Privacy policy

Policy version: September 28, 2026. Applies to GitHub Rich Diff version 0.1.0.

Data used by the extension

The extension reads the current github.com pull request address to identify its owner, repository and PR number. When you open or refresh the preview, it requests PR metadata and file information directly from api.github.com. It processes file paths, file status, additions, deletions, commit identifiers and totals to build the preview. GitHub's API responses can also include PR descriptions, account metadata and patch text. Unused response fields are discarded after processing; descriptions and patches are not stored in the normalized cache or displayed in the preview.

If you connect a personal access token, the extension sends it only to GitHub for account validation and API authorization. It also reads your GitHub account ID and login. The extension has no developer-operated backend, analytics, advertising, telemetry or crash reporting. It does not sell data or transmit it to the developer. GitHub receives API requests under its own privacy terms.

Local storage and retention

The token and account identity are encrypted in the extension's IndexedDB database. The encryption key is non-extractable and stored in the same Chrome profile. This does not protect against all software or people with access to that profile. The connection remains until you disconnect, remove the extension or clear its data; expiration or revocation can make it unusable sooner. It is not synced between profiles.

Normalized PR data is held in memory and Chrome session storage, bounded to 20 PRs and 4 MiB with least-recently-used eviction. Presentation state (expanded rows, grouping and scroll position) is separately bounded to 20 tabs and 1 MiB. Session storage does not persist across browser restarts. Oversized previews can remain in memory while in use. Enable/disable and grouping preferences persist locally.

Your controls

Data is fetched on preview open or refresh, with revalidation on later opens. There is no background polling. Disconnect clears the credential, cached PR data and open previews. Changing the connected account clears prior PR data. If erasure fails, the extension reports an error so you can retry. Turning the preview off clears cached PR data but keeps the connection. Uninstalling removes extension storage. Disconnecting or uninstalling does not revoke the token at GitHub; revoke it in GitHub settings when no longer needed.

Limited Use

GitHub Rich Diff's use and transfer of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. The extension uses data only to provide its pull request composition preview and connection settings.

Contact and support

See the support page for the publisher's contact channel. Do not send tokens, private file paths or confidential screenshots with support requests.