Privacy Policy
Last updated: 2026-09-12
Deepdeep is committed to protecting your privacy. This policy explains what data we collect and how we use it.
1. Data We Don't Collect
Deepdeep does not collect, store, or transmit any personal data to our servers. We have no servers. The extension runs entirely in your browser.
- No analytics — no usage tracking
- No telemetry — no crash reports or performance data
- No accounts — no login or registration system
2. Data Stored Locally
The following data is stored in your browser's local storage (chrome.storage.local) and never leaves your device unless you actively send it to your chosen AI provider:
| Data | Storage | Purpose |
|---|---|---|
| API settings (Base URL, key, model) | storage.local | Connect to your AI provider |
| System prompt, Temperature | storage.local | Customize AI behavior |
| Conversation history | storage.local | Saved conversations (one record per conversation plus a small index), so you can reopen past chats. Delete them anytime from the side panel |
| Job profile (name, contact, education, work history, ID number, family members, saved answers, etc.) | storage.local | Power the job-application autofill feature. Stored only on this device; export/import is a manual local file operation |
| Resume / photo documents attached to a job profile | storage.local (dedicated keys) | Attach files to application forms |
Local storage note: all of the above is stored unencrypted in your browser profile. Anyone with access to your device or browser profile can read it, including your API key and job profile. Protect it with OS-level disk encryption and device locking if needed.
Sensitive fields note: your job profile may include highly sensitive data such as your national ID number and family information. This data never leaves your device through Deepdeep itself. The autofill engine fills sensitive fields only from locally stored values via deterministic rules — they are never included in any prompt sent to an AI provider.
3. Data Sent to Third-Party AI Providers
Deepdeep is a BYOK (Bring Your Own Key) extension. When you send messages or use features, the following data is sent directly from your browser to your configured AI API provider (such as DeepSeek, OpenAI, Anthropic, MiMo):
- Your input messages
- Selected text from webpages (when using text selection popup or right-click menu)
- Page content (when using page summary, translation, or explanation; limited to ~12,000 chars)
- Tab content (when using
@tabreferences, up to ~8,000 chars per tab) - Web search queries (when the search toggle is on) — the query is first sent to DuckDuckGo (
html.duckduckgo.com) to fetch results, and those results are then included in the prompt sent to your AI provider - Images you right-click or select (when using vision features) — fetched directly from their source and sent to your AI provider as image data
- Your system prompt and temperature settings
This data is governed by your AI provider's privacy policy, not ours. We cannot access this data.
4. Permissions
| Permission | Why Needed |
|---|---|
| storage | Save API settings (profiles), conversation history, and job profiles |
| unlimitedStorage | Resume PDFs and photos attached to a job profile exceed the default 10 MB local quota |
| sidePanel | Display chat sidebar |
| contextMenus | Right-click "Explain / Translate / Summarize" on selected text |
| scripting | Read page content for summary and @tab context |
| tabs | List open tabs for @tab references |
| <all_urls> | Content script must work on all web pages for the text selection popup and job-application form detection; fetch images you right-click on (sent directly to your configured AI provider for vision models) |
5. API Key Security
Your API key is stored in chrome.storage.local and only sent to your configured AI provider via Authorization: Bearer header when you make a request. It is never logged, shared, or transmitted anywhere else.
6. Third-Party Libraries
| Library | License | Purpose |
|---|---|---|
| marked | MIT | Markdown rendering |
| DOMPurify | Apache-2.0/MPL-2.0 | HTML sanitization |
| Lucide | ISC | Icons |
7. Policy Changes
As the extension evolves, we may update this policy. Any changes will be posted on this page.
8. Contact Us
For privacy concerns: deepdeep@nopress.net