Your prompt context
stays yours.
This policy covers the CacheTray Chrome extension, the website at cachetray.gitflex.lol, the phone web app, and optional Pro billing.
What CacheTray stores
CacheTray stores the following data locally on your device using your browser's built-in storage API:
- Prompt assets you copy โ screenshots, images, links, code snippets, plain text, and notes
- Workspace names, tab colors, and organization preferences
- Category filter preferences and favourite items
- Timestamps of when items were saved
- Auto-capture toggle state (on/off)
This data stays in browser-managed storage by default. Pairing a phone enables the transfer and automatic clip-sync features described below. The phone web app stores its device credentials and preferences in browser storage and caches app files so it can be opened from your home screen.
What we do NOT collect
- No account is required for local-only use or QR phone pairing.
- We do not collect your general browsing history. URLs and titles you choose to save, or links you copy into CacheTray, become part of your saved clips and can sync to your paired phone.
- We do not add advertising or clipboard-content analytics to the extension. The backend does keep image-send usage records to enforce plan limits.
- The transfer service can generate operational error logs. Cloudflare processes technical request information, including IP addresses, for hosting, security and service operation.
- Device IDs identify paired installations; they are not used for advertising.
- We do not receive or store your card details. Optional Pro payments are processed by Dodo Payments.
Where your data goes
Images you send. If you use Send to Phone, the selected image is uploaded directly from your extension to a private Cloudflare R2 bucket using a short-lived upload URL. A Cloudflare Worker/D1 backend stores the filename, MIME type, size, device IDs, and transfer times. The paired phone can request a short-lived download URL. The original image remains in local IndexedDB. The transfer is hidden after 24 hours; R2 lifecycle deletion may take longer.
Automatic clip sync after pairing. Recent text, links, code and tasks are sent to Cloudflare D1 while your phone is paired, within your plan limits. The synced snapshot contains clip content, URLs, timestamps, item IDs and task completion state. Only clips from the last 24 hours are eligible; each snapshot expires 24 hours after its latest update and is removed by scheduled cleanup. Updates replace the previous snapshot. Images are not uploaded automatically. Disconnect the phone in the extension to stop future sync to it; disconnecting alone does not immediately erase existing cloud copies.
Pairing and usage. Our backend stores random device IDs, device names and platform labels, hashed device tokens and pairing codes, pairing relationships, connection timestamps, and image-send usage records. These support authentication, device status, rate limiting and Free/Pro limits. QR pairing sessions and pairing phrases expire after 10 minutes.
Optional Pro billing. Dodo Payments processes checkout, subscription management and payment information. Our backend stores checkout, subscription and provider customer IDs, subscription status and renewal dates, your random extension device ID, and a hash of your recovery key. Keep your recovery key private: it can restore your subscription to another installation. Billing records are separate from temporary transfers and are not automatically removed after 24 hours.
Separately, when you use the right-click "Save image" feature, your browser may fetch the image URL to save it locally. This is a standard browser action โ not an upload to our transfer service.
AI chats and sharing. When you choose to insert a clip into an AI chat or share it with another app, the destination service receives the content you send and handles it under its own policy. This is separate from CacheTray phone sync.
Support. If you email us, we receive your email address and the message or attachments you provide. We use these to answer your request and troubleshoot the issue. Do not send passwords, card details or recovery keys.
Permissions and why we need them
| Permission | Why it's needed |
|---|---|
| clipboardRead | To automatically detect and save copied prompt assets (Ctrl+C) into your local workspace. |
| clipboardWrite | To copy a saved item back to your clipboard when you click copy inside the extension. |
| storage | To save your notes, workspaces, and preferences locally, plus opt-in pairing information. |
| unlimitedStorage | To retain locally saved image data without the extension's usual storage quota. Available disk space and browser behavior still apply. |
| alarms | To schedule local expiry cleanup and refresh clips for paired phones. |
| activeTab | To read the current tab's URL and title when you click "Save current tab". Only triggered by your explicit action. |
| scripting | To inject a lightweight script that detects copy events and inserts selected text/images into focused inputs such as AI chat composers. |
| contextMenus | To add right-click options โ Save link, Save image, Save selection โ directly from any webpage. |
| offscreen | To access clipboard data and process images through an offscreen document in Chrome Manifest V3. |
| sidePanel | To open CacheTray as a persistent side panel beside Claude, ChatGPT, NotebookLM, docs, or research tabs. No data is transmitted by opening the panel. |
| HTTP/HTTPS host access | To detect copied content on supported webpages, fetch images you save, insert selected clips into focused inputs, and contact the phone-transfer service. It is not used to collect your general browsing history. |
Third-party services
The website and phone-transfer service use Cloudflare Pages, Workers, D1 and private R2 storage. See Cloudflare's privacy policy. Pro checkout and subscription management use Dodo Payments, which handles payment, tax and fraud-prevention data under its own policies; see Dodo Payments' data-processing information.
The current phone-pairing flow does not require Google sign-in or Firebase. Older preview versions included optional Google/Firebase sync; upgrading does not itself delete any data previously stored by that feature. Contact support if you used that preview and need help with its cloud data.
The website loads Google Fonts and may load third-party embeds such as the Product Hunt badge. Those providers receive the requests needed to display these resources. External services and email providers handle information according to their own policies. Hosting and payment services may process data outside your country.
How we use and protect information
We use data to provide the features you choose, deliver clips to paired devices, verify Pro subscriptions, enforce usage limits, prevent abuse and respond to support requests. We do not sell your clipboard content or use it for advertising or AI model training.
Transfers use HTTPS, authenticated device requests and short-lived image URLs. Cloud phone transfers are not end-to-end encrypted: the service processes synced clip content and stores uploaded images. Keep device credentials, recovery keys and signed image URLs private. No online service can guarantee absolute security.
Data retention and deletion
Local history is subject to the extension's 3-day cleanup; cleanup runs while the browser/extension can operate, so removal is not guaranteed at an exact instant. Send to Phone images are visible for 24 hours; R2 lifecycle deletion runs asynchronously and can take longer. Expired transfer metadata is currently retained in D1 but no longer returned in the phone inbox.
Deleting an image from the phone inbox requests deletion of its R2 object and transfer record. It does not delete your extension's original or copies downloaded or shared elsewhere. The separate Free image-send usage record remains until its rolling 24-hour allowance expires; deleting an image does not reset that allowance. Expired clip snapshots and pairing sessions are removed by scheduled cleanup.
Device, pairing, billing and support records have separate retention from temporary clip content. They are not all automatically deleted after 24 hours. Billing and payment records may need to be retained for subscription operation, fraud prevention, disputes or legal requirements. Cancelling Pro stops renewal according to your subscription settings; it is not a request to erase all data.
You can manage your local data:
- Delete individual items using the trash icon
- Bulk-select and delete multiple items at once
- Clear an entire workspace with the "Clear all" button
- Uninstall the extension to delete its local data; this does not immediately delete previously sent R2 transfers
Clearing the phone site's browser storage removes its local identity and preferences; it does not immediately erase server records. For access, correction or deletion requests concerning cloud or support data, email treastingmike@gmail.com. We may need to verify that the records belong to you without asking for your password or recovery key. Requests are subject to applicable law and any records that must be retained. Requests about payment data held by Dodo Payments may also need to be handled by Dodo Payments.
Children's privacy
CacheTray is not directed at children under 13. We do not knowingly collect data from children.
Changes to this policy
If this policy is updated, the "Last updated" date at the top of this page will reflect the change. Significant changes will also be noted in the extension's store changelog.
Contact
Questions about this privacy policy? Reach out at: treastingmike@gmail.com