๐Ÿ” Privacy Policy

Your prompt context
stays yours.

Last updated: October 6, 2026

This policy covers the CacheTray Chrome extension, the website at cachetray.gitflex.lol, the phone web app, and optional Pro billing.

TL;DR โ€” The short version
โœ“ Your clipboard collection stays local when no phone is paired.
โœ“ Pairing enables automatic sync of recent text, links, code and tasks. Images are sent only when you choose Send to Phone.
โœ“ Phone items are temporary: images expire after 24 hours. Physical cloud deletion can take longer.
โœ“ Deleting or uninstalling the extension removes local data, not existing cloud transfers immediately.
โœ“ Pro checkout uses Dodo Payments. CacheTray does not receive your full card details.

What CacheTray stores

CacheTray stores the following data locally on your device using your browser's built-in storage API:

This data stays in browser-managed storage by default. Pairing a phone enables the transfer and automatic clip-sync features described below. The phone web app stores its device credentials and preferences in browser storage and caches app files so it can be opened from your home screen.

What we do NOT collect

Where your data goes

Images you send. If you use Send to Phone, the selected image is uploaded directly from your extension to a private Cloudflare R2 bucket using a short-lived upload URL. A Cloudflare Worker/D1 backend stores the filename, MIME type, size, device IDs, and transfer times. The paired phone can request a short-lived download URL. The original image remains in local IndexedDB. The transfer is hidden after 24 hours; R2 lifecycle deletion may take longer.

Automatic clip sync after pairing. Recent text, links, code and tasks are sent to Cloudflare D1 while your phone is paired, within your plan limits. The synced snapshot contains clip content, URLs, timestamps, item IDs and task completion state. Only clips from the last 24 hours are eligible; each snapshot expires 24 hours after its latest update and is removed by scheduled cleanup. Updates replace the previous snapshot. Images are not uploaded automatically. Disconnect the phone in the extension to stop future sync to it; disconnecting alone does not immediately erase existing cloud copies.

Pairing and usage. Our backend stores random device IDs, device names and platform labels, hashed device tokens and pairing codes, pairing relationships, connection timestamps, and image-send usage records. These support authentication, device status, rate limiting and Free/Pro limits. QR pairing sessions and pairing phrases expire after 10 minutes.

Optional Pro billing. Dodo Payments processes checkout, subscription management and payment information. Our backend stores checkout, subscription and provider customer IDs, subscription status and renewal dates, your random extension device ID, and a hash of your recovery key. Keep your recovery key private: it can restore your subscription to another installation. Billing records are separate from temporary transfers and are not automatically removed after 24 hours.

Separately, when you use the right-click "Save image" feature, your browser may fetch the image URL to save it locally. This is a standard browser action โ€” not an upload to our transfer service.

AI chats and sharing. When you choose to insert a clip into an AI chat or share it with another app, the destination service receives the content you send and handles it under its own policy. This is separate from CacheTray phone sync.

Support. If you email us, we receive your email address and the message or attachments you provide. We use these to answer your request and troubleshoot the issue. Do not send passwords, card details or recovery keys.

Permissions and why we need them

PermissionWhy it's needed
clipboardReadTo automatically detect and save copied prompt assets (Ctrl+C) into your local workspace.
clipboardWriteTo copy a saved item back to your clipboard when you click copy inside the extension.
storageTo save your notes, workspaces, and preferences locally, plus opt-in pairing information.
unlimitedStorageTo retain locally saved image data without the extension's usual storage quota. Available disk space and browser behavior still apply.
alarmsTo schedule local expiry cleanup and refresh clips for paired phones.
activeTabTo read the current tab's URL and title when you click "Save current tab". Only triggered by your explicit action.
scriptingTo inject a lightweight script that detects copy events and inserts selected text/images into focused inputs such as AI chat composers.
contextMenusTo add right-click options โ€” Save link, Save image, Save selection โ€” directly from any webpage.
offscreenTo access clipboard data and process images through an offscreen document in Chrome Manifest V3.
sidePanelTo open CacheTray as a persistent side panel beside Claude, ChatGPT, NotebookLM, docs, or research tabs. No data is transmitted by opening the panel.
HTTP/HTTPS host accessTo detect copied content on supported webpages, fetch images you save, insert selected clips into focused inputs, and contact the phone-transfer service. It is not used to collect your general browsing history.

Third-party services

The website and phone-transfer service use Cloudflare Pages, Workers, D1 and private R2 storage. See Cloudflare's privacy policy. Pro checkout and subscription management use Dodo Payments, which handles payment, tax and fraud-prevention data under its own policies; see Dodo Payments' data-processing information.

The current phone-pairing flow does not require Google sign-in or Firebase. Older preview versions included optional Google/Firebase sync; upgrading does not itself delete any data previously stored by that feature. Contact support if you used that preview and need help with its cloud data.

The website loads Google Fonts and may load third-party embeds such as the Product Hunt badge. Those providers receive the requests needed to display these resources. External services and email providers handle information according to their own policies. Hosting and payment services may process data outside your country.

How we use and protect information

We use data to provide the features you choose, deliver clips to paired devices, verify Pro subscriptions, enforce usage limits, prevent abuse and respond to support requests. We do not sell your clipboard content or use it for advertising or AI model training.

Transfers use HTTPS, authenticated device requests and short-lived image URLs. Cloud phone transfers are not end-to-end encrypted: the service processes synced clip content and stores uploaded images. Keep device credentials, recovery keys and signed image URLs private. No online service can guarantee absolute security.

Data retention and deletion

Local history is subject to the extension's 3-day cleanup; cleanup runs while the browser/extension can operate, so removal is not guaranteed at an exact instant. Send to Phone images are visible for 24 hours; R2 lifecycle deletion runs asynchronously and can take longer. Expired transfer metadata is currently retained in D1 but no longer returned in the phone inbox.

Deleting an image from the phone inbox requests deletion of its R2 object and transfer record. It does not delete your extension's original or copies downloaded or shared elsewhere. The separate Free image-send usage record remains until its rolling 24-hour allowance expires; deleting an image does not reset that allowance. Expired clip snapshots and pairing sessions are removed by scheduled cleanup.

Device, pairing, billing and support records have separate retention from temporary clip content. They are not all automatically deleted after 24 hours. Billing and payment records may need to be retained for subscription operation, fraud prevention, disputes or legal requirements. Cancelling Pro stops renewal according to your subscription settings; it is not a request to erase all data.

You can manage your local data:

Clearing the phone site's browser storage removes its local identity and preferences; it does not immediately erase server records. For access, correction or deletion requests concerning cloud or support data, email treastingmike@gmail.com. We may need to verify that the records belong to you without asking for your password or recovery key. Requests are subject to applicable law and any records that must be retained. Requests about payment data held by Dodo Payments may also need to be handled by Dodo Payments.

Children's privacy

CacheTray is not directed at children under 13. We do not knowingly collect data from children.

Changes to this policy

If this policy is updated, the "Last updated" date at the top of this page will reflect the change. Significant changes will also be noted in the extension's store changelog.

Contact

Questions about this privacy policy? Reach out at: treastingmike@gmail.com