, or uninstall Pin Things.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Pin Things uses handled information only to provide or improve its single user-facing purpose and does not transfer that information to third parties.
Policy changes
This V2 policy, the browser-store disclosures, the enrollment consent, and the in-product help must stay aligned with the shipped runtime. If Pin Things' data practices change, the policy and required notices are updated before those changes are released.
Contact
Privacy questions can be sent to brehm.matheus@hotmail.com.
brehm.matheus@hotmail.com