Nibble Privacy Policy
Nibble is a Chrome extension that replaces your new tab page and shows you one starred Gmail newsletter per day. This policy explains what data Nibble accesses, what it does with it, and what it does not do.
The short version: Nibble has no server. Everything it reads stays on your device. Nothing is sent to me or to any third party.
What Nibble accesses
Gmail (only if you grant access)
Nibble asks for one Google permission: gmail.metadata. This is a read-only permission. Through it, Nibble reads, for emails you have starred:
- the sender's name and address
- the subject line
- the date
- whether the email has a
List-Unsubscribeheader (used to tell newsletters from other mail) - the message ID
- the short text snippet Gmail provides for the message
Nibble does not read the full body of your emails or attachments, and it cannot send, modify, label or delete anything in your mailbox.
Browser data
To build the new tab page, Nibble reads from Chrome:
- your most-visited sites (title and URL), to show shortcuts
- your recently closed tabs (title and URL), to show the "continue tabs" panel
This data is read when the page loads, is only displayed to you, and is not stored by Nibble or transmitted anywhere. Site icons are loaded from Chrome's own local favicon cache.
Things you enter
If you add a custom shortcut, its name and URL are saved on your device.
What is stored, and where
All of the following is stored locally in your browser (chrome.storage.local and localStorage) and nowhere else:
- the newsletter details listed above, for starred emails Nibble has fetched
- today's selected newsletter, a record of recent daily picks, and the list of newsletters you have opened
- your reading-garden progress (a level and the date you last read)
- your custom shortcuts and chosen theme
Your Google access token is managed by Chrome. Nibble does not store it.
Who data is shared with
No one. Nibble does not sell, rent, share or transfer your data. It has no analytics, no telemetry, no advertising, and no user accounts. Nibble does not load fonts, icons, scripts or other resources from third parties.
The only network requests Nibble makes are to Google: the Gmail API (https://www.googleapis.com/gmail/v1/) to fetch your starred message details, and Google's sign-in and consent flow.
Google API Services User Data Policy
Nibble's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In line with that policy:
- Gmail data is used only to show you a newsletter and to remember which ones you have already seen.
- No humans read your data, except where required for security, legal compliance, or with your explicit consent.
- Your data is not used for advertising, and not used to develop, improve or train machine-learning models.
Self-hosted installs
If you install Nibble from nechalmaggon.com/nibble rather than the Chrome Web Store, you supply your own Google OAuth client ID. The same rules apply: data stays in your browser and is not sent to me.
Retention and deletion
Nibble keeps data on your device until you remove it. Uninstalling the extension deletes everything it stored. You can also revoke Nibble's Gmail access at any time at myaccount.google.com/permissions.
Children
Nibble is not directed at children under 13 and does not knowingly collect information from them.
Changes to this policy
If this policy changes, I will update the effective date above and post the new version at this address. Material changes will also be noted in the extension's store listing.
Contact
Questions about this policy: nechalmaggon@gmail.com