No Spoilers — privacy policy
Effective date: 11 October 2026
Short version: by default, nothing you read ever leaves your browser.
What the extension does on the pages you visit
No Spoilers reads the text of the pages you visit so it can hide parts that match the topics you turned on. It does this inside your browser. It does not send page content, URLs or browsing history anywhere.
What is stored, and where
- Your choices (which topics are on, snooze state, your own topics, words you marked "Not a spoiler", paused sites, display settings) are kept in your browser's extension storage. If you're signed in to your browser with sync turned on, the browser syncs them between your devices. We never receive them.
- iCloud sync (on by default where available). In Safari, and in Chrome on a Mac with the No Spoilers app installed, those same choices are also stored in your own iCloud account (iCloud key-value storage) so your devices stay in step. Apple holds that data under your Apple ID; we never receive it. Your smart-filtering key and the hidden-item counts are never synced. You can turn this off on each device in Options › Sync across devices.
- Counts of hidden items per topic and site are kept on this device only, so you can see them in the options page.
- Chrome on a Mac reaches iCloud through a small helper inside the No Spoilers Mac app, using Chrome's native-messaging interface. The helper reads and writes only the settings store above. Connecting it writes one file into Chrome's own settings folder, and only when you click Connect Chrome and choose the folder.
- Topic list updates are downloaded read-only from a static URL. The request contains no information about you. Updates are signed, and the extension checks the signature before using them.
Optional: smart filtering (off by default)
If you turn on Smart filtering and paste your own TypeSafe API key:
- The text of posts the word lists aren't sure about is sent to TypeSafe's API (
api.typesafe.ai) to decide whether it reveals a result. In "Deep scan" mode, the text of every post on supported sites is sent. At most 2,000 characters per post, never the whole page, never the URL. - Your key is stored on this device only (it is not synced), and only the extension's background worker uses it. Page scripts can never read it.
- Answers are cached on this device for 24 hours so the same post isn't sent twice.
- TypeSafe's own privacy terms apply to what you send them.
Turn smart filtering off and no page text leaves your browser again.
Contact
Questions: web@cameroncooke.com, or open an issue on the project repository.