Chrome extension policy
Privacy Policy
This policy explains how 4Later handles browser information when you use the Chrome extension, website, account, payment, and support features.
What 4Later Does
4Later helps you search and clean Chrome history, review tabs, manage bookmarks, and create site blocking rules. These features use Chrome extension APIs in your browser.
Browser Data
The extension may read history, open tab, tab group, bookmark, and URL information when you use features that need that access. This information is used to display results, organize items, delete selected history entries, update bookmarks, or apply blocking rules in Chrome.
4Later does not sell browser data. 4Later does not use browser history, tabs, bookmarks, or blocking rules for advertising.
Account, billing, and email features on the website are separate from the extension workspace. You do not need a website account for local browser history, tab, bookmark, or blocking management inside Chrome.
Local Storage and Extension Settings
The extension may store preferences and blocking rules locally through Chrome extension storage or related browser storage. Those settings support the extension features you choose to use.
You can remove local extension data by changing or clearing extension settings, deleting related browser data where Chrome allows it, or uninstalling the extension.
Bookmark Metadata
Bookmark notes, favourite flags, and saved visual references are stored locally in the extension workspace. 4Later does not fetch saved bookmark pages for preview metadata.
Optional Encrypted Bookmark Sync
Encrypted synchronization is disabled by default and requires an active Pro account. Only bookmarks you explicitly select participate. A selected record contains a portable ID, its title and URL, and informational creation and update timestamps.
Your device validates and encrypts the complete selected-bookmark snapshot with AES-256-GCM before upload. The service stores ciphertext plus account, publishing-device, byte-size, revision, and timing metadata. The service must not receive readable bookmark content or the synchronization key.
Chrome bookmark IDs, mobile notification IDs, screenshots, preview caches, history, tabs, blocking rules, passwords, folders, notes, reminders, and unrelated bookmarks remain local. This policy does not claim that the existing Chrome or mobile bookmark stores are encrypted at rest.
Revoking a device prevents future service access but does not erase plaintext already downloaded to that device. If you lose every stored copy of the synchronization key, the service cannot recover it and the server ciphertext becomes unreadable.
Account, Email, and Payments
If you create an account, request email login, join a launch list, or make a support payment, the website may process the email address, account profile, checkout email, payment amount and currency, plan and entitlement status, device name and platform, device-credential hash and expiry, Stripe checkout session identifiers, Stripe customer and subscription identifiers, and support messages needed to provide those services.
Website account, device, encrypted-library, and lead records may be stored in a production MongoDB database. Entitlement and payment records may also be stored there when needed for account access and billing. Email login and launch-list messages may be sent through Cloudflare Email Service. Payments and billing portal actions are processed by Stripe. 4Later does not store full card numbers.
Usage Analytics
4Later may use PostHog to collect coarse usage events, such as which page or workspace was opened, whether checkout started, broad count buckets for selected extension actions, normalized blocked or allowed domains, blocking pack changes, and coarse local-time buckets for focus sessions. These events help debug launch flows and understand feature adoption.
4Later does not send browser history URLs, tab URLs or titles, bookmark titles or notes, search text, full blocking URLs, page paths, page contents, raw notes, or raw bookmark and tab content, encryption keys, or synchronized ciphertext to PostHog. Session replay is disabled on both the website and extension.
Service Providers
4Later may use hosting, database, authentication, email, payment, browser platform, and support providers to run the website, account, payment, email, analytics, and extension distribution features. Current providers may include PostHog for privacy-reviewed usage analytics. These providers should only receive the information needed for those services.
Permissions
4Later requests permissions for Chrome history, tabs, tab groups, bookmarks, declarative network request blocking, storage, alarms, favicon display, and HTTP/HTTPS host access. These permissions are used only for the browser cleanup, organization, and blocking features described in the extension.
What History Deletion Cannot Erase
4Later cannot erase Google account activity, synced activity on other devices, website-side logs, cookies, cache, passwords, or search-engine records. Deleting selected Chrome history entries does not remove bookmarks; bookmark changes happen only through the separate bookmark actions you choose.
Requests and Deletion
To ask about website account, billing, support, or launch-list records, email tpotgroup418@gmail.com. Browser data controlled by Chrome or other websites must be managed in Chrome, your Google account, the relevant website, or the relevant service.
Contact
For privacy questions or requests, email tpotgroup418@gmail.com.