Shelf 개인정보처리방침

최종 갱신: 2026-09-13

Shelf(이하 "확장")는 크롬 새 탭을 탭·북마크 컬렉션 대시보드로 바꾸는 크롬 확장 프로그램입니다. 이 문서는 확장이 어떤 정보를 어떻게 다루는지 설명합니다.

1. 수집·저장하는 정보

정보용도저장 위치
저장한 탭·북마크(제목, URL, 메모), 컬렉션 이름·순서·숨김 여부확장의 유일한 기능(컬렉션 관리)사용자의 브라우저(chrome.storage). 로그인한 경우 동기화 서버에도 저장
계정 이메일, 비밀번호 해시(scrypt)선택 사항. 여러 기기 간 동기화·백업 계정동기화 서버 데이터베이스. 비밀번호 원문은 저장하지 않음
세션 토큰(무작위 값)로그인 유지브라우저 및 서버(해시)
기기 식별자(무작위 UUID)여러 기기의 변경 충돌 해결브라우저 및 서버

확장은 방문 기록, 페이지 내용, 입력 내용, 쿠키를 읽거나 저장하지 않습니다. 사용자가 명시적으로 저장한 탭의 제목과 URL만 다룹니다. 현재 창의 열린 탭 목록은 화면에 표시하기 위해 읽을 뿐 서버로 전송하지 않습니다.

2. 로그인하지 않으면

모든 데이터는 사용자의 브라우저 안에만 있으며 어떤 서버로도 전송되지 않습니다. 계정 없이도 모든 기능을 사용할 수 있습니다.

3. 로그인하면

사용자가 직접 회원가입/로그인한 경우에만, 사용자의 컬렉션 데이터가 운영자의 동기화 서버(bookmark.godd.app)에 HTTPS로 전송·저장됩니다. 목적은 백업과 사용자 자신의 다른 기기와의 동기화뿐입니다. 로그아웃하면 해당 기기의 로컬 데이터가 삭제되고 서버 세션이 폐기됩니다.

4. 제3자 제공·판매

수집한 정보를 제3자에게 판매하거나 제공하지 않습니다. 광고·분석·추적 도구를 사용하지 않습니다. 확장 기능과 무관한 목적으로 데이터를 사용하지 않으며, 신용도 판단이나 대출 목적으로 사용하지 않습니다.

예외: 설정에서 사용자가 직접 "Google 파비콘 서비스에서 가져오기"를 켠 경우, 저장된 URL의 도메인이 Google 파비콘 서비스로 전송됩니다(기본값: 꺼짐).

5. 보안

서버 통신은 HTTPS로 암호화됩니다. 비밀번호는 scrypt로 해시하여 저장하고, 세션 토큰은 SHA-256 해시로만 저장합니다. 로그인 시도는 횟수 제한을 둡니다.

6. 보관 기간 및 삭제

로그인한 계정의 데이터는 사용자가 삭제하거나 계정 삭제를 요청할 때까지 보관됩니다. 계정과 모든 데이터의 삭제를 원하시면 아래 연락처로 요청해 주세요. 요청 후 7일 이내에 삭제합니다.

7. 권한 사용 설명

8. 문의

개인정보 관련 문의나 삭제 요청: 확장 스토어 페이지에 표시된 게시자 이메일


Shelf Privacy Policy

Last updated: 2026-09-13

Shelf (the "Extension") replaces Chrome's new tab with a dashboard of tab and bookmark collections. This document describes what information the Extension handles and how.

1. Information stored

DataPurposeWhere
Saved tabs/bookmarks (title, URL, note) and collections (name, order, hidden flag)The Extension's single purpose: managing collectionsYour browser (chrome.storage). Also the sync server if you log in
Account email and password hash (scrypt)Optional account for backup and multi-device syncSync server database. The plain password is never stored
Session token (random value)Keeping you logged inBrowser and server (hashed)
Device identifier (random UUID)Resolving conflicting edits between your devicesBrowser and server

The Extension does not read or store browsing history, page content, keystrokes or cookies. It only handles the title and URL of tabs you explicitly save. The list of open tabs in the current window is read to display it and is never sent to a server.

2. Without an account

All data stays inside your browser and is never transmitted anywhere. Every feature works without an account.

3. With an account

Only if you sign up or log in, your collection data is sent over HTTPS to and stored on the operator's sync server (bookmark.godd.app), solely for backup and syncing between your own devices. Logging out deletes the local data on that device and revokes the server session.

4. Sharing and sale

We do not sell or share collected information with third parties. No advertising, analytics or tracking tools are used. Data is not used for purposes unrelated to the Extension's functionality, nor for creditworthiness or lending purposes.

Exception: if you enable "fetch favicons from Google's favicon service" in settings (off by default), the domain of saved URLs is sent to Google's favicon service.

5. Security

Server communication is encrypted with HTTPS. Passwords are stored as scrypt hashes; session tokens only as SHA-256 hashes. Login attempts are rate-limited.

6. Retention and deletion

Account data is kept until you delete it or request account deletion. To delete your account and all data, contact us below; deletion is completed within 7 days.

7. Permissions

8. Contact

Privacy questions or deletion requests: the publisher email shown on the Chrome Web Store listing.