Effective date: 9 September 2026 Applies to: the PromptMill Chrome extension, all versions.
English · Tiếng Việt
PromptMill collects no data. It has no server, no account system, no analytics, and no remote configuration. Nothing you type, load, or generate is transmitted to the developer or to any third party. Everything the extension stores stays in your own browser profile on your own computer.
This is verifiable rather than promised: the extension is open source, and the entire codebase contains no network calls to any server. See Verifying these claims.
None. Using the categories defined by the Chrome Web Store’s Privacy Practices disclosure:
| Category | Collected? |
|---|---|
| Personally identifiable information | No |
| Health information | No |
| Financial and payment information | No |
| Authentication information | No |
| Personal communications | No |
| Location | No |
| Web history | No |
| User activity | No |
| Website content | No |
“Collected” here has the meaning Google gives it: transmitted off your device. PromptMill transmits nothing off your device.
The extension saves the following to chrome.storage.local, which lives inside your browser profile
on your computer. It is never uploaded anywhere.
| Stored value | What it is | Why |
|---|---|---|
prompts |
The text in the prompt box | So your list survives closing the side panel |
queueItems |
Each prompt plus its status (pending / done / error / timeout) | So a finished prompt isn’t generated again on the next run |
folder |
The download subfolder name you chose | To remember your setting |
serial |
Whether file numbering is on | To remember your setting |
timeoutMin |
Your per-image timeout | To remember your setting |
That is the complete list.
chrome://extensions. Chrome deletes its local storage
with it.Because nothing is ever sent to us, there is no copy anywhere for us to delete, and no account for you to close.
Accessing something locally is not the same as collecting it. For completeness, here is everything PromptMill touches:
On Google Flow pages (labs.google, flow.google.com — and nowhere else), a content script:
<img> elements on the page to detect when new images have finished generating.role="alert") so the queue can stop with a real explanation
instead of waiting out a timeout.All of this happens in the page, in memory, and is used only to drive the current run.
Files you load. Text files you drag in or open with the file button are read in your browser and their contents are placed into the prompt box. The files themselves are never copied or uploaded.
Images you generate. Images are saved to your Downloads folder using Chrome’s downloads API. Fetching an image downloads it from the same Google server your browser already loaded it from — no other server is involved, and the image never passes through the developer.
| Permission | Why |
|---|---|
debugger |
Google Flow’s prompt box is a Slate.js editor, which ignores synthetic keyboard events. Typing into it requires real input events at the browser layer, which only the Chrome DevTools Protocol can produce. |
downloads |
To save generated images to your Downloads folder. |
storage |
To remember your prompt list and settings locally (see the table above). |
tabs |
To find your open Google Flow tab. |
scripting |
To re-inject the content script into a Flow tab that was already open when the extension loaded. |
sidePanel |
To show the extension’s interface in Chrome’s side panel. |
Host access to labs.google and flow.google.com |
The only two sites the extension is allowed to run on. |
debugger permissionThis permission is powerful, so here is exactly what it is used for. Across the whole codebase, PromptMill issues only four DevTools Protocol commands:
| Command | Purpose |
|---|---|
Input.dispatchMouseEvent |
Click the prompt box to focus it |
Input.dispatchKeyEvent |
Select-all, and press Enter to submit |
Input.insertText |
Type your prompt |
Runtime.evaluate |
Called with the literal expression 1, and nothing else — a harmless probe to check whether the debugger session still belongs to this extension after Chrome restarts its service worker |
It is not used to execute arbitrary code, read page memory, intercept network traffic, or access any tab other than the Flow tab you are working in. Chrome displays a yellow “PromptMill is debugging this browser” banner the entire time the session is attached, so you always know when it is active.
There are none. No analytics provider, no error reporting service, no advertising network, no CDN, no telemetry of any kind. The extension loads no remote code and fetches no remote configuration.
None occurs, because no data is collected. PromptMill does not sell, rent, share, or transfer user data to anyone, and does not use any data for advertising, profiling, or creditworthiness assessment.
PromptMill’s use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
PromptMill is a developer/creator tool. It is not directed at children and collects no data from anyone, including children.
You do not have to take any of this on trust. The full source is in this repository, with no build step and no minification — what you read is what runs.
To check the central claim yourself, search the codebase for outbound network calls:
grep -rnE 'fetch\(|XMLHttpRequest|WebSocket|sendBeacon' *.js
You will find exactly one result, in content.js. It reads a blob: URL — an in-memory reference
that already exists inside the Flow page — so that an image held in memory can be saved to disk. A
blob: URL cannot reach the network; it resolves entirely within your browser.
If this policy changes, the effective date at the top will change and the revision will appear in this repository’s commit history, which is public and cannot be quietly rewritten.
Questions, or a privacy concern: open an issue at https://github.com/thuongvb/PromptMill/issues
Email: thuongvanbui39@gmail.com
PromptMill is released under the MIT License.