Mine · Privacy Policy
This describes what the Mine Chrome extension and app actually read, store, and send to other services.
Mine is operated by Yahli Heimann, an individual based in Israel, not a registered company. Under GDPR and Israeli law, an individual can act as the data controller — that's the role Yahli holds here: the person who decides what data Mine collects and why, and who you can contact using Section 10 below for anything covered by this policy.
When you sign in, Google shares your account's email address and a Google account ID with us so we can recognize you on future visits. We never see your Google password — sign-in happens entirely through Google, and we only receive proof that it succeeded.
Each time you save something, we store what the page itself publishes about that specific piece of content — its title, a short description, and a preview image — along with the page's own address. If you save a physical note by photographing it, or save a PDF, we keep a copy of that image or file. Anything you type yourself — a note, a tag, a collection name — is stored exactly as you wrote it.
This is read from whatever is actually visible on the page you have open at the moment you choose to save it — the same information your own browser already renders on screen. If you save something you can only see because you're logged in (a private post, an unlisted document, a repository only your account can view), that content is read the same way, because it's what's genuinely on your screen when you click save. Mine does not bypass any login, permission, or access control on the site itself; it only ever reads what the site has already shown you.
We keep a record of which features you use and whether an action succeeded, failed, or took an unusual amount of time — for example, that a save from a given website succeeded, or that it timed out. This is tied to your account so we can investigate a specific report, but it does not include the content of pages you didn't save. When something breaks, we automatically log what failed and where, which may include the address of the page you were trying to save at the time.
The extension reads the page open in your active browser tab, and only at the moment you click the extension icon to save it. It does not run in the background scanning your tabs, does not keep a history of pages you've visited, and cannot see any browser window, tab, or history other than the one you're actively looking at when you click save.
| Permission | What it's for |
|---|---|
identity | Lets you sign in with your Google account. |
storage | Keeps you signed in between clicks, on your own device. |
activeTab + scripting | Lets the extension read the currently open tab's title, description, and preview image — only when you click save, and only that one tab. |
| Host access to specific platforms | A short list of sites (Instagram, X, YouTube, LinkedIn, Facebook, Pinterest, Reddit, GitHub, TikTok, Threads) where the extension reads slightly more detail directly from the page, since these sites don't always publish clean previews on their own. The extension does not request access to every website you visit — on any other site, it can still save the page using the narrower activeTab permission above, triggered only by your click. |
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Mine is built on a small number of outside services. Each one receives only what it needs to do its specific job — never your full account or library.
| Service | What it receives | Why |
|---|---|---|
| Google Sign-In | Your Google account, for authentication only | Lets you sign in without a separate password |
| Supabase | Everything described in Section 1 | Hosts our database, file storage, and server functions — this is where your account and saves actually live |
| Anthropic (Claude) | A save's title and description only | Generates suggested tags for that one save |
| fal.ai | A collection's name only — never your saves or account details | Generates a decorative placeholder image for that collection |
| Google Cloud Vision | A photo, only when you photograph a physical note | Reads the text out of that photo |
| Resend | Aggregate, anonymous usage statistics | Sends the operator (not you) a daily internal summary of app health — this never emails users directly |
Anthropic and Google both publish a clear commitment that they do not: Anthropic's stated policy for API customers is that inputs and outputs are not used to train its models by default, and Google's Cloud Vision documentation states plainly that "Google does not use the content you send to train and improve our Cloud Vision features." fal.ai's own terms are less specific for the tier Mine uses, which is one reason only a collection's name — never a save, a URL, or anything about your account — is ever sent there.
Your account, your saves, and your files are stored on Supabase infrastructure in Frankfurt, Germany — inside the EU. The specific tasks above that need an outside service (generating tags, generating a collection thumbnail, reading text from a photo, sending an internal status email) do involve a transfer outside the EU, since Anthropic, Google Cloud, and Resend primarily operate from the United States. Anthropic, Google, and Resend are each certified under the EU–US Data Privacy Framework, the legal mechanism the EU recognizes for exactly this kind of transfer; fal.ai's own privacy policy states it applies comparable contractual safeguards for the same purpose.
By default, everything you save is private to your account. This is enforced at the database level — every table Mine's data lives in has row-level access rules that check who's asking, not just a check in the app itself, so a bug in the app's own code can't accidentally expose your library to anyone else.
As the person who operates Mine, I can see aggregate usage statistics and error logs to keep the product working, and I can see a rolling window of the 50 most recently saved items across all accounts — their titles, descriptions, source addresses, and platforms. This exists specifically to test and improve how accurately Mine reads different websites, and is not used to browse anyone's library. Under GDPR this access is based on legitimate interest (Article 6(1)(f)): keeping the core save feature working correctly for everyone is necessary to operate the service at all, and is limited to exactly the fields needed to diagnose an extraction problem, for a rolling 50-item window rather than unlimited history. I do not sell, rent, or otherwise share your saved content with anyone.
Items you delete from your library are removed immediately from view, and their files are permanently removed from storage within about a week. Deleting your account permanently removes your saved items, tags, collections, and account record — including any stored photos, PDFs, and preview images — and this cannot be undone or recovered afterward.
Usage records are kept for up to 12 months, and error logs for up to 6 months, then automatically and permanently deleted. Both windows are set to comfortably outlast what we actually use them for — the longest analysis we run looks back 90 days, and the daily automated health check looks back 7.
Your data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher, enforced on every connection). Access to your account data is scoped to you by database-level rules, not just application logic, so a bug in the app's own code can't accidentally expose your library to anyone else. No system is perfectly secure, and we can't guarantee absolute security, but we build with this as a first-class concern rather than an afterthought.
Most of Mine's users are in Israel and the European Union, so the rights below are described with both in mind.
You have the right to access the personal data we hold about you, correct it, request its erasure, receive a copy of it in a portable format, and object to or restrict certain processing. You can also lodge a complaint with your local data protection authority at any time — contacting us first is appreciated but never required.
We rely on two legal bases, depending on the data:
Under Israel's Privacy Protection Law, you have the right to inspect the personal information we hold about you and to request that inaccurate information be corrected or deleted. As required by Section 11 of that law:
You can exercise any of the above by contacting us below.
Mine is not directed at children, and we don't knowingly collect information from anyone under 13.
If this policy changes in a way that meaningfully affects how your data is handled, we'll update the date at the top of this page and, where practical, let you know directly.
Yahli Heimann, individual, based in Israel — the operator and data controller of Mine (see the "Who's responsible" section above). Questions about this policy, or requests to access, correct, or delete your data, can be sent to yahli109@gmail.com.