privacy
Privacy policy
Last updated: 22 July 2026 · Controller located in Germany, GDPR (DSGVO) applies.
The short version
- This website sets no cookies, runs no analytics, and loads nothing from third parties — no trackers, no CDN fonts.
- If you join the waitlist, we store your email address only at Mailgun (EU region) until launch. One email when the extension ships, one when Pro ships. No newsletter.
- The browser extension keeps all of your data on your machine. Cookies, profiles, and settings never leave your browser.
- Usage telemetry is off by default and strictly opt-in: five documented, anonymous events, hosted at PostHog EU — never URLs, domains, or cookie data (full list).
- We never sell data and share it with no one except the processors named below.
1. Controller
The controller responsible for data processing on this website and in the SessionCourier browser extension (Art. 4(7) GDPR):
FiRonDU Software UG (haftungsbeschränkt), Lillinger Weg 8, 91367 Weißenohe, Germany — email: support@sessioncourier.dev
2. This website
2.1 Hosting (Cloudflare Pages)
This site is a static website served by Cloudflare Pages. When you open a page, Cloudflare processes the connection data technically required to deliver it — IP address, date and time, requested URL, and browser user agent — in its server logs. We do not receive or evaluate these logs for analytics; they serve the secure and reliable operation of the site.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, reliable delivery of the website). Processor: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, bound by an EU data processing agreement; transfers to the USA are covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.
2.2 No cookies, no analytics, no third-party requests
This website sets no cookies and stores nothing in your browser. It loads no fonts, scripts, images, or other resources from third-party servers, and it contains no analytics or tracking code. The only outbound request the site makes on your behalf is the waitlist form below, and only when you submit it.
2.3 Waitlist
If you join the waitlist, we process your email address for one purpose only: notifying you — once when the extension launches on the Chrome Web Store, once when SessionCourier Pro ships. The form's hidden "company" field is a spam trap and is discarded unread. The address is stored in a mailing list at our email processor Mailgun (Sinch), EU region, under an EU data processing agreement.
Legal basis: Art. 6(1)(a) GDPR (your consent). We keep the address until the launch notifications have been sent or you withdraw consent, whichever comes first. You can withdraw at any time with effect for the future — just reply to any waitlist email or write to the contact address in section 1.
3. The browser extension
3.1 Local-only by design
SessionCourier reads, edits, imports, and exports cookies entirely inside your
browser. Cookie data, protected-cookie copies, settings, and preferences are stored
only in your browser profile (browser.storage.local; in incognito windows,
in memory only). Exports (JSON, Netscape, curl, Playwright storageState) are written as
downloads to your own disk. Nothing of this is transmitted to us or to anyone else.
The extension requests only the permissions cookies, storage, and
activeTab; broad website access (optional_host_permissions) is
requested at runtime only when a feature you invoked needs it. The extension is open source
with a reproducible build, so these statements are verifiable in the
public repository.
3.2 Optional, anonymous telemetry
On first start the extension asks once whether it may count usage. The default is
off; declining is exactly as easy as accepting. If you opt in, the extension
sends exactly five documented events — popup_opened, export_used
(with the export format), protect_toggled, pro_teaser_clicked, and
waitlist_signup — together with a random anonymous identifier generated and
stored on your device. The events structurally cannot contain URLs, domains, cookie names, or
cookie values; the complete event list is published at /telemetry.
Destination: PostHog EU cloud (PostHog, Inc., EU region), under an EU data processing agreement. Legal basis: Art. 6(1)(a) GDPR (your consent). You can withdraw consent at any time in the extension's Settings — this stops all future events immediately. To have previously sent events deleted, email the contact address in section 1; since events are stored under a random identifier only, we will help you read that identifier from the extension's local storage so we can find and delete your events.
4. Recipients of data
| Processor | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | Website hosting & delivery (connection logs) | Global edge network; DPF/SCCs for US transfers |
| Mailgun (Sinch) | Waitlist email storage & delivery | EU |
| PostHog, Inc. | Opt-in anonymous usage telemetry | EU |
Beyond these processors, no data is shared with third parties. We do not sell personal data, and we do not use it for advertising, credit, or profiling purposes.
5. Your rights
You have the right to:
- access the personal data we hold about you (Art. 15 GDPR);
- rectification of inaccurate data (Art. 16 GDPR);
- erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- object to processing based on legitimate interests (Art. 21 GDPR);
- withdraw any consent at any time with effect for the future (Art. 7(3) GDPR);
- lodge a complaint with a supervisory authority (Art. 77 GDPR) — in Germany, the data protection authority (Landesdatenschutzbeauftragte) of your federal state, or the one competent for the controller's seat.
To exercise any of these rights, email the contact address in section 1.
6. Changes to this policy
We will update this policy when the site or the extension change in ways that affect data processing — for example when accounts and end-to-end-encrypted sync ship (the server will then store ciphertext it cannot read). The current version is always on this page.