Skip to main content

    Browser Extension Privacy Policy

    Last updated: August 12, 2026

    This policy covers the AngelBacked browser extension. Our general Privacy Policy covers angelbacked.co and the web application.

    What the extension collects

    • The hostname of the tab you are viewing — for example notion.com. It is sent to our servers to look up whether that company has angel investors on record. We do not receive the full URL, the page path, query strings, or any page content.
    • Your account credentials at sign-in — your email and password are sent once to our authentication provider to create a session. The password is never stored by the extension.
    • A count of lookups — recorded per account to enforce fair-use limits and detect abuse.

    What it never collects

    • Page content. The extension injects no scripts into the sites you visit.
    • Full URLs, paths, or search queries.
    • Browsing history for sites that are not looked up.
    • Keystrokes, form data, cookies, or credentials belonging to other sites.

    Why each permission is needed

    • tabs — to read the hostname of the active tab, so the toolbar icon can show how many angels we hold for that company and the panel can display the right record. Only the hostname is used.
    • storage — to keep your signed-in session on your own device, so you are not asked to sign in on every page. Stored in chrome.storage.local, readable only by this extension.
    • Host access to our own API domain — the extension communicates with AngelBacked servers only, and has no access to any other website.

    Storage and retention

    Your session is stored locally and removed when you sign out or uninstall the extension. Lookup counts are retained on our servers for fair-use enforcement and deleted on the same schedule as our other operational logs.

    Data sharing

    We do not sell data collected by the extension and do not share it for advertising or any purpose unrelated to operating the service. Data is processed by our infrastructure providers (Supabase for authentication and data, Stripe for billing) solely to deliver it.

    Contact

    Questions: [email protected]. You can request deletion of your account and associated data at any time from your account settings.