The policy
Your sessions stay on your machine. The sessions you create, the cookies they hold, your settings and the extension's journal are stored in your browser profile and never sent to us or anyone else. NVX Session has no account and no server that sees your browsing.
What can leave your browser, and only in these cases:
- Anonymous usage counts, if you turn them on. Off by default. A random install id, the extension version, your OS family, CPU type, browser brand and major version, UI language and whole-hour time zone offset, and rounded counts of how features are used, errors and timings. Never a web address, a site name (other than which of a fixed list of major sign-in providers, such as google.com or okta.com, had trouble), a cookie, an account or a session name. Turning it off deletes the install id and anything not yet sent.
- Licence checks, if you enter a Pro key. The key, a random device id the extension made, a label like “Windows, Chrome”, and a hashed summary of coarse computer traits so browsers on the same computer share one licence seat. The hash includes your licence key, so it is different for every licence and cannot be used to recognise you anywhere else.
- Problem reports, if you send one. What you wrote, your email if you gave it, and, if you leave diagnostics on, the extension version, settings, counts of sessions and tabs and its recent journal, with site and session names removed unless you choose to include site names. You see exactly what is sent before you send it.
We do not sell data, use it for advertising, or use it for anything other than running and improving NVX Session. Payments are handled by Polar (polar.sh) on our website, never inside the extension. Usage counts are kept for at most 12 months. Problem reports are deleted 90 days after they arrive.
Uninstalling the extension removes everything it stored. Cookies it copied from your browser during setup were copies: your browser's own cookies were never moved.
Contact: support@nvx.sh, or https://session.nvx.sh/support
The detail
Usage counts
The format is a closed allowlist: every field is a fixed choice, a range or a bounded number, with no free text anywhere, so a URL or a cookie cannot be sent even by accident. The complete list is published at what it collects, generated from the same definition the server checks against. Each batch carries a small proof of work so the counts cannot be cheaply flooded; it contains nothing about you.
The install id is random and connected to nothing else. You can see it in Settings, under “Anonymous usage stats”, once stats are on. Usage rows are deleted 12 months after they arrive.
Licence checks
The device id is made by the extension the first time it needs one. The computer summary is a one-way hash of coarse traits every browser on one computer shares (operating system and version, processor type and core count, a memory range, the graphics renderer and the time zone), salted with your licence key. It lets Chrome, Edge, Brave and Arc on the same computer share one seat, and nothing more: it cannot be reversed, and it is different for every licence.
To tell one computer from a copy of its browser profile on another, the server also keeps a keyed hash of the network your requests come from, cut to the block of addresses your provider assigns (never the address itself), with a key that changes every month. Licence keys are looked up by their hash and kept encrypted so a lost key can be sent to you again. All of it is deleted with the licence.
Problem reports
A report is read by the author to fix the problem, and your email, if you gave one, is used only to reply. If the extension could not send it and you pasted it on the support page instead, it is handled the same way. Every report, email included, is deleted 90 days after it arrives.
Sync (Pro)
Off unless you turn it on. It carries your session structure: names, colours, pinned domains and settings. It never carries cookies, logins, history or page content: a session that arrives on another device is a labelled shell you sign into there.
The structure is encrypted on your device with a key derived from a passphrase you choose. The passphrase never leaves your devices, so what reaches the server is ciphertext we cannot read. If you forget the passphrase, the synced copy cannot be recovered; we can only delete it.
Buying Pro, and your account
Pro is sold through Polar, the merchant of record, which handles payment and tax. Your card details go to Polar and its payment processor, never to us. We receive the email you paid with and the order references, and use them only to issue, send and recover your key, run the “Your account” page, and handle refunds.
Signing in to your account uses a single-use link emailed to that address. Opening it sets one cookie on this site, which names the address and expires after an hour. There are no other cookies on this site, and no third-party analytics, advertising or tracking service here or in the extension.
Your choices
Turn usage counts off at any time in the extension's settings, which stops collection and erases the install id. To have data linked to an install id deleted sooner, write to support@nvx.sh with that id; because the data is anonymous, it cannot be found without it. To have a report or your licence details deleted, write from the address involved.
A risk worth naming
Signing into a federated provider such as Google inside a session can, in rare cases, leave a partially written login. Providers treat that as a possibly compromised session and may sign you out across your devices. The extension detects this pattern and steps back rather than retrying into it, and signing in fresh inside a session avoids it.
Children
This is a developer tool and is not directed at children. No data is knowingly collected from anyone under 13.
Changes
If this policy changes, the date at the top changes with it. Material changes to what is collected also appear in the changelog. The author is based in Victoria, Australia.