1. Introduction
Phantom Typer — Human Typing Simulator ("the Extension") is a Chrome browser extension that provides user-controlled typing automation. The Extension allows users to prepare text in a popup interface, configure typing speed and behavior settings, and then simulate realistic human-like keyboard input into text fields on websites chosen by the user.
This privacy policy explains in detail what data we collect, how we handle and use that data, where it is stored, how long it is retained, and whether and how it is shared with third parties. We are committed to protecting your privacy and collecting only the minimum data necessary to provide the Extension's functionality.
📌 Chrome Web Store Compliance & Data Disclosure Matrix
The table below provides a quick reference to our data collection, handling, storage, retention, and sharing practices in full accordance with the Chrome Web Store User Data Policy.
| Data Category | Collected? | Handling / Purpose | Storage Location | Retention Period | Sharing / Disclosure |
|---|---|---|---|---|---|
| Personal Info (Email, User ID) | Yes (Optional) | Account authentication & subscription management | Firebase (Google Cloud) | Duration of account (deleted on request) | Firebase (Google) only |
| Authentication Info (Passwords & Tokens) | Yes (Optional) | User account registration & login authentication via Firebase | Firebase Auth (Cryptographically hashed; plain text NEVER stored) | Duration of account (deleted on request) | Firebase Auth (Google) only — NEVER shared or sold |
| User-Provided Text | Local Only | Typing automation into selected web fields | Local device (chrome.storage.local) | Until uninstalled or cleared by user | NEVER shared or transmitted |
| Website Content & Access | No Data Collected | Focus field & dispatch keystrokes on demand | None (No storage) | Transient in-memory during typing | NEVER shared or transmitted |
| Financial & Payment Info | Processed by Paystack | Pro subscription checkout | Paystack (PCI-DSS compliant) | Per Paystack policy (Not stored by us) | Paystack (Payment processor) |
| User Activity & Web History | NO | Session count tracked for free tier limits | Firebase & Local Storage | Duration of account | NEVER shared or sold |
2. Data We Collect
We collect and process the following categories of data to provide the Extension's features:
Account and Authentication Information (including Passwords):
- Email address: Provided by you when signing up or logging into an optional account (via email/password or Google Sign-In).
- Account passwords: When you register or log in using an email address and password, your chosen password is collected solely to authenticate your identity and protect your account. Passwords are sent securely over encrypted HTTPS (TLS) connections directly to Google Firebase Authentication. Phantom Typer never views, logs, or stores your plain-text password. Google Firebase securely hashes and salts passwords using industry-standard cryptographic algorithms.
- Firebase user ID & account identifier: A unique identifier generated by Firebase to track your account and associate your Pro subscription status.
- Authentication tokens and session credentials: Secure JSON Web Tokens (JWTs) issued by Google Firebase Authentication to maintain your authenticated session.
Important: Account registration is completely optional. You can use Phantom Typer offline on the free tier without ever entering an email or password.
Subscription and Payment Data:
- Subscription status (free or Pro)
- Subscription plan type (monthly or yearly)
- Subscription expiration date
- Payment confirmation and transaction status (received from the payment provider)
Important: Phantom Typer does not collect, see, or store payment card numbers, CVVs, bank account details, or other financial credentials. All payment card processing is handled entirely by Paystack, our third-party payment processor.
Usage Data:
- Typing session count (used to enforce free-tier usage limits)
Local Extension Settings (stored on your device):
- Typing speed preference
- Typing mode selection (Always Type, Replace, If Empty, If Content)
- Keyboard shortcut preference
- Human Feel toggle states (randomized delays, natural pauses, typo simulation, invisible paste, keyboard sounds, keep line breaks)
- Other UI preferences and feature toggles
User-Provided Text (stored locally on your device):
- Text entered by the user into the Extension's popup or side panel text area
Important clarification: When you enter or paste text into the Phantom Typer popup or side panel, that text is saved locally in Chrome extension storage (chrome.storage.local) on your device so it persists between sessions. This text is not transmitted to our servers. It remains on your device and is used only to perform the typing action you request. The Side Panel is an additional UI surface only — it does not collect any new data or introduce any new server traffic; it reads and writes the same locally stored text the popup uses.
Website Field Interaction Data:
- Detection and focusing of the active input field, textarea, or contenteditable element on the current page
- Simulated keyboard events dispatched to the focused field to type user-provided text
Important: This interaction is limited to performing the typing action requested by the user. The Extension does not read, collect, scrape, or transmit the existing content of web pages or form fields to any server.
3. Data We Do Not Collect
To be fully transparent, we explicitly state that Phantom Typer does not collect, store, or transmit the following:
- We do not sell, rent, or trade user data to any third party.
- We do not collect or store browsing history.
- We do not track which websites you visit.
- We do not record or log keystrokes.
- Third-party website passwords & credentials: We do NOT read, capture, intercept, or collect passwords, login credentials, or sensitive authentication data entered into fields on third-party websites. (Phantom Typer only processes the password you choose when creating your optional Phantom Typer extension account).
- We do not store your Phantom Typer account password in plain text.
- We do not transmit the text typed into website fields to our servers.
- We do not collect, see, or store payment card numbers, CVVs, or bank details.
- We do not use any collected data for advertising, profiling, or credit decisions.
- We do not use cookies for advertising or user tracking.
- We do not monitor or log browsing activity.
- We do not collect the contents or HTML of web pages you visit.
4. How We Handle and Use Your Data
Each type of data we collect is used for a specific, limited purpose directly related to providing the Extension's functionality:
Account passwords and authentication credentials → Used strictly to authenticate your identity, create your user account, and protect access to your Pro subscription features via Google Firebase Authentication. Passwords are transmitted directly to Firebase via encrypted HTTPS and are never stored in plain text or used for any other purpose.
Email address and account identifiers → Used to identify your user account, authenticate your identity via email or Google Sign-In, and maintain your login session.
Subscription status, plan type, and expiration date → Used to determine whether you have an active Pro subscription and to unlock or restrict premium features accordingly.
Payment confirmation/status → Used to verify successful payment and activate or renew your Pro subscription. We receive only confirmation of payment status from Paystack, not your card details.
Typing session count → Used to enforce free-tier usage limits. This counter tracks lifetime typing sessions for free users and is stored in your account.
Local extension settings → Used to remember your preferred typing speed, mode, shortcut key, and Human Feel options so the Extension works according to your preferences each time you use it.
User-provided popup or side panel text → Used only to perform the typing automation action you request. This text is stored locally on your device and is not sent to our servers. The popup and side panel are two interchangeable UI surfaces that share the same local chrome.storage.local entry — no new data is collected when you use one instead of the other.
Website field interaction → Used only to detect the currently focused text field and dispatch simulated keyboard events to type the text you provided. This access is used solely to perform the typing action you requested.
5. Data Storage: Local vs. Server
Your data is stored in different locations depending on its type:
Stored locally on your device (chrome.storage.local):
- Extension settings (typing speed, mode, shortcut, toggles)
- User-provided text from the popup or side panel text area
- Cached authentication state
- Free-tier usage counter (cached locally, synced with your account)
This data never leaves your device and is not transmitted to any server.
Stored on Firebase / Google Cloud servers:
- Email address and Firebase user ID
- Account password authentication hashes (passwords are securely salted and hashed by Google Firebase Authentication; plain-text passwords are NEVER stored)
- Authentication tokens and session data
- Subscription status, plan type, and expiration date
This data is stored securely on Google Cloud infrastructure used by Firebase.
Processed by Paystack (not stored by Phantom Typer):
- Payment card details and billing information
- Transaction records
Phantom Typer does not see or store your payment card information. Paystack handles all payment card processing.
Processed by Vercel backend:
- Payment webhook verification (confirms payment success and updates subscription status in Firebase)
The Vercel backend acts as a secure intermediary to verify payment webhooks from Paystack and update your subscription status in Firebase. It does not store user data persistently.
6. Data Sharing
This section describes exactly what data leaves your device, who receives it, and why.
Data shared with Firebase (Google Cloud):
- Email address and account password — transmitted over encrypted HTTPS directly to Google Firebase Authentication to verify credentials and authenticate your account
- Firebase user ID — to identify your account
- Subscription status, plan type, and expiration — to manage Pro access
- Typing session count — to enforce free-tier usage limits
Data shared with Paystack (payment processor):
- Email address — pre-filled on the Paystack checkout page
- Payment card details — entered by you directly on Paystack's page (Phantom Typer never sees or handles this data)
Phantom Typer receives only a payment confirmation status (success/failure) and a reference ID from Paystack. No card details are transmitted to or stored by Phantom Typer.
Data shared with Vercel backend:
- Firebase authentication token — to verify your identity when confirming payment
- Payment reference — to verify payment status with Paystack
The Vercel backend acts as a secure intermediary. It does not store user data persistently.
Data that is NEVER shared or transmitted:
- Your plain-text account password (never stored, logged, or shared; managed solely via Google Firebase cryptographic hashes)
- Passwords or credentials entered into third-party websites (Phantom Typer never captures, logs, or intercepts third-party passwords)
- The text you enter in the popup or side panel (stays on your device)
- Your extension settings (speed, mode, shortcuts, toggles — stays on your device)
- The content of web pages you visit
- Your browsing history or the URLs you visit
- Any data typed into website fields
We do not:
- Sell, rent, or trade user data to any third party.
- Share user data with advertisers or data brokers.
- Use user data for advertising, profiling, or credit decisions.
- Share data with any party other than the three services listed above, and only for the purposes described.
7. Third-Party Services
We use the following trusted third-party services. Each service's own privacy policy governs how they handle data they receive:
Firebase by Google (Google Cloud): Used for user authentication (Google Sign-In) and storing account and subscription data. Firebase is operated by Google and subject to Google's privacy policies.
Paystack: Used for payment processing when users upgrade to Pro. Paystack handles all payment card details directly. Phantom Typer receives only payment confirmation status. Paystack is subject to Paystack's privacy policy.
Vercel: Used to host a serverless backend that receives payment webhooks from Paystack and updates subscription status in Firebase. The Vercel backend does not store user data persistently.
8. Website Content and Host Permissions
Phantom Typer requests broad website access permissions (<all_urls>) in its Chrome extension manifest. This section explains why this access is needed and exactly how it is used.
Why broad access is required:
Phantom Typer's core function is to simulate typing into text fields on websites chosen by the user. Because users may want to type on any website (email clients, document editors, forms, messaging apps, CMS platforms, etc.), the Extension needs permission to run its content script on all websites. Without this permission, the Extension would not be able to detect or interact with text fields on most websites.
What the Extension does with website access:
- Detects and focuses the active input field, textarea, contenteditable element, or supported rich text editor on the current page
- Dispatches simulated keyboard events (keydown, keypress, input, keyup) to type user-provided text into the focused field
- Interacts with supported iframe-based editors when necessary (using
all_frames: true) - Uses experimental main-world script injection for Google Docs compatibility
- Provides a dockable Chrome Side Panel (
chrome.sidePanel) that mirrors the popup's Save Text and Start Typing controls and adds a Stop button. The Side Panel reads and writes the same locally stored text the popup uses; it does not access any additional page content and does not transmit data to any server.
What the Extension does NOT do with website access:
- Does not read, collect, scrape, or store the existing content of web pages
- Does not intercept, capture, read, or collect passwords or credentials from web pages or login forms
- Does not collect or transmit form field values to any server
- Does not collect or transmit browsing history
- Does not inject advertisements or tracking scripts
- Does not modify web page content for any purpose other than typing the user's requested text
- Does not send any page content, URLs, or field data to our servers or any third party
9. Data Retention
This section describes how long each type of data is retained:
Local data (on your device):
- Extension settings, saved text, and cached state are retained until you uninstall the Extension, clear extension data via
chrome://extensions, or manually clear the data.
Account and Authentication data (on Firebase servers):
- Email address, user ID, password authentication hashes, subscription status, and usage count are retained for as long as your account exists.
- You may request deletion of your account and all associated server-side credentials and data at any time by emailing gmuraguri75@gmail.com. We will permanently delete your account, authentication records, and data within 30 days.
Payment data (on Paystack):
- Payment records are retained by Paystack according to Paystack's data retention policy. Phantom Typer does not store payment card information.
10. User Consent and Opt-Out
Phantom Typer collects data only with your informed consent:
How consent is collected:
- Before you can sign in or create an account, you must check a consent checkbox that summarises the data collected and links to this full Privacy Policy.
- No account data is collected or transmitted until you actively agree.
- The consent checkbox lists the specific types of data collected and how they are used.
How to withdraw consent / opt out:
- Sign out: Click the sign-out button in the Extension popup to stop all server-side data collection immediately.
- Use without an account: The Extension's basic local features (saving text, typing at Slow/Normal speed) work without signing in. No data leaves your device in this mode.
- Uninstall: Removing the Extension from Chrome deletes all locally stored data.
- Request account deletion: Email gmuraguri75@gmail.com to have all server-side account data permanently deleted.
Offline / local-only mode:
You can use Phantom Typer without creating an account. In this mode, all data stays on your device, nothing is transmitted to any server, and the Extension functions as a fully offline typing tool (limited to free-tier speeds and session count).
11. Legal Basis for Processing
We process your personal data on the following legal bases:
- Consent: You provide explicit consent via the Privacy Policy consent checkbox before signing in. You may withdraw consent at any time by signing out or requesting account deletion.
- Contractual necessity: Processing subscription status and payment verification data is necessary to fulfil the Pro subscription contract between you and Phantom Typer.
- Legitimate interest: We process usage count data to enforce free-tier limits, which is a legitimate interest in maintaining a sustainable freemium service. This processing is minimal and does not override your privacy rights.
12. Data Security
We take the following measures to protect your data:
- Password Protection: Passwords entered for Phantom Typer accounts are transmitted exclusively over encrypted HTTPS (TLS) connections directly to Google Firebase Authentication. Passwords are never stored in plain text, are never accessible to Phantom Typer staff, and are protected by Google's industry-standard cryptographic salted hashing algorithms (scrypt/bcrypt).
- All communication with Firebase, Paystack, and Vercel is conducted over HTTPS (encrypted in transit).
- Payment card details are handled entirely by Paystack, a PCI-DSS compliant payment processor. Phantom Typer never sees or handles your card information.
- User authentication is handled by Firebase Authentication (Google), which provides industry-standard security measures including secure token management.
- Local extension data (settings, user-provided text) is stored in Chrome's extension storage API, which is sandboxed and accessible only to the Extension.
- The Vercel backend uses secret keys to verify the authenticity of payment webhooks.
13. User Control and Data Deletion
You have full control over your data:
- Clear local data: You can clear all locally stored extension data (settings, saved text, cached state) by removing or resetting the Extension in Chrome's extension management page (
chrome://extensions). - Request account deletion: You may request deletion of your account and all associated server-side data (email, user ID, subscription status) by emailing gmuraguri75@gmail.com. We will process your request within 30 days.
- Cancel subscription: You may cancel your Pro subscription at any time. Contact support for assistance with cancellation or refunds.
- Data export: You may request a copy of your stored data by emailing gmuraguri75@gmail.com.
14. Children's Privacy
Phantom Typer is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.
15. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, features, or legal requirements. Any changes will be posted on this page with an updated effective date. If we make material changes to how we handle your data, we will notify users through the Extension's popup before the changes take effect. We encourage you to review this policy periodically.
16. Chrome Web Store User Data Policy Compliance
Phantom Typer complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Limited Use Disclosure:
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- We limit our use of user data to the practices explicitly disclosed in this privacy policy.
- We do not transfer user data to third parties except as necessary to provide or improve the Extension's user-facing features, as described in Sections 6 and 7, or as required by law.
- We do not use or transfer user authentication information (such as passwords or authentication tokens) for any purpose other than authenticating the user and providing access to their Phantom Typer account.
- We do not use or transfer user data for serving advertisements.
- We do not use or transfer user data for creditworthiness or lending purposes.
- We do not allow humans to read user data, except with the user's affirmative consent for specific messages (e.g., support requests), if necessary for security purposes (e.g., investigating abuse), or to comply with applicable law.
17. Contact Us
If you have any questions, concerns, or requests regarding this privacy policy or your personal data, contact us at: