Skip to main content
← All policies

Browser Extension Privacy Policy

The extension works with no account, sets no cookies, and never sends us the book you are looking at or what you searched for — unless you opt in to contributing search-results data, which is off by default. Live suggestions under the search box go from your browser straight to Amazon, without your Amazon cookies; pressing Expand sends the phrase to our server first, which asks Amazon on your behalf. Anonymous usage counts are on by default and one checkbox turns them off.

Version
2.4
Effective
Last updated

This policy covers the SmartKDP browser extension only. Our main privacy policy covers the website and the web app; where the two overlap, this one is the more specific and applies to the extension.

We have written it against what the code actually does, request by request. The short version is unusually short, so here it is up front:

  • The extension works fully without an account. Connecting one is optional and adds exactly the three things described below.
  • It sets no cookies and does no fingerprinting.
  • No request to us ever carries the book you are looking at — not its title, not its ASIN, not the page address, not what you searched for. The one exception is a contribution you switch on yourself: item 6 below, off by default.
  • The keyword features do send a phrase you typed to Amazon's own public suggestion service, without your Amazon cookies. The live suggestions under the search box go directly from your browser; an Expand run sends the phrase to our server first, which asks Amazon on your behalf and falls back to your browser if it cannot. See items 7 and "To Amazon, from your browser" below.
  • It sells nothing and shares nothing with advertisers or data brokers.

What changed in version 2.3 (2 September 2026). A correction, not a new category of data. Since 2 August 2026 the Expand action has tried our own server first — the phrase you typed is sent to us, our server asks Amazon's suggestion service on your behalf, and your browser only asks Amazon directly when our server cannot. Earlier versions of this policy said the phrase "never reaches us", which was true of the live suggestions under the search box but not of Expand. Item 7 below states it plainly. Nothing else about the request changed: it carries the phrase, the marketplace, and the same random install identifier as the usage counts, and never the page you are on.

What changed in version 2.2 (26 August 2026). One new, opt-in item: "Contribute anonymous search-results data", a checkbox in the extension's settings that is off until you tick it. With it on, when you open an Amazon search results page yourself, the extension sends us what is printed on it — the search phrase and the products listed, with their positions — so that our Reverse ASIN Lookup tool can answer from data instead of guesses. It is described in full as item 6 below. Nothing changes for anyone who does not turn it on, and the bullet above gains its first (clearly labelled) exception.

What changed in version 2.1 (23 August 2026). The extension gained a panel under Amazon's own search box: when you stop typing, it asks Amazon's public suggestion service about the phrase you typed and shows what comes back. That is a request that had not previously been made without a click, so it is called out here rather than folded into the existing wording, and the summary bullet above has been narrowed from "no request ever carries what you searched for" to "no request to us" — which is what was always true and what the new panel makes worth stating precisely. Nothing new is sent to us, and no new category of data is collected. This version also fills a gap that predates it: the keyword expander's requests to Amazon's suggestion service were not described in "To Amazon, from your browser", and now are.

What changed in version 2.0 (2 August 2026). Version 1.0 said the extension's diagnostic events were never transmitted, and committed to updating this policy before that changed. This is that update. Two things are new: anonymous counts of which features you use, covered by the same opt-out that already existed, and — only if you choose to connect an account — settings sync and saved research. The diagnostic events themselves are unchanged and still never leave your machine on their own.

Where it runs

The extension activates on three sites, and only these three:

  • www.amazon.com
  • www.amazon.co.uk
  • www.amazon.de

On a search results page, a book's page, or a bestseller chart, it reads the page you have already opened — the titles, prices, ranks, formats and review counts that are printed on it — and adds its own figures alongside. It does this in your browser. The page content is not transmitted to us.

It runs on no other website. It cannot: the list above is fixed in the extension's manifest at install time, which is what your browser showed you when you added it.

What leaves your computer

To us

1. Its configuration. On startup and roughly every six hours, the extension asks our server for its settings — which features are currently switched off, and updated rules for reading Amazon's pages. This request carries no body and no identifier of any kind. It exists so that when Amazon changes a page layout and a figure starts coming out wrong, we can switch that feature off within the hour instead of waiting days for a store review.

2. A sales rank, to estimate against. When you open a book's page, the extension sends us three values: the book's Best Sellers Rank (a number), which marketplace it came from (us, uk, or de), and whether it is a print book or a Kindle book. We return an estimated sales range. We are not sent the book — no title, no author, no ASIN, no URL — and we could not identify it from what we receive. As with any web request, our servers see the originating IP address; it is used for rate limiting and is not stored against you or joined to anything.

3. Anonymous counts of which features you use. When an overlay opens, a deep analysis finishes, an export is saved, something is saved to an account, or you follow a link to our site, the extension records the name of that action from a fixed list, plus which Amazon marketplace and which of its own surfaces. That is the whole payload — there is no field in it that could carry a book, an address, or a search term, and you can read the list in the extension's own settings. These counts carry a random identifier created when you installed the extension: it is not derived from you, your browser, or your account, it is never combined with anything else, and it is deleted when you remove the extension. It exists only so that one person using a feature ten times is not counted as ten people. We forward these counts to Google Analytics from our server; no Google script runs in your browser. Switching off "Don't record or send usage data" in Settings → Privacy stops all of it, and also deletes what is already stored locally.

4. If — and only if — you connect an account. Connecting is optional and the extension is fully functional without it. When you do, three further things happen: it asks which plan your account is on; it syncs the extension's own settings (which overlays are on, which marketplaces, light or dark) so a second browser picks up where you left off; and anything you explicitly press Save on is stored in your account and shown at smartkdp.com. Your privacy choice above is deliberately not synced — that stays a decision about the device you made it on. Disconnecting from the extension's settings removes the connection from that browser; revoking it from your account's security page removes it everywhere.

5. If — and only if — you send a problem report. The "Report a problem" form sends what you type, plus the technical context described in the next section. The form shows you exactly what it will send before you send it, and it works whether or not you have an account.

6. If — and only if — you opt in to contributing search-results data. A checkbox in the extension's settings — off by default — reads "Contribute anonymous search-results data". With it on, when you open an Amazon search results page yourself, the extension sends us what that page prints: the search phrase, and for each listed product its ASIN, its position on the page, whether it is an ad, and its visible review count and price. That is public shelf data — which products Amazon showed for a search — and it is what powers our Reverse ASIN Lookup tool's index. Three boundaries hold whether or not you trust us on the rest: it reads only pages you open yourself (the extension never browses on its own), it reads only Amazon search pages (never a product page, never your orders, never anything about your account), and the request carries the same random install identifier as item 3 — used only to cap how much one install can contribute per day — and no cookies. Untick the box and it stops immediately; the checkbox is beside the description in the extension's settings.

7. A phrase you asked to expand. When you press Expand on a search results page, or the panel under the search box auto-expands a finished phrase, the extension sends us that phrase and which marketplace it is for, together with the same random install identifier as the usage counts (so the free daily allowance can be counted). Our server asks Amazon's public suggestion service on your behalf and streams the results back; if it cannot — it is unavailable, or the request is refused — your browser asks Amazon directly instead, as described under "To Amazon, from your browser". The request never carries the page you are on, and an expansion is only ever of a phrase you typed yourself.

That is the complete list. If you would like to confirm it rather than take our word for it, the extension's entire permitted network surface is a single hard-coded list in its source, and it will not make a request that is not on it.

To Amazon, from your browser

Two features talk to Amazon directly. Both go from your browser straight to Amazon, and both are made logged out — the extension deliberately sends no cookies, so it never acts as you or under your Amazon session. For the keyword features that is not only a privacy choice: carrying your Amazon session would personalize the suggestions by your own shopping history, which would make them wrong as research.

Reading product pages. On an Amazon search results page, the extension reads each result's own product page to show figures the results page does not carry — sales rank, category ranks, publisher, page count, ISBN, formats and the like. Since version 2.4 this happens automatically as the results appear, from your browser, a few pages at a time with a pause between requests; a page read today is not read again, and the extension stops on its own if Amazon asks for a check. It is a switch in the extension's settings ("Read product pages automatically"); with it off, product pages are read only when you press the button. On a bestseller chart the deeper read still runs only when you press it, and tells you how many pages it will open first. In every case the requests carry none of your cookies and nothing about them is sent to SmartKDP; the one server call a search page makes is to turn the sales ranks it found into estimated sales, which carries ranks and nothing else.

The keyword features send a search phrase to Amazon's public suggestion service, the same service that powers the dropdown under Amazon's own search box. They ask in two places:

  • On a search results page, when you press Expand: the phrase, plus a set of automatically derived variations of it, so the results can be grouped into a tree. This is the browser fallback for item 7 above — it runs when our server could not do the expansion for you.
  • Under Amazon's search box, when you stop typing: the phrase you have typed, and the same phrase followed by a space (which asks Amazon what people search for next). If the phrase looks like a finished search, the fuller expansion above may then run automatically — a switch in the panel turns that off, and the panel shows how many free expansions you have left before you spend one.

Only a phrase you typed yourself is ever sent, and nothing is sent on page load. The search box on an Amazon search page arrives pre-filled with your query; the extension does not read it until you type. Requests carry no cookies, are paced by a fixed rate limit, and are capped by a per-minute budget.

To nobody, unless you ask: the diagnostic events

The extension records a small log of technical events on your own machine — for example "a price failed to parse on a .de search page", or "a deep analysis run finished in 14 seconds after 9 fetches". These are counts, timings and fixed category labels. They never include the book you were looking at, what you searched for, or anything that identifies you.

Nothing transmits them automatically. They are a separate list from the usage counts above, they are capped at the most recent 200 events, they stay on your computer, and they are deleted when you uninstall.

They leave your machine in exactly one situation: you file a problem report. The report form summarizes them as counts (for example "amazon.de/serp/price ×41") and shows you that summary, along with everything else it will send, before you press send. That summary is the difference between a report we can act on the same day and one that needs a conversation first.

You can switch the recording off in Settings → Privacy — the same checkbox that stops the usage counts. Doing so also deletes whatever has already been recorded.

What is stored, and where

WhatWhere it livesLeaves your machine?
Your settings (which features are on, which marketplaces, theme, opt-out)Your browser's sync storageSee below
Cached configuration, the diagnostic log, cached analysis resultsYour browser's local storage for the extensionOnly in a problem report you send
The random install identifier used for the usage countsYour browser's local storage for the extensionWith the usage counts, unless you opt out
Your account connection (if you connect one) and its device tokenYour browser's local storage for the extensionNo — the token is used to authenticate, never shared

The settings row deserves a plain answer, and it now has two halves.

Browser sync storage is a feature of your browser, not of ours: if you are signed into Chrome with sync enabled, your browser copies that data between your own devices through your Google account. It is a handful of on/off switches, and it is governed by Google's privacy policy. If you are not signed into your browser, it stays on the one machine.

Separately, if you connect a SmartKDP account, those same switches are also mirrored to that account on our servers, so a different browser — or a different computer — picks up your setup. That mirror exists only while an account is connected, it holds nothing but the switches, and your privacy opt-out is excluded from it by design. Disconnecting stops the mirroring; the copy on our side is deleted with your account.

Uninstalling removes all of it.

Two pages we open

When you install the extension, it opens a welcome page on smartkdp.com once. When you uninstall it, your browser opens a short feedback page on smartkdp.com. Both are ordinary visits to our website — they are subject to our cookie policy and its consent banner exactly like any other page, and neither carries anything about your browsing. Each link includes the extension's version number so we can tell which release a problem relates to.

Chrome Web Store Limited Use

Our use of information received from Google APIs, and any data obtained through the extension, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically, we confirm that we do not:

  • sell this data to third parties;
  • use or transfer it for purposes unrelated to the extension's single purpose;
  • use or transfer it to determine creditworthiness or for lending purposes;
  • allow humans to read it, except with your explicit consent for a support request you have raised, where required by law, or where the data is aggregated and de-identified.

Permissions, and why each one exists

PermissionWhy
storageTo keep your settings and the local caches described above.
activeTabSo the toolbar popup can tell which book you are currently looking at, and only at the moment you open the popup.
The three Amazon hostsTo read the page and add figures to it. Without these the extension does nothing at all.
smartkdp.comSo the extension can reach our own two endpoints. Declaring our own site here is what lets the request happen at all; it grants no access to anyone else's.

There is no permission for reading your browsing history, your tabs, your bookmarks, or any other website — because there is no feature that would use one.

Children

The extension is a tool for people publishing books commercially and is not directed at children. See our main privacy policy for the full position.

Your rights

The extension holds nothing that identifies you, so there is normally no personal data of yours for us to find, export or erase in connection with it — uninstalling removes everything it stored, immediately and locally. If you have contacted us and want that correspondence dealt with, or you want to check whether we hold anything at all, the routes and statutory deadlines in our main privacy policy apply.

Changes to this policy

If what the extension collects changes, this page changes first, its version number goes up, and the date above moves. Material changes — anything that starts sending something new — will also be described in the extension's release notes rather than landing quietly.