Privacy Policy
The short version. Boltfill has two modes and you choose which. Local mode is the default, needs no account, and sends nothing anywhere — your snippets stay on your own device. Sync mode starts only if you deliberately sign in, and stores your snippets on Boltfill's server so your other computers can read them. In both modes Boltfill reads and changes web pages only on sites you have allowed, and only to insert the text you asked it to insert. There are no analytics in either mode.
What Boltfill stores, and where
| Data | Where it is stored | Who can see it |
|---|---|---|
| Your shortcuts and their content | chrome.storage.local on this device |
You, and anything else with access to your Chrome profile |
| Your settings (on/off, expansion mode, excluded sites) | chrome.storage.local on this device |
Same |
That is the complete list. Boltfill stores nothing else.
chrome.storage.local is Chrome's per-device extension storage. It is
not synced to your Google account, so your snippets do not travel
between machines unless you export them yourself or turn on Boltfill's own sync by
signing in.
What Boltfill sends over the network
Signed out, nothing at all. No request of any kind leaves your computer: no tracking pixel, no analytics call, no remote font or stylesheet. Every file Boltfill uses is inside the extension package, and expansion reads only your own device's storage. This is the default, and it is the whole product for anyone who never signs in.
Signed in, three things and nothing else. Accounts and sync arrive with version 0.4.0, and stay off until you choose them:
- Your snippets — their shortcuts, their text, and any folders and tags — to Boltfill's own server, so your other computers can read them.
- Your email address and a random device id, so the account can be identified and its devices counted. The device label is coarse — "Chrome on Windows" — and is not derived from your machine.
- If you buy Pro, a request to start a checkout. The payment itself happens on Lemon Squeezy's own pages and Boltfill never sees a card.
Those requests go to Boltfill's own Supabase project and to Lemon Squeezy, and nowhere else. Exactly one file in the extension is permitted to make a network request at all, and the release build fails if any other file tries.
Expansion never needs the internet in either mode. Shortcuts expand from your own device, so Boltfill works on a plane whether you have an account or not.
What Boltfill can access on web pages
To insert text into a field, Boltfill needs to run on the page containing that field. This is a real capability and we will not pretend otherwise:
- Boltfill does not request access to any website when you install it. A fresh install can read and change nothing.
- Access is requested only when you click Enable, and Chrome shows you exactly what you are granting.
- Once granted, Boltfill's code runs on pages you visit. It watches for typing in text fields so it can recognise a shortcut, and reads up to 52 characters immediately before your cursor to check for one.
- That text is examined in memory on your device and is never stored, transmitted, or logged.
- Boltfill does not read page content generally, does not track which sites you visit, and does not record what you type.
-
You can remove access at any time from Boltfill's settings page or from
chrome://extensions, and you can exclude individual sites so Boltfill never runs on them at all.
Where Boltfill refuses to work
Boltfill will not expand text inside:
- password fields
- credit- and debit-card number, expiry and CVV fields
- one-time-code and verification-code fields
- fields whose name or label suggests a password, PIN, token, secret or bank account number
- fields marked
disabledorreadonly - any site you have added to your exclusion list
- any element inside a region marked
data-boltfill="off"
Boltfill is not a password manager
Please do not store passwords, card numbers, CVV codes, one-time codes, private keys, recovery phrases or banking credentials in Boltfill. Its storage is not encrypted beyond the protections Chrome applies to your profile, and it is not designed to be a secrets vault. Use a real password manager for those.
Accounts, payments and third parties
Signing in is optional. If you never do, Boltfill uses no third-party service of any kind and this section does not apply to you.
If you do sign in, two third parties are involved and no others:
- Google, only during sign-in, to confirm who you are. Boltfill asks for the smallest possible scopes — your email address and basic profile — and cannot read your Gmail, Drive, contacts or calendar.
- Supabase, which hosts Boltfill's database and handles authentication. Your snippets and email address are stored there.
If you buy Boltfill Pro, one more is involved: Lemon Squeezy, who are the merchant of record for every Boltfill sale. They take the payment, handle the tax, and tell Boltfill's server that your subscription started, renewed or ended. Boltfill never sees your card — it has no code that could accept a card number. We store only a customer reference, a subscription reference, its status and the relevant dates. Lemon Squeezy's own policy is at lemonsqueezy.com/privacy.
Boltfill uses no analytics service, no advertising network and no crash reporter. It does not sell your data, does not share it with anyone, and does not use it to train anything.
Is my snippet content encrypted?
Your snippets travel over HTTPS and are stored encrypted at rest. That is not end-to-end encryption, and we will not call it that. Boltfill's operators hold the keys to the database, which means snippet content in a synced account is technically readable by us. We do not read it and have no interest in it, but you should judge the guarantee by what is technically true rather than by our intentions.
If that matters to you, stay signed out — local mode sends nothing at all — and please do not put anything sensitive in a synced snippet.
Cancelling Pro
Cancelling never deletes anything. Your snippets, folders and tags stay exactly where they are. If you end up above the free limits, Boltfill stops accepting new cloud data and new devices rather than removing what is already there, and your local snippets are untouched regardless. A failed payment never deletes anything either.
Analytics
Boltfill collects no analytics, no telemetry, no crash reports and no usage statistics.
This website collects nothing either. It is static HTML and CSS, with no cookies, no trackers, no analytics, no JavaScript and no third-party resources of any kind.
Your controls
| You want to | Do this |
|---|---|
| See everything Boltfill has stored | Open Settings → Backup → Export Boltfills |
| Stop Boltfill without deleting anything | Open Settings → turn off "Boltfill is on" |
| Keep Boltfill off a particular site | Open Settings → "Never run on these sites" |
| Take away website access | Open Settings → Website access → Remove access |
| Delete everything | Open Settings → "Delete everything", type DELETE |
| Delete everything including the extension |
Uninstall Boltfill from chrome://extensions; Chrome deletes its
storage with it
|
Deletion is immediate and permanent. There is no copy anywhere else to delete, because no copy is ever made.
Children
Boltfill is not directed at children and collects no personal information from anyone.
Changes to this policy
Material changes will be noted in the project's changelog and reflected here with a new "Last updated" date before the version that makes the change is published.
Contact
For privacy questions, support, or feedback, contact: plugins.dns@gmail.com
For anything that is not private, the support page explains how to open an issue.