Session Share Add to Chrome

Privacy Policy

Last updated October 3, 2026

This policy describes the Session Share Chrome extension and the Session Share Plus purchase, operated by Shayu Liang (Scott Leung), an individual developer based in China. Contact: support@sharkx.ai.

Summary

Data that stays on your device

When you save, switch, copy or paste a login, the extension reads and writes the current site's cookies, and Local Storage and Session Storage only if you enable that for the site. Saved logins, their names, sites and times are stored in Chrome's extension storage, encrypted with AES-GCM using a key kept in the same browser profile. This protects them from casual inspection, not from someone with access to your unlocked computer. Auto-save is off until you turn it on for a site. Uninstalling the extension deletes this data.

Share codes and the clipboard

Share codes are created only when you copy one and contain the login they share. Without a separate password, anyone holding the code can use it. The extension reads the clipboard only when you paste a session and writes to it only when you copy one. Notifications report only the result of a right-click or address-bar action.

Permissions

The extension can access all websites so it can read and write the current site's cookies when you act on it; it runs no scripts in the pages you browse unless you save or restore Web Storage. The popup shows the current site's own icon, which Chrome provides for the open tab.

Ads (free version)

This extension uses AdsOnBread to display contextual ads. The SDK stores a random pseudonymous token and a 24-hour expiration time in local extension storage and transmits the unexpired token, browser language, impressions, and clicks to AdsOnBread for frequency capping, billing accuracy, and fraud prevention. An expired storage record is replaced the next time the SDK runs and can also be removed by clearing extension storage or uninstalling. AdsOnBread also derives coarse country from the network request. This information is not used for behavioral advertising or cross-site profiling. See the AdsOnBread privacy policy. Website addresses, cookies, account names and share codes are never sent to AdsOnBread. Clicking an ad opens the advertiser's site, which has its own privacy practices.

Plus purchases

When you start or restore a purchase, the extension contacts our billing service at billing.sharkx.ai, hosted on Cloudflare. It stores a hash of a random installation credential, the Creem checkout and order IDs, the price tier and the purchase status, and keeps webhook event IDs for 90 days to prevent replays. The price tier is chosen on your device from your browser's time zone; your time zone, country and IP address are not stored. Payment is processed by Creem, the merchant of record, which handles your name, email, payment details and tax information under the Creem privacy policy. We never see your card number.

Purchase records are kept while Plus is active and for up to 7 years after a refund or chargeback where needed for accounting. Cloudflare may process connection data (such as IP addresses) to deliver and protect the service; we do not log requests.

Your choices

Delete any saved login in the extension, turn auto-save off per site, or delete all local copies in the Stored on this device screen. To ask about or delete purchase records, email us with your order number.

Children

Session Share is not directed at children under 13.

Changes

We will update the date above when this policy changes and tell you in the extension about significant changes.