PromptMill

Privacy Policy — PromptMill

Effective date: 9 September 2026 Applies to: the PromptMill Chrome extension, all versions.

English · Tiếng Việt


Summary

PromptMill collects no data. It has no server, no account system, no analytics, and no remote configuration. Nothing you type, load, or generate is transmitted to the developer or to any third party. Everything the extension stores stays in your own browser profile on your own computer.

This is verifiable rather than promised: the extension is open source, and the entire codebase contains no network calls to any server. See Verifying these claims.


Data we collect

None. Using the categories defined by the Chrome Web Store’s Privacy Practices disclosure:

Category Collected?
Personally identifiable information No
Health information No
Financial and payment information No
Authentication information No
Personal communications No
Location No
Web history No
User activity No
Website content No

“Collected” here has the meaning Google gives it: transmitted off your device. PromptMill transmits nothing off your device.


Data stored on your device

The extension saves the following to chrome.storage.local, which lives inside your browser profile on your computer. It is never uploaded anywhere.

Stored value What it is Why
prompts The text in the prompt box So your list survives closing the side panel
queueItems Each prompt plus its status (pending / done / error / timeout) So a finished prompt isn’t generated again on the next run
folder The download subfolder name you chose To remember your setting
serial Whether file numbering is on To remember your setting
timeoutMin Your per-image timeout To remember your setting

That is the complete list.

Deleting it

Because nothing is ever sent to us, there is no copy anywhere for us to delete, and no account for you to close.


What the extension accesses while it runs

Accessing something locally is not the same as collecting it. For completeness, here is everything PromptMill touches:

On Google Flow pages (labs.google, flow.google.com — and nowhere else), a content script:

All of this happens in the page, in memory, and is used only to drive the current run.

Files you load. Text files you drag in or open with the file button are read in your browser and their contents are placed into the prompt box. The files themselves are never copied or uploaded.

Images you generate. Images are saved to your Downloads folder using Chrome’s downloads API. Fetching an image downloads it from the same Google server your browser already loaded it from — no other server is involved, and the image never passes through the developer.


Permissions, and why each is needed

Permission Why
debugger Google Flow’s prompt box is a Slate.js editor, which ignores synthetic keyboard events. Typing into it requires real input events at the browser layer, which only the Chrome DevTools Protocol can produce.
downloads To save generated images to your Downloads folder.
storage To remember your prompt list and settings locally (see the table above).
tabs To find your open Google Flow tab.
scripting To re-inject the content script into a Flow tab that was already open when the extension loaded.
sidePanel To show the extension’s interface in Chrome’s side panel.
Host access to labs.google and flow.google.com The only two sites the extension is allowed to run on.

About the debugger permission

This permission is powerful, so here is exactly what it is used for. Across the whole codebase, PromptMill issues only four DevTools Protocol commands:

Command Purpose
Input.dispatchMouseEvent Click the prompt box to focus it
Input.dispatchKeyEvent Select-all, and press Enter to submit
Input.insertText Type your prompt
Runtime.evaluate Called with the literal expression 1, and nothing else — a harmless probe to check whether the debugger session still belongs to this extension after Chrome restarts its service worker

It is not used to execute arbitrary code, read page memory, intercept network traffic, or access any tab other than the Flow tab you are working in. Chrome displays a yellow “PromptMill is debugging this browser” banner the entire time the session is attached, so you always know when it is active.


Third parties

There are none. No analytics provider, no error reporting service, no advertising network, no CDN, no telemetry of any kind. The extension loads no remote code and fetches no remote configuration.

Sale or transfer of data

None occurs, because no data is collected. PromptMill does not sell, rent, share, or transfer user data to anyone, and does not use any data for advertising, profiling, or creditworthiness assessment.

Limited Use compliance

PromptMill’s use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Children

PromptMill is a developer/creator tool. It is not directed at children and collects no data from anyone, including children.


Verifying these claims

You do not have to take any of this on trust. The full source is in this repository, with no build step and no minification — what you read is what runs.

To check the central claim yourself, search the codebase for outbound network calls:

grep -rnE 'fetch\(|XMLHttpRequest|WebSocket|sendBeacon' *.js

You will find exactly one result, in content.js. It reads a blob: URL — an in-memory reference that already exists inside the Flow page — so that an image held in memory can be saved to disk. A blob: URL cannot reach the network; it resolves entirely within your browser.


Changes to this policy

If this policy changes, the effective date at the top will change and the revision will appear in this repository’s commit history, which is public and cannot be quietly rewritten.

Contact

Questions, or a privacy concern: open an issue at https://github.com/thuongvb/PromptMill/issues

Email: thuongvanbui39@gmail.com


License

PromptMill is released under the MIT License.