yDirect
Privacy Policy
Effective: August 10, 2026 · Last updated: August 21, 2026
This policy describes how Abhay Yemekar, an independent developer in Maharashtra, India, publishes yDirect ("yDirect," "we," "us," or "our") and processes information through the Chrome extension, account pages, cloud services, workspace sharing, and support.
Information we process
- Account data: Firebase user ID, email address, display name, authentication provider, email-verification state, account timestamps, and—if you use Google sign-in—the profile photo URL and basic profile information supplied by Google.
- Content and usage data: folder names, snippet labels and text, masked-value preference, links you deliberately store, creation/update timestamps, copy counters, last-used timestamps, and ownership metadata.
- Workspace data: workspace name, member identity and role, invitations, sharing grants, contributions, content revisions, and activity records needed to operate and secure shared workspaces.
- Backup and settings data: the latest and immediately previous cloud backup when you use cloud backup, backup schedule/status, theme, sort order, view mode, and floating-shortcut settings.
- Support data: rating, feedback text, optional account-deletion reason, account email and name, extension version, app surface, and any diagnostic details or screenshots you choose to provide.
- Security and service data: short-lived hashed network-address identifiers used to rate-limit public account-email requests, request/authentication metadata, error logs, and infrastructure logs generated by Firebase, Google Cloud, and our email provider.
We do not use yDirect to collect your browsing history, the contents of web pages, keystrokes, advertising identifiers, or precise location. Chrome's native side panel opens only after you invoke yDirect. We do not sell personal information, serve targeted advertising, or use snippet content for advertising.
Sources of information
We receive information from you when you create an account, enter content, configure sharing, create a backup, or contact support; from Google when you choose Google sign-in; from Firebase Authentication; and from other workspace users when they invite you, share content with you, or contribute to a workspace you can access.
Purposes and legal bases
- Provide the service: authenticate accounts, store and copy snippets, synchronize workspace changes, enforce roles, share selected resources, create exports and backups, and send requested account, deletion-confirmation, invitation, and new-share messages. Where applicable, this is necessary to perform our contract with you.
- Your choices: use optional cloud backup, Google sign-in, workspace sharing, and feedback features that you deliberately select. Where consent is the applicable basis, you may withdraw it by stopping the feature, signing out, deleting cloud data, or deleting your account.
- Security and reliability: prevent abuse, diagnose failures, protect accounts and workspaces, and improve service reliability. Where applicable, we rely on our legitimate interests in operating a safe service.
- Legal compliance: respond to valid legal requests, protect rights, and satisfy applicable recordkeeping obligations.
Local and cloud storage
An active copy is kept in Chrome extension storage on your device. Signed-in workspace content is stored in the yDirect Firebase/Google Cloud project so authorized accounts can access it. Cloud backup is optional and stores two recovery points: the latest successful backup and the immediately preceding backup. JSON and Excel exports are downloaded to a location you control. Unencrypted exports can expose every included snippet to anyone who obtains the file.
Service providers and recipients
- Google Firebase and Google Cloud: authentication, database, server functions, hosting, security, and operational logging.
- Google OAuth: optional Google account sign-in.
- Resend: delivery of verification, password-reset, account-deletion, invitation, new-share, and support-related transactional email. A new-share notice may include the workspace and shared folder or snippet name, but never the snippet value.
- Authorized workspace users: content, identity, and activity information within the access level you or an authorized manager grants.
Providers process information under their contracts and privacy terms. Information may be processed in countries other than yours, including the United States, subject to the transfer protections made available by those providers and applicable law. We may also disclose information when legally required or when reasonably necessary to protect users, the service, or legal rights.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
yDirect uses account and user data only to provide, maintain, secure, or improve its disclosed snippet-management, synchronization, backup, and sharing features. We do not use or transfer this data for personalized advertising, credit decisions, data-broker services, or unrelated profiling. We do not allow a person to read user content unless the user gives specific consent for support, access is necessary to investigate abuse or protect security, access is required by law, or the data has been aggregated and anonymized for permitted internal operations.
Chrome permissions
- Storage: save snippets, local account state, backup status, and preferences.
- Clipboard write: copy a snippet only when you request it or invoke the copy-last shortcut.
- Active tab and scripting: attach yDirect to the active supported page after you invoke the extension. yDirect does not request permanent access to every site.
- Identity: complete Google sign-in through Chrome.
- Alarms: schedule automatic-backup checks at the frequency you select.
- Cloud Functions host access: send authenticated requests to yDirect's server endpoints for accounts, workspaces, backup, sharing, and feedback.
Retention
- Local extension data remains until you clear it, uninstall the extension, or Chrome removes extension storage.
- Account, active workspace, membership, sharing, and backup records remain while needed to provide your account or the relevant workspace. A backup save retains the latest and immediately previous recovery point.
- Trashed workspace folders and snippets are scheduled for deletion after 30 days. Workspace activity records may remain for the life of the workspace for access integrity and security.
- Feedback records are scheduled for deletion within 12 months. A delivered copy may remain in the support mailbox for up to 12 months or longer if needed to resolve an active request or comply with law.
- Application rate-limit records are scheduled for deletion within two days. Infrastructure security logs and transactional-email delivery records follow the provider's configured retention and backup cycles.
- When account deletion starts, a temporary deletion job stores the account identifier, account email, optional exit feedback, and processing status only until cleanup and transactional email finish. Completed jobs are deleted immediately. Interrupted jobs carry a seven-day expiration timestamp; the corresponding Firestore TTL policy is a required production-retention control.
- When you complete in-app account deletion, yDirect deletes your Firebase Authentication account, personal cloud backups, owned workspaces, memberships, grants, invitations, and stored feedback. We send a transactional deletion confirmation to the account email. If you voluntarily provide an exit reason, a copy is delivered to the support mailbox and follows the support-mail retention described above. Residual encrypted backups or provider logs may persist for a limited period before automatic expiry and are not used to restore your account.
Security
We use verified authentication, recent-login checks for account deletion, server-side authorization, scoped sharing grants, write-conflict detection, HTTPS, payload limits, rate limits, and provider security controls. No system is completely secure. yDirect is a productivity tool, not a password manager; do not store passwords, payment-card data, private keys, recovery codes, health records, government identifiers, or other highly sensitive secrets as ordinary snippets.
Your choices and rights
You can update your display name, enable or disable automatic backup, export your content, remove shared access, leave external workspaces, sign out, clear local data, and delete your account in yDirect settings. An export supplies the content available to your signed-in account. To request access, correction, deletion, portability, restriction, objection, or withdrawal of consent for other records, email support@ydirect.tech. We may verify your identity before fulfilling a request.
Depending on where you live, you may have additional rights. EEA/UK users may complain to their local data-protection authority. California residents may request to know, access, correct, or delete covered personal information and may exercise applicable rights without discrimination. yDirect does not sell or share personal information for cross-context behavioral advertising and therefore does not offer a “Do Not Sell or Share” link.
Children
yDirect is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If local law requires a higher age to consent to online services, use yDirect only with authorization from a parent or guardian.
Policy changes
We may update this policy when features, providers, or legal requirements change. We will revise the effective date and provide additional notice when required by law.
Contact
Publisher and data contact: Abhay Yemekar, Maharashtra, India. For privacy requests or product support, email support@ydirect.tech. Do not include passwords, authentication links, or sensitive snippet content.