Ref extension privacy policy

Last updated: October 1, 2026

This policy describes how the Ref browser extension and the hosted Ref service handle information used by the extension. Contact: evanmpun@gmail.com.

Information we collect and use

When you choose to save, Ref reads the selected page's URL, title, media URLs, and relevant page content or metadata. Pinterest board capture can read pin links, titles, images, and embedded board data visible in the tab, including private content you choose to save. Ref sends captured items and collection choices to your configured Ref server (by default https://api.ref.design) to store, organize, and process your archive. The extension does not continuously record your browsing history.

The server origin and last-used collection choices are stored through Chrome Sync and may sync across your browsers according to your Chrome settings. Pinterest refresh consent is stored locally in the extension for a specific server. Ref uses your sign-in session for authenticated requests. The hosted service processes account information, including your email and any profile information provided during sign-in, to identify your account and provide access to your archive.

Optional Pinterest connection

Connect Pinterest asks for browser permission to read the _pinterest_sess authentication cookie and sends that cookie to the saved Ref server displayed beside the controls for signed-in Pinterest imports. This credential can grant access to Pinterest content available to your session. After connecting, Pinterest saves may refresh the stored session on that same server. Changing the server does not transfer this consent. Ordinary page capture does not require connecting Pinterest.

Disconnect stops automatic refresh in this browser, removes the extension's Pinterest cookie permissions, and requests deletion of the session held by the displayed server. If deletion cannot be confirmed, the extension reports this so you can sign in and retry. Disconnect does not sign you out of Pinterest, delete saved archive items, or disable connections in other browser installations.

How information is processed and shared

Ref uses information only to provide its features, including archive storage, imports, organization, search, analysis, and account access. Ref does not sell user data or use it for advertising, credit or lending decisions, or unrelated sharing.

The following services process information where enabled:

Cloudflare provides the API, database, media storage, image processing, and browser-assisted imports. Browser-assisted Pinterest imports may use the Pinterest session cookie you choose to connect.

Vercel hosts the Ref website.

Google provides optional Google sign-in, Chrome Sync, and cloud infrastructure used for media processing and analysis jobs.

Anthropic and OpenAI process saved images and related content for configured AI analysis features. OpenAI may also provide generated imagery for Ref features.

TypeSafe processes search queries and collection descriptions, names, and analysis summaries for configured search ranking.

Resend processes recipient addresses and message content for account and service emails.

Ref also contacts source websites and their media hosts to retrieve content you choose to import. Pinterest receives the connected session credential when it is used for authenticated Pinterest requests. If you use Ref's sharing features, the content you choose to share is available to the collaborators or link recipients you select.

If you configure a custom Ref server, its operator controls the information you send there and may have different processing practices. Review that operator's privacy policy before sending saved content or connecting Pinterest.

Retention and deletion

Saved references and media remain in your Ref archive until deletion is requested. Removing a reference from a collection or deleting a collection does not delete its underlying saved reference or media. Contact evanmpun@gmail.com to request deletion of hosted Ref data.

A connected Pinterest session remains stored until it is replaced or deleted. Use Disconnect to request deletion of that session. Uninstalling the extension does not itself delete server-held archive data or a previously stored Pinterest session.

Security and your controls

The extension requires HTTPS for remote server origins and rejects redirects for Pinterest credential requests. HTTP is available only on local loopback addresses for development. The Pinterest cookie value is not displayed by the extension interface.

You can change your server in Options, disconnect Pinterest, manage Chrome Sync, remove extension permissions, or uninstall the extension. For access, correction, deletion, or other privacy requests concerning the hosted Ref service, contact evanmpun@gmail.com.

Changes to this policy

We will update this policy when our data practices change. Changes to the extension's data practices will be disclosed to users.