Effective date: 19 March 2026
This privacy policy explains how the "Home" browser extension and its backend service at hp.itst.net handle your data.
Data controller: Sascha A. Carlin · privacy@itst.net
1. What the Extension Does
Home is a browser extension for Chrome, Firefox, and Safari that replaces your new-tab page with a background photo, clock, search bar, daily focus field, and a quote. It fetches a daily photo and quote from our backend server and lets you search the web using the search engine of your choice.
2. Data We Use
2.1 Timezone
Your IANA timezone identifier (e.g. Europe/Berlin) is sent to our server once per day so we can serve the correct daily photo and quote for your calendar date. It is used only for cache keying and is not stored beyond the cache lifetime.
2.2 Photo Category
If you choose a photo category (e.g. "forest", "ocean"), that keyword is sent to our server as a query parameter to fetch a matching image from Pexels. It is not logged or stored beyond the cache lifetime.
2.3 Screen Dimensions
Your screen width and device pixel ratio are included in the image URL requested from the Pexels CDN so you receive an appropriately sized image. These values are not sent to our server.
2.4 Server Logs
Our server records abbreviated log entries for each request. IP addresses are anonymized by zeroing the last two octets (e.g. 11.22.33.44 becomes 11.22.0.0). Each log entry contains:
- Anonymized IP address
- Timestamp
- Request path and query parameters (timezone, category)
- HTTP status code
- User-agent string
Log files are rotated and deleted daily.
3. Data We Do NOT Collect
- Search queries — Your searches are sent directly from your browser to the search engine you selected (e.g. DuckDuckGo, Google). They never pass through our server.
- Focus text — The daily focus you type is stored only on your device and is never transmitted to us.
- Browsing history or personal information — We do not collect names, email addresses, or any other personally identifiable information.
- Analytics or tracking — We do not use any analytics services, tracking pixels, or fingerprinting techniques.
- Cookies — The extension does not set any cookies.
- E-Mail addresses or names — You do not need to provide us with any personal data.
4. Data Stored on Your Device
The extension stores small amounts of data locally in your browser:
| Storage | Contents | Retention |
|---|---|---|
browser.storage.sync |
Your preferences (search engine, photo category, focus text) | Until you change them or uninstall the extension |
browser.storage.local |
Cached photo metadata and daily quote | Auto-deleted daily |
| Cache API | Cached background image | Auto-deleted daily |
browser.storage.sync may be synchronized across your devices by your browser vendor (Google, Mozilla, or Apple) according to their own privacy policies. We have no access to this synchronized data.
Uninstalling the extension removes all locally stored data.
5. Third-Party Services
5.1 Pexels (Canva Pty Ltd)
We use the Pexels API to fetch daily background photos. When a photo is requested, our server sends the photo category and orientation preference to Pexels. Pexels' CDN delivers the image directly to your browser.
Pexels privacy policy: pexels.com/privacy-policy
5.2 Your Search Engine
When you perform a search, your browser navigates directly to the search engine you selected (e.g. DuckDuckGo, Google, Bing, Brave). We are not involved in this request and have no access to your search queries. The search engine's own privacy policy applies.
5.3 Browser Vendor
Your browser vendor (Google, Mozilla, or Apple) may synchronize the preferences stored in browser.storage.sync to their servers. This is governed by your browser vendor's privacy policy, not ours.
6. Legal Basis for Processing (GDPR Art. 6)
We process the limited data described above on the basis of legitimate interest (Art. 6(1)(f) GDPR):
- Timezone and category are necessary to deliver the core functionality of the extension (serving a daily photo and quote matching your calendar date and preference).
- Anonymized server logs are necessary for maintaining the security and availability of the service.
7. Data Retention
| Data | Retention |
|---|---|
| Server-side photo/quote cache | 2 days |
| Server logs (anonymized IPs) | 1 day (rotated daily) |
| Client-side cache (photos, quotes) | Auto-deleted daily |
| Client-side preferences | Until changed by you or extension is uninstalled |
8. Your Rights
Under the GDPR, you have the right to:
- Access the data we process about you
- Rectification of inaccurate data
- Erasure of your data
- Restriction of processing
- Data portability
- Object to processing based on legitimate interest
Given the minimal and anonymized nature of the data we process, there is generally no personal data to access or delete. If you have questions or wish to exercise your rights, contact us at privacy@itst.net.
You also have the right to lodge a complaint with a data protection supervisory authority.
9. Data Security
- All communication between the extension and our server uses HTTPS encryption.
- API keys for third-party services are stored only on our server, never in the extension code delivered to your browser.
- Server-side input validation prevents injection and abuse.
- No user accounts or authentication credentials exist.
10. International Data Transfers
Our backend server is located in Germany (EU). We do not transfer your data to countries outside the EU/EEA.
Background images are delivered by Pexels' CDN, which may serve content from servers in various countries. This is governed by Pexels' own privacy policy.
If you use browser.storage.sync, your browser vendor may store synced preferences on servers outside the EU, subject to their privacy policy.
11. Children's Privacy
The extension does not knowingly collect any personal data, including from children. Since no accounts or personal information are required to use the extension, no age verification is necessary.
12. Changes to This Policy
We may update this policy from time to time. Changes will be reflected by an updated effective date at the top of this document.
For questions about this privacy policy, contact privacy@itst.net.