All privacy policies

Effective and last updated: 29 July 2026

Extension-specific privacy policy

Published by Selfhood Studios

Shiori privacy policy.

This policy applies only to Shiori — Tab Manager & Session Saver, version 0.1.1. It explains what user data the extension handles, how the data is collected and used, where it is stored, how long it is retained, and every party it may be shared with.

Extension version
0.1.1
Selfhood account
Not required
Policy scope
Shiori only
[ 01 ]

Scope

This page is the complete, extension-specific privacy disclosure for Shiori. It does not describe another Selfhood Studios extension. The studio-wide policy remains available at /privacy.

Shiori requires no Selfhood Studios account. Extension data is processed locally unless a feature you deliberately use needs to contact a destination identified in the sharing section below.

[ 02 ]

Data collected or handled

Saved tab titles, URLs, and favicons, session groups, folders, tags, notes, to-dos, automation rules, optional tab preview screenshots, on-device search embeddings, preferences, and any AI provider API key or sync passphrase you choose to save.

[ 03 ]

How collection occurs

The extension obtains this data when you provide or save it, or when you invoke a user-facing feature that needs access through the extension's disclosed Chrome permissions. It does not collect the data for unrelated purposes.

[ 04 ]

How data is used

To save and restore tab sessions, free memory, search and organize your saved tabs locally, and run user-created automation rules. Semantic search embeddings are computed on-device.

The data is not used for personalized advertising, unrelated profiling, credit or eligibility decisions, resale, or data-broker services.

[ 05 ]

Handling and storage

Extension content, preferences, and credentials are kept in browser-managed local storage on your device unless the sharing disclosure below says a selected feature sends specific data elsewhere. The extension does not use a Selfhood Studios account, sync, analytics, advertising, or telemetry backend.

Selfhood Studios cannot inspect, recover, or restore data that remains only in your browser profile.

[ 06 ]

All parties data is shared with

No data is sent to Selfhood Studios. Shiori has no content scripts and no telemetry. Only if you enable optional AI are saved tab titles, URLs, and group titles sent directly to the provider you configure; optional sync uses Dexie Cloud under your control.

No data is sold or rented, shared with data brokers, or transferred for personalized, retargeted, or interest-based advertising. External recipients process data under their own terms, privacy policies, account settings, and retention controls.

[ 07 ]

Retention and deletion

Locally stored data remains until you delete it through the extension, reset the extension, or uninstall it. Data sent to a provider or destination at your request follows that recipient's retention policy; Selfhood Studios cannot retrieve or delete that copy for you.

Before uninstalling, use the extension's delete, clear, reset, or export controls where available. Uninstalling normally removes browser-managed extension storage from that Chrome profile.

[ 08 ]

Security

Remote requests containing user data or credentials use secure transport such as HTTPS or WSS, except a user-configured service that is deliberately hosted on the same device or private network. Authentication information is not publicly disclosed.

Local data relies on Chrome's extension isolation and the security of your Chrome profile, operating system, and device. No security measure is absolute; protect your device account and revoke a provider credential if you believe it has been exposed.

[ 09 ]

Chrome Web Store Limited Use disclosure

User data is used only to provide or improve Shiori's disclosed single purpose and user-facing features. Selfhood Studios does not permit personnel or contractors to read extension data. Routine human access is not possible because Selfhood Studios does not receive extension content.

The limited exceptions are when you explicitly send specific data for support, access is necessary to investigate security or abuse, disclosure is required by law, or data is first aggregated and anonymized for lawful internal operations.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

[ 10 ]

Notice, choices, and contact

Where a feature sends data to a third party, the transfer must be disclosed before it begins and occur only after an affirmative user action. You can avoid the transfer by not invoking or enabling that optional feature, and you can remove local data through the controls described above.

Analytics on this marketing website are separate from the extension and cannot access its stored content. Website practices are explained in the studio-wide privacy policy.

For a privacy question, rights request, or security report, contact Selfhood Studios. Do not send API keys or unrelated private content.