📋 Privacy Policy

How we collect, handle, store, share, and retain your data

Last Updated & Effective Date: July 23, 2026

1. Introduction

Phantom Typer — Human Typing Simulator ("the Extension") is a Chrome browser extension that provides user-controlled typing automation. The Extension allows users to prepare text in a popup interface, configure typing speed and behavior settings, and then simulate realistic human-like keyboard input into text fields on websites chosen by the user.

This privacy policy explains in detail what data we collect, how we handle and use that data, where it is stored, how long it is retained, and whether and how it is shared with third parties. We are committed to protecting your privacy and collecting only the minimum data necessary to provide the Extension's functionality.

📌 Chrome Web Store Compliance & Data Disclosure Matrix

The table below provides a quick reference to our data collection, handling, storage, retention, and sharing practices in full accordance with the Chrome Web Store User Data Policy.

Data Category Collected? Handling / Purpose Storage Location Retention Period Sharing / Disclosure
Personal Info (Email, User ID) Yes (Optional) Account authentication & subscription management Firebase (Google Cloud) Duration of account (deleted on request) Firebase (Google) only
Authentication Info (Passwords & Tokens) Yes (Optional) User account registration & login authentication via Firebase Firebase Auth (Cryptographically hashed; plain text NEVER stored) Duration of account (deleted on request) Firebase Auth (Google) only — NEVER shared or sold
User-Provided Text Local Only Typing automation into selected web fields Local device (chrome.storage.local) Until uninstalled or cleared by user NEVER shared or transmitted
Website Content & Access No Data Collected Focus field & dispatch keystrokes on demand None (No storage) Transient in-memory during typing NEVER shared or transmitted
Financial & Payment Info Processed by Paystack Pro subscription checkout Paystack (PCI-DSS compliant) Per Paystack policy (Not stored by us) Paystack (Payment processor)
User Activity & Web History NO Session count tracked for free tier limits Firebase & Local Storage Duration of account NEVER shared or sold

2. Data We Collect

We collect and process the following categories of data to provide the Extension's features:

Account and Authentication Information (including Passwords):

Important: Account registration is completely optional. You can use Phantom Typer offline on the free tier without ever entering an email or password.

Subscription and Payment Data:

Important: Phantom Typer does not collect, see, or store payment card numbers, CVVs, bank account details, or other financial credentials. All payment card processing is handled entirely by Paystack, our third-party payment processor.

Usage Data:

Local Extension Settings (stored on your device):

User-Provided Text (stored locally on your device):

Important clarification: When you enter or paste text into the Phantom Typer popup or side panel, that text is saved locally in Chrome extension storage (chrome.storage.local) on your device so it persists between sessions. This text is not transmitted to our servers. It remains on your device and is used only to perform the typing action you request. The Side Panel is an additional UI surface only — it does not collect any new data or introduce any new server traffic; it reads and writes the same locally stored text the popup uses.

Website Field Interaction Data:

Important: This interaction is limited to performing the typing action requested by the user. The Extension does not read, collect, scrape, or transmit the existing content of web pages or form fields to any server.

3. Data We Do Not Collect

To be fully transparent, we explicitly state that Phantom Typer does not collect, store, or transmit the following:

4. How We Handle and Use Your Data

Each type of data we collect is used for a specific, limited purpose directly related to providing the Extension's functionality:

Account passwords and authentication credentials → Used strictly to authenticate your identity, create your user account, and protect access to your Pro subscription features via Google Firebase Authentication. Passwords are transmitted directly to Firebase via encrypted HTTPS and are never stored in plain text or used for any other purpose.

Email address and account identifiers → Used to identify your user account, authenticate your identity via email or Google Sign-In, and maintain your login session.

Subscription status, plan type, and expiration date → Used to determine whether you have an active Pro subscription and to unlock or restrict premium features accordingly.

Payment confirmation/status → Used to verify successful payment and activate or renew your Pro subscription. We receive only confirmation of payment status from Paystack, not your card details.

Typing session count → Used to enforce free-tier usage limits. This counter tracks lifetime typing sessions for free users and is stored in your account.

Local extension settings → Used to remember your preferred typing speed, mode, shortcut key, and Human Feel options so the Extension works according to your preferences each time you use it.

User-provided popup or side panel text → Used only to perform the typing automation action you request. This text is stored locally on your device and is not sent to our servers. The popup and side panel are two interchangeable UI surfaces that share the same local chrome.storage.local entry — no new data is collected when you use one instead of the other.

Website field interaction → Used only to detect the currently focused text field and dispatch simulated keyboard events to type the text you provided. This access is used solely to perform the typing action you requested.

5. Data Storage: Local vs. Server

Your data is stored in different locations depending on its type:

Stored locally on your device (chrome.storage.local):

This data never leaves your device and is not transmitted to any server.

Stored on Firebase / Google Cloud servers:

This data is stored securely on Google Cloud infrastructure used by Firebase.

Processed by Paystack (not stored by Phantom Typer):

Phantom Typer does not see or store your payment card information. Paystack handles all payment card processing.

Processed by Vercel backend:

The Vercel backend acts as a secure intermediary to verify payment webhooks from Paystack and update your subscription status in Firebase. It does not store user data persistently.

6. Data Sharing

This section describes exactly what data leaves your device, who receives it, and why.

Data shared with Firebase (Google Cloud):

Data shared with Paystack (payment processor):

Phantom Typer receives only a payment confirmation status (success/failure) and a reference ID from Paystack. No card details are transmitted to or stored by Phantom Typer.

Data shared with Vercel backend:

The Vercel backend acts as a secure intermediary. It does not store user data persistently.

Data that is NEVER shared or transmitted:

We do not:

7. Third-Party Services

We use the following trusted third-party services. Each service's own privacy policy governs how they handle data they receive:

Firebase by Google (Google Cloud): Used for user authentication (Google Sign-In) and storing account and subscription data. Firebase is operated by Google and subject to Google's privacy policies.

Paystack: Used for payment processing when users upgrade to Pro. Paystack handles all payment card details directly. Phantom Typer receives only payment confirmation status. Paystack is subject to Paystack's privacy policy.

Vercel: Used to host a serverless backend that receives payment webhooks from Paystack and updates subscription status in Firebase. The Vercel backend does not store user data persistently.

8. Website Content and Host Permissions

Phantom Typer requests broad website access permissions (<all_urls>) in its Chrome extension manifest. This section explains why this access is needed and exactly how it is used.

Why broad access is required:

Phantom Typer's core function is to simulate typing into text fields on websites chosen by the user. Because users may want to type on any website (email clients, document editors, forms, messaging apps, CMS platforms, etc.), the Extension needs permission to run its content script on all websites. Without this permission, the Extension would not be able to detect or interact with text fields on most websites.

What the Extension does with website access:

What the Extension does NOT do with website access:

9. Data Retention

This section describes how long each type of data is retained:

Local data (on your device):

Account and Authentication data (on Firebase servers):

Payment data (on Paystack):

10. User Consent and Opt-Out

Phantom Typer collects data only with your informed consent:

How consent is collected:

How to withdraw consent / opt out:

Offline / local-only mode:

You can use Phantom Typer without creating an account. In this mode, all data stays on your device, nothing is transmitted to any server, and the Extension functions as a fully offline typing tool (limited to free-tier speeds and session count).

11. Legal Basis for Processing

We process your personal data on the following legal bases:

12. Data Security

We take the following measures to protect your data:

13. User Control and Data Deletion

You have full control over your data:

14. Children's Privacy

Phantom Typer is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.

15. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, features, or legal requirements. Any changes will be posted on this page with an updated effective date. If we make material changes to how we handle your data, we will notify users through the Extension's popup before the changes take effect. We encourage you to review this policy periodically.

16. Chrome Web Store User Data Policy Compliance

Phantom Typer complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Limited Use Disclosure:

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

17. Contact Us

If you have any questions, concerns, or requests regarding this privacy policy or your personal data, contact us at:

📧 gmuraguri75@gmail.com