SkillPiece Back to home

Privacy and data

Privacy policy

How the SkillPiece Chrome extension stores, processes, and protects the ideas you capture and the explanations you write.

Last updated September 5, 2026

The SkillPiece extension has no SkillPiece-operated backend, accounts, analytics, telemetry, or advertising. Your library stays in your browser.

What SkillPiece stores

SkillPiece stores the information needed to provide capture, explanation practice, and scheduling:

  • Captured text, source titles, source URLs, and short supporting quotes.
  • Generated explanations, focused learning-point sections, recall questions, and explanation checks.
  • Your typed answers, practice results, review history, and local schedule.
  • Your settings, including provider profiles and any API key you choose to save.

Learning data is stored in IndexedDB. Settings and provider keys are stored in Chrome extension local storage. Keys are never stored in Chrome sync storage.

What SkillPiece collects

The extension does not collect data for SkillPiece. It has no SkillPiece analytics service, telemetry endpoint, account system, crash reporter, advertising network, or learning-data backend.

Local processing and storage still count as handling data. This policy explains that handling even when nothing leaves your device.

Chrome Web Store Limited Use

SkillPiece's use of information received through Chrome extension APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Data is used only to provide the extension's disclosed learning features. It is never sold, used for advertising, or used to determine creditworthiness or lending. It is transferred only when needed to provide a feature you request, such as sending the necessary text directly to the model endpoint you chose. Humans do not read your data except when you explicitly ask for support and consent to sharing it, when required for security or abuse investigation, or when required by law.

When text leaves your browser

Chrome built-in model

When you use Chrome's on-device model, model processing happens on your device. Captured text and answers are not sent to SkillPiece, Google, or another model provider by the extension.

A provider you configure

When you choose a remote provider, model work begins only after an explicit request. Capture selection sends the cleaned selected passage, its structure-aware source units when available, the page title, and local selectors. Capture page sends only the Readability-cleaned page, its source units, and the page title. Each source unit is sent as one small sequential request so complete Concepts and knowledge pieces can be validated and saved incrementally. Check explanation sends the saved questions, frozen checks, and your typed answer.

Each requested model action is tied to the provider setup selected when you pressed it, without copying that setup's key, endpoint, or model name into the waiting work. If the selected provider or its configuration changes before the request is sent, SkillPiece sends nothing and marks the action failed. Retry is a new user action and uses the model selected at that time.

The separately stored source URL is never added to a model request. Captured text may itself contain a URL. Existing topics, concepts, and unrelated library content are not included. A terminal failure requires an explicit retry or self-grading. If Chrome terminates the extension service worker while a requested job is still running, the durable queue may resume that job so the user's work is not lost. Timers, page visits, and worker startup do not originate speculative model work or retry a terminal failure.

The provider receives and processes that data under its own terms and privacy policy. SkillPiece does not proxy the request and does not receive a copy. If the configured endpoint uses an API key, the key is sent only to that endpoint as request authorization and is not included in the model prompt. Remote endpoints must use HTTPS.

A local endpoint

When you configure a loopback endpoint such as Ollama on localhost, requests stay on your device. Plain HTTP is accepted only for loopback addresses. Remote endpoints must use HTTPS.

Website access

On ordinary web pages, an isolated extension script detects meaningful text selections so it can show Focus on selection, Capture selection, and Capture page while Quick capture is enabled. Merely selecting text does not save it or send it anywhere. Focus shows a local clean reader and never stores or transmits page content.

Opening the extension popup while Quick capture and a model are ready can read up to 161 characters of the current selection locally for an ephemeral selected-text preview. The preview disappears with the popup and is not stored or sent to a provider. Popup Focus opens the full Readability-cleaned page locally. Turning Quick capture off disables the floating actions, popup capture controls, both capture context menus, and the capture shortcut; local popup Focus remains available.

The separately stored source URL fields stay local. After Capture selection or Capture this page, SkillPiece can compare the current URL locally and show capture progress and matching Concept links beside the source page. This separate companion can be disabled in Settings under Privacy and data.

Your responsibility for source material

SkillPiece is intended for personal learning and individual study. You are responsible for ensuring that you have the right to access, capture, store, process, and, when a remote provider is configured, transmit any source material you use with SkillPiece.

Do not use SkillPiece to bypass access controls, violate a website's terms, infringe copyright, confidentiality, or other proprietary rights, or reproduce or distribute material you are not authorized to share. A personal or educational purpose does not by itself grant permission to use protected material. Review the source's terms and license and the selected model provider's policies before sending content. Use Chrome's built-in model or a local endpoint when material must remain on the device.

Notifications

On pages where Chrome prevents extension-owned page interface, a local notification may show capture status without captured text. If reminders are enabled, a local system notification can name concepts that are ready for practice. Those names may be visible on a lock screen or shared display. Nothing is transmitted to SkillPiece to create either notification.

Your controls

  • Export or import your complete local library. Backup exports never include provider keys and replace raw provider or job error text with fixed local text.
  • Export a topic without practice history, answers, raw captured text, source URLs, or provider keys.
  • Edit or delete concepts and captured sources.
  • Purge captured source text while keeping the concepts created from it.
  • Disable Quick capture, reminders, and the source-page companion.
  • Erase all SkillPiece learning data, including unsubmitted recall drafts, from Settings, or remove the extension.

Importing a backup never starts model work. Imported pending or running jobs and pending grades are restored as failed, then require an explicit Retry or self-grade action. Full replacement and Start over invalidate and clear unsubmitted recall drafts, stored capture-error details, active SkillPiece reminder notifications, and capture-toast Undo grants from the prior library.

Security boundaries

Provider keys are restricted to trusted extension contexts and excluded from exports and diagnostic reports. Diagnostic exports contain counters and allowlisted job metadata only, never raw provider errors or learning content. Model output is treated as untrusted data, validated, and rendered as text rather than executable HTML.

SkillPiece cannot protect data from malware or someone who already controls your browser profile. It also cannot control how a remote provider uses information you intentionally send to it.

Public website

The extension has no SkillPiece-operated backend and sends no learning data to SkillPiece. The public website's hosting infrastructure may process standard request metadata needed to serve and secure the site. Website request metadata is not combined with extension learning data.

Contact

Privacy and support questions can be sent to support@skillpiece.com. Never send an API key, captured private passage, or private explanation.

Changes to this policy

If SkillPiece's data handling changes, this page and the extension's disclosure will be updated before the new behavior is released.