Privacy policy
Refresh Pilot is built so that refreshing and monitoring happen entirely inside your browser. This page explains, in plain words, exactly what leaves your machine, when, and why. Effective date: July 23, 2026.
The short version
- Page refreshing and keyword monitoring run locally in your browser. The content of the pages you watch is never sent to us.
- Free use needs no account — no name, no browsing history. A PRO subscription uses an account: your email address and a securely hashed password, so your purchase and synced settings can follow you across devices.
- Data only leaves your browser for features that need a server by nature: cloud sync of your settings, your PRO account and sign-in, email alerts, AI generation, the script marketplace, and payments.
- We use no analytics, no ads, no trackers, and we never sell or share your data with anyone for marketing.
What stays on your device
Everything the extension does moment to moment is local: reloading tabs, the countdown overlay, scanning pages for your keywords, highlighting matches, desktop notifications, and alert sounds. The words on the pages you monitor are read by the extension inside your browser and are not transmitted anywhere. Your settings are stored in Chrome's extension storage on your computer.
Accounts & how the dashboard connects
Guest mode (free). The web dashboard can manage one browser's Refresh Pilot settings without any account. It links to the extension in that same browser through a short-lived session kept in the browser's local storage. In guest mode, nothing about you is stored on our servers.
PRO account. A PRO subscription uses a real account: an email address and a password. We store the email and a securely hashed version of the password on our server — never the password itself. Signing in issues a session token that your browser keeps locally so you stay logged in; you can revoke it any time with "Log out" or "Sign out everywhere." There is no Google sign-in and no two-factor.
What is sent to our server, and when
| Feature | What is sent | When |
|---|---|---|
| Cloud sync & web dashboard | Your extension settings: defaults, schedules, auto-start rules, saved expressions, custom scripts — which can include the URLs and keywords you configured | When you use cloud sync or a signed-in dashboard — your settings are saved to your account so they sync across devices |
| Account & sign-in | Your email address, a securely hashed password, and session tokens that keep you signed in | When you create a PRO account, sign in, or reset your password |
| Email alerts | The email address you entered, the watched page's URL, the matched keyword, and a short text snippet (≤300 characters) | Only when a monitor you configured with email alerts finds a match |
| AI generation | Your written prompt and — only if you choose to include it — a short excerpt of the page's visible text | Only when you press the ✨ Generate button |
| Script marketplace | Browsing queries; if you share a script: its name, description, code, and the author name you type | Only when you browse or submit |
| License recovery | The email address you type, to match it against a past purchase | Only when you use "Restore a purchase" |
Payments
The $2.99/year PRO subscription is processed by Stripe. Your card details go to Stripe only — we never see or store them. Checkout creates a PRO account from the email you paid with and emails you a temporary password to sign in. Our server stores your Stripe customer reference, subscription status, and that email so your subscription follows your account. Stripe's own privacy policy applies to the payment itself.
Third-party services we rely on
- Stripe — payment processing.
- Resend — delivers the alert and recovery emails we send.
- Anthropic — processes AI-generation prompts when you use ✨ features.
Each receives only the minimum needed to do its job, and only when you use that feature.
Data retention & deletion
For signed-in users, your account and its synced settings stay on our server until you delete them. Uninstalling the extension stops the extension's own collection immediately. To have your account, synced settings, email address, or purchase records deleted, contact us (below) using the email address on your account. Alert emails are delivered and not archived beyond normal delivery logs.
Children
Refresh Pilot is a general-audience tool and is not directed at children under 13.
Changes to this policy
If this policy changes, we'll update this page and its effective date. Substantive changes will be called out in the extension's release notes.
Contact
Questions or deletion requests: support@refreshpilot.com