# Privacy Policy — PromptMill

**Effective date:** 9 September 2026
**Applies to:** the PromptMill Chrome extension, all versions.

**English** · [Tiếng Việt](PRIVACY.vi.md)

---

## Summary

**PromptMill collects no data.** It has no server, no account system, no analytics, and no remote
configuration. Nothing you type, load, or generate is transmitted to the developer or to any third
party. Everything the extension stores stays in your own browser profile on your own computer.

This is verifiable rather than promised: the extension is open source, and the entire codebase
contains **no network calls to any server**. See [Verifying these claims](#verifying-these-claims).

---

## Data we collect

**None.** Using the categories defined by the Chrome Web Store's Privacy Practices disclosure:

| Category | Collected? |
|---|---|
| Personally identifiable information | **No** |
| Health information | **No** |
| Financial and payment information | **No** |
| Authentication information | **No** |
| Personal communications | **No** |
| Location | **No** |
| Web history | **No** |
| User activity | **No** |
| Website content | **No** |

"Collected" here has the meaning Google gives it: transmitted off your device. PromptMill transmits
nothing off your device.

---

## Data stored on your device

The extension saves the following to `chrome.storage.local`, which lives inside your browser profile
on your computer. It is never uploaded anywhere.

| Stored value | What it is | Why |
|---|---|---|
| `prompts` | The text in the prompt box | So your list survives closing the side panel |
| `queueItems` | Each prompt plus its status (pending / done / error / timeout) | So a finished prompt isn't generated again on the next run |
| `folder` | The download subfolder name you chose | To remember your setting |
| `serial` | Whether file numbering is on | To remember your setting |
| `timeoutMin` | Your per-image timeout | To remember your setting |

That is the complete list.

### Deleting it

- **Inside the extension:** the **Xoá tất cả** (Clear all) button empties the prompt list and queue.
- **Completely:** remove the extension at `chrome://extensions`. Chrome deletes its local storage
  with it.

Because nothing is ever sent to us, there is no copy anywhere for us to delete, and no account for
you to close.

---

## What the extension accesses while it runs

Accessing something locally is not the same as collecting it. For completeness, here is everything
PromptMill touches:

**On Google Flow pages** (`labs.google`, `flow.google.com` — and nowhere else), a content script:

- Locates the prompt input box, and reads its text back to verify what was typed actually landed.
- Reads `<img>` elements on the page to detect when new images have finished generating.
- Reads on-page error notices (`role="alert"`) so the queue can stop with a real explanation
  instead of waiting out a timeout.

All of this happens in the page, in memory, and is used only to drive the current run.

**Files you load.** Text files you drag in or open with the file button are read in your browser and
their contents are placed into the prompt box. The files themselves are never copied or uploaded.

**Images you generate.** Images are saved to your Downloads folder using Chrome's downloads API.
Fetching an image downloads it from the same Google server your browser already loaded it from — no
other server is involved, and the image never passes through the developer.

---

## Permissions, and why each is needed

| Permission | Why |
|---|---|
| `debugger` | Google Flow's prompt box is a [Slate.js](https://docs.slatejs.org/) editor, which ignores synthetic keyboard events. Typing into it requires real input events at the browser layer, which only the Chrome DevTools Protocol can produce. |
| `downloads` | To save generated images to your Downloads folder. |
| `storage` | To remember your prompt list and settings locally (see the table above). |
| `tabs` | To find your open Google Flow tab. |
| `scripting` | To re-inject the content script into a Flow tab that was already open when the extension loaded. |
| `sidePanel` | To show the extension's interface in Chrome's side panel. |
| Host access to `labs.google` and `flow.google.com` | The only two sites the extension is allowed to run on. |

### About the `debugger` permission

This permission is powerful, so here is exactly what it is used for. Across the whole codebase,
PromptMill issues only four DevTools Protocol commands:

| Command | Purpose |
|---|---|
| `Input.dispatchMouseEvent` | Click the prompt box to focus it |
| `Input.dispatchKeyEvent` | Select-all, and press Enter to submit |
| `Input.insertText` | Type your prompt |
| `Runtime.evaluate` | Called with the literal expression `1`, and nothing else — a harmless probe to check whether the debugger session still belongs to this extension after Chrome restarts its service worker |

It is **not** used to execute arbitrary code, read page memory, intercept network traffic, or access
any tab other than the Flow tab you are working in. Chrome displays a yellow "PromptMill is
debugging this browser" banner the entire time the session is attached, so you always know when it
is active.

---

## Third parties

There are none. No analytics provider, no error reporting service, no advertising network, no CDN,
no telemetry of any kind. The extension loads no remote code and fetches no remote configuration.

## Sale or transfer of data

None occurs, because no data is collected. PromptMill does not sell, rent, share, or transfer user
data to anyone, and does not use any data for advertising, profiling, or creditworthiness
assessment.

## Limited Use compliance

PromptMill's use of information complies with the
[Chrome Web Store User Data Policy](https://developer.chrome.com/docs/webstore/program-policies/user-data-faq),
including the Limited Use requirements.

## Children

PromptMill is a developer/creator tool. It is not directed at children and collects no data from
anyone, including children.

---

## Verifying these claims

You do not have to take any of this on trust. The full source is in this repository, with no build
step and no minification — what you read is what runs.

To check the central claim yourself, search the codebase for outbound network calls:

```bash
grep -rnE 'fetch\(|XMLHttpRequest|WebSocket|sendBeacon' *.js
```

You will find exactly one result, in `content.js`. It reads a `blob:` URL — an in-memory reference
that already exists inside the Flow page — so that an image held in memory can be saved to disk. A
`blob:` URL cannot reach the network; it resolves entirely within your browser.

---

## Changes to this policy

If this policy changes, the effective date at the top will change and the revision will appear in
this repository's commit history, which is public and cannot be quietly rewritten.

## Contact

Questions, or a privacy concern: open an issue at
**https://github.com/thuongvb/PromptMill/issues**

Email: **thuongvanbui39@gmail.com**

---

## License

PromptMill is released under the [MIT License](LICENSE).
