PageClip 隐私政策
生效日期:2026-08-29
最后更新:2026-08-29
1. 我们处理什么数据
PageClip 在本地处理用户主动保存的网页信息,包括 URL、标题、favicon 地址、文件夹、标签、备注、创建时间、置顶状态、快捷收藏夹、标签集合、Inbox、已读状态、回收站快照和应用设置。
2. 本机存储
永久收藏、快捷收藏夹、Inbox、回收站和设置默认保存在当前浏览器的 chrome.storage.local。本机密钥模式使用浏览器 IndexedDB 保存本机加密密钥。
PageClip 没有独立应用服务器。除非用户主动导出或启动云备份,否则本地数据不会被发送到其他服务。
3. Chrome 权限
- bookmarks:浏览和管理 Chrome 原生书签;浏览器书签导入是复制操作,不修改原书签。
- tabs:读取当前页面或当前窗口标签页的 URL、标题和 favicon 信息。
- storage:保存 PageClip 本地数据。
- favicon:显示网页图标。
- contextMenus:提供右键快捷操作。
- tabGroups:保存标签集合中的标签组信息。
- scripting:在普通网页中显示 PageClip 网页侧栏入口。
- identity / identity.email:连接并显示用户选择的 Google 账号。
- readingList(可选):在用户授权后读取、添加、标记或删除 Chrome Reading List 条目。
4. Google OAuth 与 Drive
用户主动连接 Google Drive 后,PageClip 使用 Google OAuth 访问该用户的 Drive 应用数据目录 appDataFolder,只保存一个名为 PageClip-latest.enc 的最新备份文件。
备份文件在上传前加密,云端不保存 PageClip 明文内容、备份密码、原始本机密钥或无关浏览历史。
5. 加密
备份密码模式使用用户输入的密码派生加密密钥;密码不会保存。Chrome 本机密钥模式使用本机加密密钥;跨设备恢复需要导入由单独恢复密码保护的恢复密钥文件。
如果用户忘记备份密码且没有可用恢复密钥,PageClip 无法解密备份。
6. 第三方服务
PageClip 依赖 Chrome、Google Drive 和 GitHub 等第三方服务。它们分别受各自的隐私政策和服务条款约束。
7. 数据保留与删除
本机数据由用户在扩展中删除或通过卸载扩展清除。云端备份由用户通过重新备份、断开账号或 Google 账号相关管理操作控制。PageClip 不会在后台自动上传数据。
隐私问题、数据删除请求和安全报告请通过 GitHub Issues 提交。不要在公开 Issue 中提交密码、恢复密钥、OAuth Token 或私人收藏内容。
8. 儿童隐私
PageClip 不是面向儿童设计的服务,我们不会故意收集儿童个人信息。
9. 政策变更
隐私政策发生实质变化时,会在本页面更新最后修改日期。
10. 联系方式
PageClip Privacy Policy
Effective date: 2026-08-29
Last updated: 2026-08-29
1. Data we process
PageClip locally processes web data that the user chooses to save, including URLs, titles, favicon URLs, folders, tags, notes, timestamps, pinned state, quick-access items, tab collections, Inbox entries, read state, recycle-bin snapshots, and application settings.
2. Local storage
Permanent collections, quick access, Inbox, recycle-bin entries, and settings are stored in the current browser's chrome.storage.local. Device-key mode uses browser IndexedDB for the local encryption key.
PageClip does not operate a separate application server. Local data is not sent elsewhere unless the user explicitly exports it or starts a cloud backup.
3. Chrome permissions
- bookmarks: browse and manage Chrome native bookmarks; browser bookmark import is copy-only.
- tabs: read active-page or current-window tab URLs, titles, and favicon information.
- storage: store PageClip data locally.
- favicon: display website icons.
- contextMenus: provide browser context-menu actions.
- tabGroups: preserve tab-group metadata in tab collections.
- scripting: display the PageClip web sidebar on ordinary pages.
- identity / identity.email: connect and display the selected Google account.
- readingList (optional): access Chrome Reading List only after permission is granted.
4. Google OAuth and Drive
When the user connects Google Drive, PageClip uses Google OAuth to access the user's Drive application data folder, appDataFolder, and keeps one latest file named PageClip-latest.enc.
The backup is encrypted before upload. The cloud copy does not contain plaintext PageClip data, the backup password, the raw device key, or unrelated browsing history.
5. Encryption
Password mode derives an encryption key from the password entered by the user; the password is not stored. Device-key mode uses a local encryption key; cross-device recovery requires an encrypted recovery-key file protected by a separate recovery password.
If the user loses the backup password and has no usable recovery key, PageClip cannot decrypt the backup.
6. Third-party services
PageClip relies on Chrome, Google Drive, and GitHub as third-party services. Each service is governed by its own privacy policy and terms.
7. Retention and deletion
Local data can be deleted in the extension or by uninstalling the extension. Cloud backups are controlled by re-backup, disconnecting the account, or relevant Google account controls. PageClip does not upload data automatically in the background.
Use GitHub Issues for privacy questions, deletion requests, and security reports. Do not post passwords, recovery keys, OAuth tokens, or private collections in public issues.
8. Children
PageClip is not directed to children and does not knowingly collect children's personal information.
9. Changes
Material changes will be reflected on this page with an updated last-modified date.