Privacy Policy
Effective and last updated: September 19, 2026
Summary
- SnippetShift has no backend, analytics, advertising, or telemetry.
- Offline rules and cached results do not send code over the network.
- An AI translation sends the selected code directly to the provider you choose, using your API key.
- The extension asks for explicit consent before its first AI request.
1. Data handled by the extension
SnippetShift locally handles the code you select or paste, provider API keys, settings, custom presets, translation cache and history, usage counters, and license status. This data is stored in chrome.storage.local, which is scoped to the extension on your device. It is not synced by SnippetShift.
SnippetShift does not collect this data on a SnippetShift server because the product has no backend. It does not use analytics, telemetry, ads, fingerprinting, cookies, or crash-reporting services.
Starting with version 0.3.2, saved API keys are encrypted using AES-256-GCM. A non-exportable cryptographic key is stored in the extension's IndexedDB; existing plaintext credentials are migrated when settings are loaded. Earlier versions store API keys without encryption. Local storage is restricted to trusted extension contexts. Encryption does not protect against compromised extension code, a compromised device, or software able to operate your browser profile. Translation history, cache, settings, and license proofs remain locally stored without this encryption. Code shown in an on-page panel is part of that page's UI; use the extension popup for code that should not be visible to a visited page.
2. AI provider disclosure
When you request an AI translation that is not served from cache or an offline rule, SnippetShift sends the selected or pasted code, the requested target, and translation instructions directly from your browser to the provider you selected:
- OpenAI -
https://api.openai.com - OpenRouter -
https://openrouter.ai - Groq -
https://api.groq.com - Google Gemini -
https://generativelanguage.googleapis.com
The request uses the API key you supplied. SnippetShift does not proxy or log the request. Each provider processes data under its own terms and privacy policy. Do not submit secrets, credentials, personal information, or confidential source code unless the provider's policy and your organization permit it.
Compare sends the same code to up to three configured providers, starting with the active provider. OpenRouter may route requests to its upstream model providers. Test connection sends a ping and your API key, without your code. These requests can incur provider charges. No full page, page URL, or browsing history is sent by SnippetShift.
3. Consent and control
Before the first AI request, SnippetShift displays a prominent disclosure and requires your affirmative consent. You can revoke that consent in Settings. Revoking consent blocks new AI requests but does not disable offline rules or cached results.
4. Retention and deletion
- Translation cache: up to 200 entries within a 2.5 MB budget, evicting oldest entries.
- Translation history: up to 50 entries within a 2.5 MB budget, evicting oldest entries. Results saved by older versions may already be truncated.
- Settings, API keys, presets, and usage totals: retained locally until changed, cleared, or the extension is uninstalled.
Clear history in the popup's History tab. Settings provides controls to clear cache and usage, remove API keys by saving an empty key, deactivate a paid license, and revoke AI consent. Uninstalling the extension removes its local Chrome storage. Provider-side retention is controlled by the provider, not SnippetShift.
5. Permissions
storage- stores settings, API keys, consent, presets, cache, history, usage, and license state locally.contextMenus- adds user-invoked right-click translation actions.- Access on web pages - detects code blocks and displays the SnippetShift controls on pages you visit. Page content is not transmitted unless you request an AI translation.
- Provider host access - permits direct HTTPS requests only to the four AI API hosts listed above.
6. Limited use
SnippetShift's use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the code translation features the user requests. It is not sold, used for advertising, used to determine creditworthiness, or transferred for unrelated purposes.
7. Security
Provider traffic uses HTTPS. API keys are never inserted into page content and are sent only in authentication fields to the selected provider. No browser extension can guarantee that a provider, browser profile, device, or visited page is risk-free, so users should avoid submitting sensitive material.
8. Changes and contact
Material changes will be reflected by updating this policy and its effective date. A new disclosure and consent will be required before materially different data handling begins.
Questions or deletion assistance: [email protected].