ClickSave does not collect, store, or sell any personal data.
Last updated: 8 October 2026
There are no analytics, no tracking and no accounts. The one thing ClickSave ever sends to us is a feedback message — and only when you write one and press Send.
Everything else ClickSave does happens locally in your browser. It finds images on the page you are looking at, and when you ask for one, it downloads that image to your computer. Nothing about you, your browsing, or the pages you visit is sent anywhere.
ClickSave adds a small hover button to images so that saving one is a single click. For that button to be there when your pointer reaches an image, the extension’s script has to already be running on the page — so unlike a click-to-activate tool, ClickSave’s content script loads on every site you visit. We would rather state that plainly than bury it.
What that script does is narrow: it watches pointer movement, works out which image is under the cursor, and draws a button. It does not read page text, form fields, passwords, or cookies, and it sends nothing anywhere. On pages where it would be in the way, it disables itself using a bundled list of site rules that ships inside the extension — that list is read from local files, never fetched.
Apart from the feedback form (below), ClickSave makes exactly two kinds of outbound request, both to the image you chose to save:
HEAD request to check whether a higher-resolution version of
the image exists, so you get the original rather than a thumbnail.GET request to download the image bytes, for saving, batching
into a ZIP, or converting between PNG / JPG / WebP.Both are sent with credentials: 'omit', so your cookies and
session for that site are not attached. If a site blocks hotlinking, ClickSave
retries once with a Referer header set to that site’s own
origin — that is the only header it adds, and it identifies the site, not
you.
The feedback form is the only other network destination in the extension. Styles, translations and the site-rules list all come from files bundled in the package.
activeTab / scripting — reach
the page you are on so the hover button and the image scan can run.activeTab does not extend to background fetches, so this is
the only way to read cross-origin image data.downloads — save the image to your normal
downloads folder. ClickSave cannot read your download history with this; it
only writes.storage — remember your settings.
chrome.storage.sync holds preferences (button size, format,
per-site on/off); chrome.storage.local records only whether you
have seen the onboarding screen. The developer has no access to either.sidePanel — show the gallery of images
found on the current page.contextMenus — add ClickSave’s entry to
the right-click menu.The popup has a feedback form. Nothing is sent until you press
Send. Then it posts, to
clicksave-feedback.gba3124.workers.dev:
That address is a small relay we run on Cloudflare Workers. It forwards the message as an email to the developer through Resend (an email-sending service) and keeps no copy of it; it reads your IP address only to limit how many messages one address can send per minute. Cloudflare and Resend handle the message as our service providers, and the email then sits in the developer’s inbox. To have a message deleted, write to the address under Contact.
For the Chrome Web Store’s data-use declarations, ClickSave declares Personally identifiable information — the optional email address in the feedback form — and no other category. It meets all three certifications: no sale of data to third parties, no use for purposes unrelated to the single purpose, and no use to determine creditworthiness or for lending.
If this policy ever changes, the revision date above changes with it. Any change that affects what the extension does with your data will ship alongside the extension update that introduces it.
Questions or reports: gba3124@gmail.com