privacy policy
Private by design — not by promise.
Last updated: July 18, 2026 · Applies to the Deja browser extension
What Deja collects and stores
- Prompt text you submit on the supported sites below, saved to a local database (IndexedDB) in your browser profile — on your device, nowhere else.
- Your settings (capture preferences, blocklist rules, capture-health status), saved in the browser's local extension storage on your device.
- Nothing else. Deja does not collect browsing history, page content, AI responses, or any usage/telemetry data.
What Deja never does
- No network transmission. The extension makes no requests to any server. Your data cannot leak because it is never sent.
- No telemetry or analytics — not even anonymous usage statistics or crash reports.
- No accounts, no cloud, no third-party services.
- No reading of the AI's responses — only the prompt text you type is saved.
- No credential capture. Password, one-time-code, and payment fields are structurally excluded from capture, and saved URLs are stripped of query strings and fragments.
Built-in protections
-
Personal-info redaction (on by default). Before a prompt is saved,
detected personal information — email addresses, phone numbers, credit-card numbers,
API keys and similar secrets — is replaced with labels like
[email]. The raw values never reach the database or your exports. Tunable per category in settings. - Pause anytime. One click pauses all capture; individual sites can be switched off; incognito windows are auto-paused by default.
- Blocklist. You can block sites or regex patterns so matching prompts are never stored.
Where your data lives, and how to delete it
Everything lives in your browser profile on your device. You are in full control:
- Export your entire library as JSON or Markdown at any time — no lock-in.
- Delete individual prompts (undoable), purge deleted prompts permanently, or erase everything with "Clear all data" in settings.
- Uninstalling the extension removes the extension's local database.
Sites the extension runs on
Deja's content scripts run only on these sites — the list is auditable in the extension manifest:
| Platform | Hosts |
|---|---|
| ChatGPT | chatgpt.com, chat.openai.com |
| Claude | claude.ai |
| Gemini | gemini.google.com |
| DeepSeek | chat.deepseek.com |
| Grok | grok.com |
Permissions, explained
storage— save your library and settings locally in the browser.alarms— clear the "capture paused" toolbar badge when a timed pause ends. Local only.- Host access (the five sites above) — read the prompt box you type into, so prompts can be saved and similar past prompts resurfaced. Deja reads only the prompt composer, never other page content.
Data sharing and selling
Deja does not share, sell, or transfer your data to anyone — including us. Since no data ever leaves your device, there is nothing we could share even if we wanted to.
Changes to this policy
If Deja's data practices ever change (for example, an optional cloud-sync feature), this policy will be updated before that change ships, the "Last updated" date will change, and any new data flow will be strictly opt-in — never a silent default.
Contact
Questions or concerns: open an issue on GitHub, or use the feedback links inside the extension's settings — they open a prefilled issue you review and submit yourself; nothing is reported automatically.