# MoYe privacy policy

Applies to version 0.3.0. This policy is prepared for publisher review and hosting; this project has not submitted the extension to the store on the publisher's behalf. 

## Purpose and processing

MoYe is a read-only Markdown reader. It requires no account and operates no document server, telemetry, advertising tracking, document-upload service or data sale.

Local files are read through user-selected files/directories. Selecting one file does not grant sibling access. Local file-URL preview is intended on by default for new installations, but remains inactive until the user allows Chrome file-URL access and grants optional API access. It reads only the browser's current, inspected raw Markdown page as a snapshot, never arbitrary local paths. Local paths and document bodies are not sent to the network.

Remote reading targets public HTTP(S) URLs the user explicitly opens/authorizes, or qualifying raw Markdown pages on individually enabled auto-preview sites. Document and image fetches omit cookies, HTTP login credentials and referrers. Remote images require separate, per-origin consent; opening a local document does not automatically fetch them. A destination website can still receive the requested URL, IP address and ordinary network information, subject to its own policies. Query parameters are used for the current request but excluded from recent reading and offline cache persistence.

## Local storage and retention

| Category | Default and content | Retention/deletion |
| --- | --- | --- |
| Preferences | Locally stores language, theme, font size, feature switches and enabled preview origins; no document text | Change settings, clear extension data or uninstall |
| Temporary entry data | Single-use URLs/current file snapshots in trusted `storage.session` memory; full URLs are not put into reader query strings | Tickets valid for at most 5 minutes and deleted on consumption; original/bypass records valid for at most 30 minutes. Tab/browser close or extension reload clears relevant data; subsequent entry maintenance prunes expired data |
| Recent reading | **Off by default**; opt-in stores up to 20 names, authorized relative paths, public query/userinfo-free URLs, positions, times and actual file/directory handles; no bodies/images | Delete one, clear all or disable. Handles stay in local IndexedDB and may require user reauthorization |
| Offline cache | **Separately off by default**; opt-in permits persistence of successfully validated public remote Markdown text, query/userinfo-free URLs and cache timestamps; no local-file bodies, credentials or images | 20 documents/20 MiB total, 5 MiB each, 7-day expiry, least-recently-used eviction. Expired data is pruned on cache access. Delete one, clear or disable to erase; no background networking |

**Document text is not persisted by default. Explicitly enabled offline caching is the exception.** Storage is local, not cloud-synchronized. Recent reading and cache consent are independent; disabling one does not silently erase the other. Transaction generations prevent queued operations from restoring cleared data. Browser storage pressure, site-data clearing or uninstall may remove data; this is not a backup service.

Chrome's own browsing history, remembered permissions, printing/PDF saving and website navigation are outside MoYe's control. MoYe does not claim to clear those records. External document links are opened by the browser only after an intentional click.

## Permissions

`storage` is the only mandatory extension permission. The context menu uses optional `contextMenus`; site/file auto-preview uses optional `scripting` and corresponding origin access. HTTP(S) host declarations are optional, granted by host through user actions—not blanket website access on installation. Optional `file:///*` and Chrome's Allow access to file URLs switch are used only for local URL preview; file pickers do not require that switch. No `tabs`, `webRequest`, `downloads` or `activeTab` permission is requested.

## Safety and limitations

Raw Markdown HTML is disabled and rendered output is sanitized. Diagram/math libraries, scripts and fonts are packaged locally, with no CDN or remote executable code. Private-network literal targets, common local hostnames, credential URLs and redirects are blocked. The extension cannot reliably inspect the final DNS destination of a public hostname; authorize trusted sites only. Private repositories, SSO, login credentials and editing/saving are not supported.

## Updates and contact

The publisher should update this policy and the store disclosure when functionality or processing changes. Before publication, the publisher must supply a valid support/contact channel in the store and host this policy at a publicly accessible URL. This repository does not invent a contact address or create/host a policy website on the publisher's behalf.
