Privacy policy for Chrome extensions

Extensions can see a lot: the pages people visit, what they type and what they read. The Chrome Web Store has strict rules for extensions that handle user data. Here is what your privacy policy needs to say.

Last reviewed September 2026. General information, not legal advice.

Does your Chrome extension need a privacy policy?

If your extension handles any personal or sensitive user data, the Chrome Web Store Developer Program Policies require you to post an accurate privacy policy and to handle the data securely. In practice, most extensions that read web pages, sync settings to a server, use analytics or ask users to sign in fall into this category. Firefox Add-ons and the Microsoft Edge Add-ons store have similar requirements, so one policy can often serve all three.

Where to add the privacy policy link

In the Chrome Web Store developer dashboard, open your item and go to the Privacy tab (privacy practices). There you describe the extension's single purpose, justify each permission, certify how you use data, and enter your privacy policy URL. Your answers there are shown on your store listing, so they must match the policy.

What counts as user data

Google treats a broad range of information as user data, including:

  • personally identifiable information, such as names, emails and addresses
  • authentication information, such as passwords and tokens
  • web browsing activity, such as URLs, page titles and history
  • website content, such as text and images from the pages a user views
  • personal communications, such as emails and chat messages
  • location, health and financial information
  • user activity, such as clicks, keystrokes and mouse position

If your extension sends any of this off the device, including to your own server or to analytics, describe it in the policy.

The Limited Use rules

Beyond disclosure, Chrome Web Store policy limits what you can do with user data. In short, you may only use it to provide or improve your extension's single purpose. Selling user data is not allowed, and neither is using it for personalized advertising or to determine creditworthiness. Humans may read it only in narrow cases, such as with the user's consent or for security. Your privacy policy is a good place to state that you follow these rules.

Explain your permissions

Broad permissions such as access to all websites, tabs, history or cookies make reviewers and users cautious. Ask only for what you need, and use the policy to explain in plain language why each sensitive permission is required and what happens to the data it gives you access to.

Checklist before you submit

  1. Every kind of user data the extension collects or transmits is listed.
  2. The policy explains why each sensitive permission is needed.
  3. It states that data is used only for the extension's purpose and is not sold.
  4. It explains retention, security and how users can delete their data.
  5. It matches your answers in the Privacy tab of the developer dashboard.
  6. The URL is public and entered in the dashboard.

Frequently asked questions

My extension works entirely on the device. Does it need a policy?

If no user data leaves the device and you don't collect any analytics, the store may not require one. Publishing a short policy that says so still builds trust with users and reviewers.

Can I use analytics in my extension?

Yes, but disclose it, collect only what you need to improve the extension, and never include browsing activity or page content unless that is essential to its purpose.

Can one policy cover Chrome, Firefox and Edge?

Yes, if the extension behaves the same in each browser. Host it on one URL and use that link in every store.

Publish your extension privacy policy

Write it, host it on a permanent link and paste the URL into the developer dashboard. Free.