Skip to content
rememberme-privacy-policy.txt

PrivacyEffective and last updated

RememberMe Privacy Policy

RememberMe remembers the Google account you select for a website and reminds you during a later traditional Google sign-in. It has no server, user registration, analytics, advertising, or tracking system. RememberMe collects no server-side data and sends no network requests.

What stays in your browser

RememberMe stores the following in the installed browser profile's extension-local storage (chrome.storage.local in Chrome, browser.storage.local in Firefox):

  • Website/app domain and app display name.
  • Most recently selected Google email address for that app.
  • First-recorded and last-selected timestamps and selection count.
  • Optional public OAuth client identifier and callback hostname, used to identify the app.
  • App links you explicitly confirm for sign-ins routed through an intermediary.
  • Your reminder, date-display, and auto-select preferences.

Temporary OAuth context stores only sanitized client identifiers, callback hosts, and timestamps in the browser's extension-session storage. It is associated with an active Google sign-in tab, expires after a short continuation window, and is removed when that tab closes or leaves Google's sign-in site. Session storage is also cleared when the browser restarts or the extension is reloaded, disabled, or updated. It contains no tokens or full navigation URLs.

RememberMe does not use synced storage. It does not automatically send records to other browsers or devices.

What is never read or stored

  • Passwords or password-field values.
  • Access tokens, refresh tokens, Google ID tokens, authorization codes, or OAuth state.
  • Google authentication cookies, session tokens, or other cookies.
  • Browsing history or a log of websites you visit.
  • Unrelated webpage content, arbitrary website email addresses, or network traffic.

The content script runs only on https://accounts.google.com/*, in the top frame. It reads account-row email identifiers and limited app-name hints from the traditional chooser, and parses OAuth routing identifiers from Google's page URL. It does not inspect browser-owned FedCM dialogs. activeTab is used only to identify the current website after you invoke the popup, without scanning that page.

How information is used and shared

Stored records are used only for RememberMe's account reminders and local management features. Information is never sold, sent to RememberMe, used for advertising, or transmitted by the extension to a third party. There are no external APIs, remote favicon lookups, or telemetry requests.

The current app's reminder is inserted into Google's sign-in page and is visible to scripts on that page. It includes the app name and, if enabled, the last-selected date. It does not expose records for other apps. The email being highlighted already exists in the account chooser. Google and the website continue their normal sign-in behavior under their own policies; RememberMe does not control their requests. Enabling auto-select activates the visible account row and starts that normal behavior.

Exporting creates a local JSON file containing your app records, links, and preferences. No upload occurs. Importing reads a file you choose and validates it before merging local records. Import never enables auto-select or changes your current preferences. How you store or share exported backups is under your control.

Your controls

  • Use Change to rename an app or change its remembered email.
  • Use Forget to delete an app's account record and manually confirmed links.
  • Disable reminders while continuing to remember choices.
  • Auto-select is off by default and must be explicitly enabled in settings.
  • Use Clear all data and confirm to delete every account, link, preference, and temporary sign-in context.
  • Disable or uninstall RememberMe to stop all detection. Uninstalling removes extension storage, but does not remove backups you exported.

Records are retained locally until you delete them or uninstall the extension. Firefox temporary-development installations may retain local data after removal; clear data before removing a temporary add-on if you want it erased. Incognito/private-window use is disabled in version 1.0.1.

Security and access

RememberMe validates runtime message senders and supplies only the current app's record to the Google content script. Chrome restricts local and session storage to trusted extension contexts. Firefox does not implement that restriction API: its session storage is private to extension pages by default, and its local storage remains accessible to the extension's own isolated content scripts. RememberMe's content script does not read local storage directly. Website scripts cannot access the extension's storage or messaging APIs.

Page-provided names and imported strings are treated as text, not executable HTML. All extension code is bundled, and extension pages prohibit network connections through their Content Security Policy.

RememberMe does not encrypt local data or exported backups. Anyone with access to your browser profile, device, or backup files may be able to read your saved email addresses. Keep exported backups private.

RememberMe's use of locally handled information is limited to its account-reminder purpose and follows the Chrome Web Store User Data Policy's Limited Use restrictions. This extension does not obtain credentials or user information from Google APIs.