ClickSaveChrome extension

Privacy Policy

ClickSave does not collect, store, or sell any personal data.

Last updated: 8 October 2026

There are no analytics, no tracking and no accounts. The one thing ClickSave ever sends to us is a feedback message — and only when you write one and press Send.

Everything else ClickSave does happens locally in your browser. It finds images on the page you are looking at, and when you ask for one, it downloads that image to your computer. Nothing about you, your browsing, or the pages you visit is sent anywhere.

What runs, and when

ClickSave adds a small hover button to images so that saving one is a single click. For that button to be there when your pointer reaches an image, the extension’s script has to already be running on the page — so unlike a click-to-activate tool, ClickSave’s content script loads on every site you visit. We would rather state that plainly than bury it.

What that script does is narrow: it watches pointer movement, works out which image is under the cursor, and draws a button. It does not read page text, form fields, passwords, or cookies, and it sends nothing anywhere. On pages where it would be in the way, it disables itself using a bundled list of site rules that ships inside the extension — that list is read from local files, never fetched.

Network requests

Apart from the feedback form (below), ClickSave makes exactly two kinds of outbound request, both to the image you chose to save:

Both are sent with credentials: 'omit', so your cookies and session for that site are not attached. If a site blocks hotlinking, ClickSave retries once with a Referer header set to that site’s own origin — that is the only header it adds, and it identifies the site, not you.

The feedback form is the only other network destination in the extension. Styles, translations and the site-rules list all come from files bundled in the package.

Permissions

Feedback

The popup has a feedback form. Nothing is sent until you press Send. Then it posts, to clicksave-feedback.gba3124.workers.dev:

That address is a small relay we run on Cloudflare Workers. It forwards the message as an email to the developer through Resend (an email-sending service) and keeps no copy of it; it reads your IP address only to limit how many messages one address can send per minute. Cloudflare and Resend handle the message as our service providers, and the email then sits in the developer’s inbox. To have a message deleted, write to the address under Contact.

Data use

For the Chrome Web Store’s data-use declarations, ClickSave declares Personally identifiable information — the optional email address in the feedback form — and no other category. It meets all three certifications: no sale of data to third parties, no use for purposes unrelated to the single purpose, and no use to determine creditworthiness or for lending.

Changes

If this policy ever changes, the revision date above changes with it. Any change that affects what the extension does with your data will ship alongside the extension update that introduces it.

Contact

Questions or reports: gba3124@gmail.com