Privacy Policy
Operator information
This policy is issued by TinyForge ("we", "us"), operator of tinyforge.space and its browser extensions. If you have questions, contact tinyforge.space@yahoo.com.
What this policy covers
The first part below applies to TinyForge as a whole — the website, purchases, and every extension we publish. After it, a separate part covers each individual extension, since what a given extension reads on your device depends on what that extension does. Currently published: Color Catcher.
Applies to all TinyForge products
The website, the purchase flow, and every extension we publish.
What we never do
- No analytics, telemetry, crash reporting, or advertising SDKs — in the extensions or on this website.
- No tracking of the websites you visit or your browsing history.
- No user accounts, logins, or profiles — you never create a username or password with us.
- No selling or sharing of data with third parties other than Paddle (payment processing) and the infrastructure provider hosting our own server.
What does identify you
If you only use the free features, we hold nothing about you: no email, no name, nothing that leaves your device. Not having accounts genuinely means we have no idea who you are.
That changes once you buy. Paddle passes us the email address you paid with, and we store it next to your transaction ID (see Payments below). An email address identifies you personally, and we use it to verify support and recovery requests. The device ID the extension generates is random and meaningless on its own — but once a purchase is activated, it's linked to that transaction, and therefore to your email.
Payments
Purchases are handled on this website, outside the extension. Checkout is run by Paddle.com Ltd, our payment provider and merchant of record. Paddle collects your email address, payment details, and billing address directly, per Paddle's own privacy policy. We never see or handle your card details.
After a successful purchase, Paddle notifies our server via webhook, and we store the transaction ID, Paddle customer ID, email address, product, and price. If a payment attempt fails, Paddle also notifies us; we log the email, price, and failure reason purely so support can confirm to a customer that an attempted charge did occur. Failed attempts never grant access.
Purchase verification
To unlock a paid extension you paste your Paddle transaction ID into it. The extension then
sends three things to api.tinyforge.space/verify over HTTPS: that transaction ID,
a randomly generated device ID, and which product is asking. The device ID isn't derived from
any hardware or account identifier — it identifies one browser installation so we can count
how many devices a purchase has been activated on, nothing more. The server replies only with
whether the purchase is valid and how many activation slots are used; it never sends
transaction or payment details back.
Data retention
Data stored locally by an extension stays on your device until you remove the extension or clear its storage. Purchase and activation records on our server are kept for as long as needed to support license activation, recovery, and customer support. Failed payment logs are retained only for support reference and contain no access-granting data.
Your rights
You can ask us what data we hold tied to your transaction ID or email, or ask us to delete it, by writing to tinyforge.space@yahoo.com from the email address used for the purchase. Because we don't operate accounts, we verify requests against the purchase email on file with Paddle.
Security
All network requests use HTTPS. Our server verifies Paddle's webhook signature before trusting any payment notification. Paddle's secret API key and webhook signing secret are held only on our server, never inside an extension package.
Children's privacy
Our products are not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
We may update this policy as our products evolve — including adding a new part when a new extension is published. Material changes will be reflected here with an updated "Last updated" date.
Color Catcher
Applies to the Color Catcher Chrome extension specifically.
What the extension does
Color Catcher scans the page you're on for the colors it uses, and lets you click a single element to inspect its colors and typography. All of this runs entirely inside your browser. Page content, extracted colors, CSS, and typography are processed in memory and are never transmitted anywhere, logged, or stored.
The only data that leaves your device is the purchase verification described in the common part above — and only if you actually buy lifetime access and activate it.
What it stores on your device
Kept in chrome.storage.local, readable only by the extension:
- Free-use counters — how many free uses of "Get palette" and "Pick element" you have left.
- Device ID — the random identifier described above, generated the first time it's needed.
- Lifetime access status and transaction ID — set once a purchase is verified.
Chrome permissions
| Permission | Why |
|---|---|
activeTab | Lets you run "Get palette" / "Pick element" on the tab you're currently viewing, only when you click the extension. |
scripting | Injects the color-extraction and element-picker code into that tab. |
storage | Stores the free-use counters, device ID, and license status listed above. |
Host permission for api.tinyforge.space | Allows the extension to call our verification endpoint to check a purchase. |