Skip to main content

Browser Extension Privacy Policy

Last Updated: August 11, 2026

This policy covers the VCbacked browser extension. Our general Privacy Policy covers vcbacked.co and the web application.

What the extension collects

  • The hostname of the tab you are viewing — for example stripe.com. This is sent to our servers so we can look up whether that company is in the VCbacked database. We do not receive the full URL, the page path, query strings, or the content of any page.
  • Your account credentials at sign-in — your email address and password are sent once to our authentication provider to establish a session. The password is never stored by the extension.
  • A record of lookups — we count lookups per account to enforce fair-use limits and to detect abuse.

What it never collects

  • Page content. The extension injects no scripts into the sites you visit.
  • Full URLs, paths, or search queries.
  • Browsing history on sites that are not looked up.
  • Keystrokes, form data, cookies, or credentials belonging to other sites.

Why each permission is needed

  • tabs — to read the hostname of the active tab, so the toolbar icon can indicate whether that company is in the database and the panel can show the right record. Only the hostname is used.
  • storage — to keep your signed-in session on your own device so you do not have to sign in on every page. Stored in chrome.storage.local, readable only by this extension.
  • Host access to our own API domain — the extension communicates with VCbacked servers only. It has no access to any other website.

Storage and retention

Your session is stored locally on your device and is removed when you sign out or remove the extension. Lookup counts are retained on our servers for fair-use enforcement and are deleted on the same schedule as our other operational logs.

Data sharing

We do not sell data collected by the extension, and we do not share it with third parties for advertising or any purpose unrelated to operating the service. Data is processed by our infrastructure providers (Supabase for authentication and data, Stripe for billing) solely to deliver the service.

Contact

Questions about this policy: [email protected]. You can request deletion of your account and associated data at any time from your account settings or by contacting us.