# プライバシーポリシー / Privacy Policy

**最終更新日: 2026年9月26日 / Last Updated: September 26, 2026**
**同意バージョン: 2026年9月8日 / Consent Version: September 8, 2026**

> 最終更新日は文書の改訂日です。全利用者に再同意を求める場合は「同意バージョン」を更新します。
> The Last Updated date is the document's revision date. Re-prompting every user is driven by the Consent Version line instead.

> **更新履歴 / Update History**:
> - **2026年9月8日**: v6.8.0 - 閲覧履歴アーカイブ機能のデータフローと、ブラウザ内蔵 AI のデータ取り扱いについて追記
> - **2026年7月31日**: v6.7.0 - プライバシー同意撤回時のデータ削除確認ダイアログについて追記
> - **2026年6月20日**: v6.0.1 - GDPR 準拠修正。プライバシー同意拒否を「永久非表示」から「30日後に再表示」に変更
> - **2026年6月13日**: v5.1.0 - PII サニタイゼーション強化（多言語対応）、データ保持期間の自動削除実装
> - **2026年6月11日**: v5.0.0 - SQLite (OPFS) 移行、データ保持ポリシー追加、GDPR 削除権の物理削除対応
> - **2026年3月9日**: v4.2.1 - 自動コンテンツフェッチ機能の有効化手順、URLログの記録について追加
> - **2026年2月23日**: v4.1.3 - マスターパスワード保護機能追加

[日本語](#日本語) | [English](#english)

---

## 日本語

### 概要
Yasumaro（以下「本拡張機能」）は、ユーザーのプライバシー保護に努めています。本ポリシーでは、収集されるデータ、その使用方法、およびユーザーの権利について説明します。

### データの収集
本拡張機能は、以下のデータを**ユーザーのデバイス上のみ（ローカル）**で収集します。

1. **閲覧履歴データ**:
   - 訪問したページのURL
   - ページのタイトル
   - 滞在時間
   - スクロール深度
   - ページ内容（AI要約生成用）
   - 遷移記録（オプトイン時のみ）: 直前に開いていたページのURL、検索エンジンの検索語

2. **構成データ**:
   - Obsidian API キー
   - Obsidian サーバー設定（プロトコル、ポート、パス）
   - AI プロバイダーの API キー（Google Gemini、OpenAI互換API等）
   - 設定情報（最小滞在時間、スクロール深度など）

### データの保存場所
- 閲覧履歴データは、デバイス上の **OPFS (Origin Private File System) 上の SQLite DB** に保存されます。
- すべての設定データは、デバイス上の **Chrome ローカルストレージ** に保存されます。
- 閲覧履歴は、ユーザー自身の **ローカル Obsidian Vault** にも保存されます。
- **データ保持ポリシー**: デフォルトでは閲覧履歴は**無制限に保持**されます（自動削除なし）。設定画面の「閲覧履歴 保持ポリシー」から、保持期間（30日〜365日）および最大件数（1,000〜100,000件）を任意で設定できます。いずれかを設定すると、24時間ごとに自動パージが実行されます。
  - **自動削除の仕組み**: 保持期間を超えた非スター付きエントリが物理削除されます。総数が最大件数を超える場合は古い非スター付きエントリから追加削除されます。スター付きエントリは自動削除の対象外です。「今すぐ削除を実行」ボタンで手動パージも可能です。
  - **PII サニタイゼーション**: 取得されたページコンテンツは保存前に PII（個人情報）サニタイザーで処理されます。メールアドレス、クレジットカード番号、電話番号（日本・米国・中国・韓国）、マイナンバー、SSN（米国社会保障番号）などが自動的にマスクされます。
- **旧バージョンからの移行**: 旧バージョンからのデータ移行はOPFS上のSQLite DBに対して実行されます。移行完了後、旧ストレージのデータは削除されます。
- **いかなるデータも開発者のサーバーには保存されません。** 開発者はサーバーを運営していません。

#### 閲覧履歴アーカイブのデータフロー

`Dashboard → Archive` パネルの操作に関するデータの取り扱いは次の通りです。

- **書き出し**: アーカイブファイル（`yasumaro_archive_<日付>.db`）はユーザーの明示操作でのみ生成され、ブラウザのダウンロードフォルダに保存されます。**暗号化・署名のない平文の標準 SQLite ファイル**です。書き出し後の保管・移動・削除はユーザーの責任で管理してください。
- **本体からの削除**: フェーズ2の削除は、フェーズ1で書き出したファイルの内容と突合せてから実行され、フェーズ1以降に追加されたレコードは保護されます。
- **復元**: ユーザーが選択したアーカイブファイルを本体 SQLite DB にマージします（重複はスキップ）。ファイルの内容が外部へ送信されることはありません。
- **一時オープン**: 本体に取り込まずにアーカイブファイルを開いて検索・タイトル編集ができます。編集内容の書き戻し先は選択したアーカイブファイルのみで、本体 DB には影響しません。
- アーカイブに関する処理はすべて端末内で完結し、開発者のサーバーへの送信は一切ありません。

### データの使用方法
1. **ページ内容**: 要約を作成するために、ユーザーが選択した AI プロバイダー API（Google Gemini、OpenAI互換API等）に送信されます。送信先の AI プロバイダーは、ユーザーが設定画面で選択したものです。各プロバイダーのデータ利用ポリシーが適用されます。各プロバイダーのプライバシーポリシーをご確認ください。**ブラウザ内蔵 AI（Chrome の Gemini Nano / Edge の Phi-mini）を選択した場合は、推論がデバイス内で完結し、ページ内容はデバイス外へ送信されません。**
2. **閲覧履歴**: OPFS上のSQLite DBに保存され、拡張機能のダッシュボード（履歴タブ）で確認・管理できます。Obsidian 連携を有効にした場合（オプション）は、Obsidian Local REST API を通じて Obsidian Vault にもデータが送信されます。この場合、データの取り扱いは Obsidian およびそのプラグイン（Local REST API）のポリシーに依存します。
3. **設定**: Obsidian および AI プロバイダー API への接続に使用されます。

### プライベートページ保護機能

#### プライベートページ自動検出
本拡張機能は以下のHTTPヘッダーを分析し、プライベートページを自動的に検出します：
- `Cache-Control: private` ヘッダー
- `Cache-Control: no-store` + `Set-Cookie` ヘッダーの組み合わせ
- `Set-Cookie` + `Vary: Cookie` ヘッダーの組み合わせ
- `Authorization` ヘッダー

> [!NOTE]
> `Cache-Control: no-cache` は検出対象に含まれません。これはニュースサイトなどでもよく使用されるディレクティブであり、必ずしもプライベートなコンテンツを示すものではありません。

##### プライバシーステータスコード

プライベートページ検出時に割り当てられるステータスコードは以下の通りです：

| コード | 説明 | 検出対象 |
|------|------|----------|
| PSH-1001 | `Cache-Control: private` または `no-store` + `Set-Cookie` 検出 | HTTPレスポンスヘッダー |
| PSH-2001 | `Set-Cookie` + `Vary: Cookie` 検出 | HTTPレスポンスヘッダー |
| PSH-3001 | `Authorization` ヘッダー検出 | HTTPリクエストヘッダー |
| PSH-9001 | 不明な理由 | その他のプライベート判定 |

> [!NOTE]
> PSH-1001 は `Cache-Control: private` 単独、または `Cache-Control: no-store` と `Set-Cookie` の組み合わせを検出します。`no-store` 単独ではプライベート判定されません。

検出されたページは、以下の方法で保護されます：

1. **手動記録時**:
   - 確認ダイアログが表示され、以下の選択肢が提供されます
     - キャンセル
     - 今回のみ保存（強制保存）
     - ドメイン全体を許可して保存（ホワイトリスト追加）
     - このパスのみ許可して保存（パスホワイトリスト追加）

2. **自動記録時**:
   - プライベートページは「保留中のページ」として一時保存されます
   - 後からポップアップUIで一括処理が可能：
     - 選択したページを保存
     - 選択したドメインをホワイトリストに追加して保存
     - 選択したページを破棄
   - 保留中のページは24時間後に自動的に期限切れとなります

#### 保留ページデータ
プライベート判定されたページを一時保存するために、以下のデータがローカルストレージに保存されます：
- ページURL
- ページタイトル
- 検出理由（cache-control / set-cookie / authorization）
- 検出されたヘッダー値（1024文字まで）
- タイムスタンプ
- 有効期限（24時間後）

### マスターパスワード保護

設定のエクスポート/インポート時には、**マスターパスワード**でファイルを暗号化できます。

- **有効にする方法**: ダッシュボード → Privacy タブ → 「マスターパスワード保護を有効にする」をオンにして、パスワードを設定します
- **暗号化方式**: AES-GCM（業界標準）+ PBKDF2による鍵導出（100,000回反復）
- **適用範囲**: エクスポートされたJSONファイルに含まれるすべての設定（APIキーを含む）
  - **注意**: パスワードを忘れた場合、暗号化されたエクスポートファイルを復号することはできません

### ログエクスポートの改竄検知

ブラウジングログを JSON 形式でエクスポートすると、ファイルに **HMAC 署名** が付与されます。インポート時にこの署名が検証され、無署名または改竄されたファイルは取り込まれません。署名鍵はブラウザプロファイルごとにローカル生成され、外部に送信されません。

- **対象**: JSON 形式のログエクスポート/インポート
- **注意**: 旧バージョン（署名なし）でエクスポートしたログ JSON は再インポートできません。必要な場合は最新バージョンで再エクスポートしてください
- `.db` 形式のエクスポートは対象外です

#### プライバシー同意の仕組み

初回起動時にデータ収集への同意確認モーダルが表示されます。同意しない場合は制限モードで動作し、記録は行われません。3回連続で拒否すると、以降30日間はモーダルが表示されなくなります。30日経過後、再度同意確認が表示されます（GDPR 第7条「再同意取得」準拠）。

**同意の撤回**: 一度同意した後でも、いつでも同意を撤回できます。同意を撤回すると、確認ダイアログが表示されます。内容を確認すると、記録済みの閲覧履歴データ（SQLite）も完全に削除されることが分かります。この操作は取り消せないため、実行前に確認が求められます。

通常の使用（拡張機能内でのAPIキー保存）では、マスターパスワードとは別の自動暗号化機構が使われます。ユーザーの操作は不要です。

#### 自動暗号化機構の仕組みと限界

通常の使用では、APIキーは**自動的に暗号化されて保存**されます。マスターパスワードの設定は不要で、ユーザーの操作なくバックグラウンドでAES-GCMによる暗号化が適用されます。

  ただし、マスターパスワードが**未設定の場合**、暗号化キー自体は `chrome.storage.local` に平文で保持されます。Chrome 拡張機能のストレージは拡張機能ごとに分離されており、他の拡張機能から直接読み取ることはできませんが、この拡張機能内からはアクセス可能です。この状態では、暗号化は外部からの読み取りを防ぎますが、拡張機能自身の内部からのアクセスは防げません。

**マスターパスワードを設定すると、暗号化キー自体をマスターパスワードから導出できるようになります。その結果、APIキーの復号にはマスターパスワードの入力が必要になります。**

### v4.2.1 プライバシー保護機能（追加）

#### 自動コンテンツフェッチ（オプトイン方式）
v4.2.1以降、以下の機能が追加されました：

#### 遷移記録（オプトイン方式）
「リサーチ・セッション」パネルで「どのページから、どの検索語で、どのページへたどったか」を見せるために使う、任意で有効にできる機能です。**既定は無効**で、有効にする=settings画面で確認ダイアログに同意した場合のみです。

1. **保存する項目**（1件の記録につき2つ）:
   - `nav_source_url`: 同じタブで直前に開いていたページのURL。URLのフラグメント（`#` 以降）は取り除いて保存します
   - `search_query`: 流入元が検索エンジン（Google・Bing・DuckDuckGo・Yahoo! Japan・Yahoo!・Brave・Ecosia）の場合に限り、その検索語。个人信息（PII）マスクを通したうえで最大200文字に切ります

2. **除外ドメインの扱い**: 流入元がドメイン除外リスト（`isDomainAllowed` が偽）に一致する場合、URL全体ではなく**オリジンのみ**を保存します。除外したサイトの閲覧歴を、遷移記録経由で持ち出さないためです。

3. **保存先と配布先**: 値はブラウザ内の SQLite DB にのみ保存されます。**AIプロバイダーへの送信内容にも、Obsidian への Markdown にも、CSV / JSON エクスポートにも含まれません。**ただし、あなた自身が**暗号化されたcombined backup**をエクスポートした場合、そのバックアップは SQLite DB を丸ごと含むため、これらの値も一緒にバックアップファイルへ入ります。バックアップは通常の設定エクスポートとは別物で、`privacy_consent`（同意状態）は復元対象の許可リストに含まれないため、別端末で復元しても遷移記録は自動的に有効になりません。

4. **同意の管理**:
   - 有効化時: 設定画面の Privacy タブで確認ダイアログを出し、同意したときだけ有効になります
   - 無効化時: 以後の記録には流入元・検索語が入りません。追跡中のタブ状態も破棄されます
   - プライバシー同意そのものを撤回した場合、本機能は自動的に無効になります
   - この同意記録は端末固有です。設定のエクスポートにもバックアップの復元にも含まれないため、別の端末で復元しても同意は引き継がれません

5. **保存済みの値**: 記録済みの値は、履歴を削除すると同時に消えます。保持ポリシーによる自動削除でも取り除かれます。

1. **"Record without AI" ボタン**: AI処理をスキップして直接Obsidianに記録
   - ダッシュボードからページ内容なしで記録を試みる場合に使用可能
   - AIプロバイダーへのデータ送信を完全に回避
   - すべてのプライバシーチェック（プライベートページ検出）は適用されます

2. **自動コンテンツフェッチ（デフォルトで無効）**:
   - マニュアル記録時にページ内容が空の場合、バックグラウンドタブでページを開いてコンテンツを取得
   - この機能は**デフォルトで無効化**されています（明示的な同意が必要）
   - 有効化するには:
     - ダッシュボード → Privacy タブ → 「自動コンテンツフェッチ」をオンにします
   - 有効化時の動作:
     - バックグラウンドタブでページを読み込み、テキストを抽出（最大10,000文字）
     - 抽出したコンテンツはAI要約に使用される可能性があります
     - タブは処理完了後に自動的に閉じられます
   - **重要**: 無効化（デフォルト）設定では、バックグラウンドタブは開かれません

3. **URL ログの記録**:
   - 記録操作のログにURLが含まれる場合があります（最大7日間保存）
   - URLはドメイン名のみが記録され（パス情報は除外）、完全なURLは記録されません
   - これらのログはデバッグ目的のみであり、ダッシュボードから確認や削除が可能です

### 第三者サービス
本拡張機能は、以下の第三者サービスと通信します：

1. **AI プロバイダー (ユーザーが選択)**: ページ内容の要約を生成するため。以下のいずれかが使用されます:
   - **Google Gemini API**: データはGoogleのプライバシーポリシーに従って処理されます。
   - **OpenAI互換API** (Groq, OpenAI, Anthropic等): データは各プロバイダーのポリシーに従って処理されます。
   - **ローカルLLM** (Ollama, LM Studio等): データはユーザーのローカル環境内でのみ処理されます。
2. **ユーザーのローカル Obsidian**: デイリーノートに履歴を保存するため。これはユーザー自身のローカルサーバーです。
3. **Tranco リスト (信頼できるドメインリスト)**: ドメイン信頼性判定のため。以下の動作を行います:
   - **Tranco Top 1000 リストの自動更新**: 拡張機能は定期的に Tranco Top 1000 ドメインリストを自動的に更新します
   - **データ取得元**: Tranco プロジェクトの公開 API (https://tranco-list.eu/) からドメインリストを取得します
   - **取得するデータ**: ドメイン名のみ（例: google.com, amazon.co.jp）。個人を特定できる情報は含まれません
   - **保存場所**: 取得したドメインリストは Chrome ローカルストレージに保存されます
   - **使用目的**: 訪問したドメインが信頼できるかどうかを判定するため（Tranco Top 1000 に含まれるドメインは信頼できるとみなされます）
   - **プライバシーへの影響**: ドメイン名のみを取得・保存するため、ユーザーの閲覧履歴や個人を特定できる情報は Tranco に送信されません

### 拡張機能の権限について
本拡張機能は以下の権限を必要とします：

1. **コンテンツスクリプトによるページアクセス権限**:
   - `content_scripts` で指定されたWebサイトのコンテンツを抽出するために必要です
   - ページのタイトル、URL、本文テキストを取得します
   - このデータはAI要約生成とObsidianへの保存にのみ使用されます
   - ページ本文をローカルに保存するかは設定で切り替えられます（デフォルト: オフ）。ダッシュボードの「設定 → コンテンツ保持設定」から変更できます
   - 閲覧履歴は標準SQLiteファイル（アーカイブ）として端末外へ書き出せます。アーカイブファイルは暗号化・署名のない平文で、保管と削除はユーザーが管理します

2. **Webリクエスト監視権限 (`webRequest`)**:
   - HTTPレスポンスヘッダーを解析し、プライベートページを自動検出するために必要です
   - `Cache-Control: no-store`、`Set-Cookie`、`Authorization` ヘッダーを検出します
   - プライベートページ（銀行、メール等）での誤った記録を防ぐために使用されます
   - **重要**: リクエストの内容は変更・ブロックしません（読み取りのみ）

3. **ネットワーク接続権限 (`connect-src`)**:
   - Obsidian Local REST API（ローカルサーバー）への接続
   - ユーザーが選択したAIプロバイダーAPIへの接続（Google Gemini API、OpenAI互換API等）
   - ユーザーが指定するカスタムAPIエンドポイントへの接続

4. **宣言的ネットワークリクエスト権限 (`declarativeNetRequest`)**:
   - ユーザーが設定したOllamaサーバーへのリクエストからのみ、`Origin` ヘッダーを削除するために使用されます
   - Ollamaのデフォルト設定でのCORS拒否を回避するためのもので、対象はOllamaのURLホストに限定されます
   - リクエスト内容の閲覧・送信先の変更は行いません（ヘッダー削除のみ）

**重要**: すべてのデータ処理はユーザーの明示的な設定に基づいて行われます。開発者はいかなるデータも収集しません。

---

## English

### Overview
Yasumaro ("the Extension") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

### Data Collection
The Extension collects the following data **locally on your device**:
- Browsing history data (URLs, titles, duration, scroll depth, content)
- Navigation trail data (previous page URL, search-engine search terms) — **only when you opt in**
- Configuration data (API keys, connection settings)

### Storage
- Browsing history data is stored in **SQLite DB on OPFS (Origin Private File System)** on your device.
- All configuration data is stored in **Chrome's local storage** on your device.
- Browsing history entries are also saved to **your local Obsidian vault**.
- **Data Retention Policy**: By default, browsing history is retained **indefinitely** (no automatic deletion). You can optionally configure a retention period (30–365 days) and/or a maximum record count (1,000–100,000) in the settings under "History Retention Policy". When either setting is configured, an automatic purge runs every 24 hours.
  - **Automatic Deletion Mechanism**: Non-starred entries older than the configured retention period are physically deleted. If the total count exceeds the configured maximum, the oldest non-starred entries are additionally removed. Starred entries are exempt from automatic deletion. A "Purge now" button is also available for immediate manual purge.
  - **PII Sanitization**: Fetched page content is processed through a PII (Personally Identifiable Information) sanitizer before storage. Email addresses, credit card numbers, phone numbers (Japan, US, China, Korea), My Number (Japan), SSN (US Social Security Numbers), and other PII patterns are automatically masked.
- **Migration from older versions**: Data migration from older versions is performed against the SQLite DB on OPFS. After migration is complete, data in the old storage is deleted.
- **No data is stored on our servers.**

#### History Archive Data Flow

Data handling for the `Dashboard → Archive` panel:

- **Export**: An archive file (`yasumaro_archive_<date>.db`) is created only by an explicit user action and saved to the browser's download folder. It is a **plaintext standard SQLite file with no encryption or signing**. Storage, moving, and deletion of the file after export are the user's responsibility.
- **Deletion from the main database**: The phase-2 deletion is cross-checked against the file exported in phase 1, and records added after phase 1 are protected.
- **Restore**: The archive file selected by the user is merged into the main SQLite DB (duplicates skipped). The file's contents are not sent anywhere.
- **Open temporarily**: You can open an archive file without importing it, to search and edit titles. Edits are written back only to the selected archive file and do not affect the main DB.
- All archive processing is completed on-device; nothing is sent to our servers.

### How Data Is Used
1. **Page content**: Sent to the AI provider API selected by the user (Google Gemini, OpenAI-compatible APIs, etc.) to generate summaries. The AI provider is the one you choose in the settings; their data usage policy applies. Please review the privacy policy of your chosen provider. **If you select browser Built-in AI (Chrome's Gemini Nano / Edge's Phi-mini), inference runs on-device and page content is not sent outside the device.**
2. **Browsing history**: Stored in the SQLite DB on OPFS and can be viewed and managed in the extension's Dashboard (SQLite History panel). If you enable Obsidian integration (optional), data is also sent to your Obsidian vault via the Obsidian Local REST API. In that case, data handling is subject to the policies of Obsidian and the Local REST API plugin.
3. **Settings**: Used to connect to Obsidian and the AI provider API.

### Master Password Protection

You can encrypt exported settings files with a **master password**.

- **How to enable**: Dashboard → Privacy tab → Enable "Master Password Protection" and set a password
- **Encryption**: AES-GCM (industry standard) + PBKDF2 key derivation (100,000 iterations)
- **Scope**: All settings in the exported JSON file, including API keys
- **Note**: If you forget your password, encrypted export files cannot be decrypted

### Log Export Tamper Detection

When you export browsing logs as JSON, the file is **HMAC-signed**. On import the signature is verified, and unsigned or tampered files are rejected. The signing key is generated locally per browser profile and is never transmitted.

- **Scope**: JSON-format log export/import
- **Note**: Log JSON files exported by an older (unsigned) version cannot be re-imported. Re-export them from the latest version if needed
- `.db`-format exports are not affected

#### Privacy Consent Mechanism

On first launch, a consent prompt appears for data collection. If you decline, the extension operates in restricted mode and no recording takes place. After 3 consecutive declines, the prompt is suppressed for 30 days. After 30 days, the consent prompt reappears (GDPR Article 7 "Right to Re-consent" compliance).

**Withdrawing Consent**: You may withdraw your consent at any time. Withdrawing consent shows a confirmation dialog that makes clear this will also permanently delete your recorded browsing history (SQLite). Because this action cannot be undone, confirmation is required before it is executed.

For regular use (storing API keys within the extension), a separate auto-encryption mechanism is used that requires no user action.

#### Auto-Encryption Mechanism: Scope and Limitations

Under normal use, API keys are **automatically encrypted** before being stored. No master password is required; AES-GCM encryption is applied in the background without any user action.

However, when no master password is set, the encryption key itself is stored in plaintext within `chrome.storage.local`. While Chrome extension storage is scoped to the extension and cannot be read directly by other extensions, it is accessible from within this extension. In this state, encryption prevents external read access, but does not prevent access from within the extension itself.

**Setting a master password changes this behavior: the encryption key is derived from the master password via PBKDF2, providing protection beyond the extension's own storage boundary.**

### v4.2.1 Privacy Protections (Updated)

#### Automatic Content Fetching (Opt-In)
v4.2.1 introduces the following privacy features:

#### Navigation Trail (Opt-In)
An optional feature behind the "Research Sessions" panel, which shows which page you came from, which search term you used, and which page you ended on. **Off by default**; turning it on requires confirming a dialog in the settings panel.

1. **What is stored** (two values per record):
   - `nav_source_url`: the URL of the page previously open in the same tab, with the fragment (everything from `#`) removed
   - `search_query`: only when the referrer is a search engine (Google, Bing, DuckDuckGo, Yahoo! Japan, Yahoo!, Brave, Ecosia) — the search term, passed through the PII sanitizer and truncated to 200 characters

2. **Excluded domains**: when the referrer matches the domain exclusion list (`isDomainAllowed` returns false), only the **origin** is stored, not the full URL. Otherwise the trail would carry out the very history the exclusion removed.

3. **Where it lives**: the values are stored only in the on-device SQLite database. They are **never included in what is sent to AI providers, in the Markdown written to Obsidian, or in CSV / JSON exports.** One boundary does carry them: the **encrypted combined backup** you export yourself contains the whole SQLite database, so the values travel inside that backup file. A backup is separate from the normal settings export, and the consent state (`privacy_consent`) is not in the restore allowlist — so restoring onto another device does not turn the trail on there.

4. **Managing consent**:
   - To enable: a confirmation dialog appears in the settings Privacy tab; the feature turns on only if you agree
   - To disable: later records carry no referrer and no search term, and the tracked tab state is discarded
   - Withdrawing privacy consent itself turns this feature off automatically
   - The consent record is device-local. It is excluded from settings export and from backup restore, so restoring onto another device does not carry the authorization over

5. **Already-stored values**: they disappear when the history is deleted, and are also removed by the automatic retention purge.

1. **"Record without AI" Button**: Skip AI processing and record directly to Obsidian
   - Available when attempting manual recording without page content from the dashboard
   - Completely bypasses AI provider data transmission
   - All privacy checks (private page detection) still apply

2. **Automatic Content Fetching (Disabled by Default)**:
   - When page content is empty during manual recording, a background tab opens to fetch content
   - This feature is **disabled by default** (requires explicit opt-in)
   - To enable:
     - Dashboard → Privacy tab → Enable "Auto Content Fetch"
   - Behavior when enabled:
     - Background tab loads the page and extracts text (up to 10,000 characters)
     - Extracted content may be used for AI summarization
     - Tab automatically closes after processing
   - **Important**: With disabled (default) setting, no background tabs are opened

3. **URL Logging**:
   - Recording operation logs may contain URLs (retained for up to 7 days)
   - URLs are logged as domain names only (path information excluded); full URLs are not recorded
   - These logs are for debugging purposes only and can be viewed or deleted from the dashboard

### Third-Party Services
1. **AI Provider (User-Selected)**: Used to generate summaries. The following options are available:
   - **Google Gemini API**: Data is processed according to Google's privacy policy.
   - **OpenAI-Compatible APIs** (Groq, OpenAI, Anthropic, etc.): Data is processed according to each provider's policy.
   - **Local LLMs** (Ollama, LM Studio, etc.): Data is processed entirely within your local environment.
2. **Your Local Obsidian Instance**: Used to save history. This is your own local server.
3. **Tranco List (Trusted Domain List)**: Used for domain trust verification. The following operations are performed:
   - **Automatic Tranco Top 1000 List Updates**: The extension periodically automatically updates the Tranco Top 1000 domain list
   - **Data Source**: Domain list is retrieved from the Tranco project's public API (https://tranco-list.eu/)
   - **Data Retrieved**: Domain names only (e.g., google.com, amazon.co.jp). No personally identifiable information is included
   - **Storage Location**: Retrieved domain lists are stored in Chrome local storage
   - **Purpose**: To determine whether visited domains are trustworthy (domains included in Tranco Top 1000 are considered trusted)
   - **Privacy Impact**: Since only domain names are retrieved and stored, your browsing history or personally identifiable information is not sent to Tranco
4. **GitHub (Bug Reporting, User-Initiated Only)**: The Diagnostics panel includes a "Report a Bug" button. This sends no data automatically:
   - **Trigger**: Only activated when you click the button and then confirm the preview
   - **Data Included**: Extension version, browser user agent, debug mode flag, SQLite initialization status, AI provider type name only, Obsidian connection protocol/port only, and recent error code names with counts
   - **Data Excluded**: API keys, base URLs, your Obsidian daily note path, and log message contents are never included
   - **Confirmation Step**: You can review the exact text before a new GitHub tab opens; closing the preview sends nothing

### Private Page Protection

#### Automatic Private Page Detection
The extension analyzes the following HTTP headers to automatically detect private pages:
- `Cache-Control: private` header
- `Cache-Control: no-store` + `Set-Cookie` header combination
- `Set-Cookie` + `Vary: Cookie` header combination
- `Authorization` header

> [!NOTE]
> `Cache-Control: no-cache` is not included in the detection criteria. This directive is commonly used on news sites and does not necessarily indicate private content.

##### Privacy Status Codes

The following status codes are assigned when private pages are detected:

| Code | Description | Detection Target |
|------|-------------|------------------|
| PSH-1001 | `Cache-Control: private` or `no-store` + `Set-Cookie` detected | HTTP response header |
| PSH-2001 | `Set-Cookie` + `Vary: Cookie` detected | HTTP response header |
| PSH-3001 | `Authorization` header detected | HTTP request header |
| PSH-9001 | Unknown reason | Other private detection |

> [!NOTE]
> PSH-1001 detects `Cache-Control: private` standalone, or `Cache-Control: no-store` combined with `Set-Cookie`. `no-store` alone does not trigger private detection.

Detected pages are protected as follows:

1. **Manual Recording**:
   - A confirmation dialog is displayed with the following options:
     - Cancel
     - Save once (force save)
     - Save and allow entire domain (add to whitelist)
     - Save and allow this path only (add path to whitelist)

2. **Auto Recording**:
   - Private pages are temporarily saved as "Pending Pages"
   - Later you can batch-process from the popup UI:
     - Save selected pages
     - Add selected domains to whitelist and save
     - Discard selected pages
   - Pending pages automatically expire after 24 hours

#### Pending Page Data
The following data is temporarily stored locally for pages detected as private:
- Page URL
- Page title
- Detection reason (cache-control / set-cookie / authorization)
- Detected header value (up to 1024 characters)
- Timestamp
- Expiration time (24 hours later)

### Extension Permissions
This extension requires the following permissions:

1. **Content Script Page Access**:
   - Required to extract content from visited pages as specified in `content_scripts`
   - Collects page titles, URLs, and body text
   - Data is used solely for AI summarization and saving to Obsidian
   - Whether page body text is stored locally is configurable in the settings (default: off). Change it under Dashboard → Settings → Content Retention Settings
   - Browsing history can be exported outside the device as a standard SQLite file (archive). Archive files are plaintext (no encryption or signing); their storage and deletion are managed by the user

2. **Web Request Monitoring (`webRequest`)**:
   - Required to analyze HTTP response headers for automatic private page detection
   - Detects `Cache-Control: no-store`, `Set-Cookie`, and `Authorization` headers
   - Used to prevent accidental recording of private pages (banking, email, etc.)
   - **Important**: Does not modify or block requests (read-only)

3. **Network Connection Permissions (`connect-src`)**:
   - Connection to Obsidian Local REST API (local server)
   - Connection to user-selected AI provider APIs (Google Gemini, OpenAI-compatible APIs, etc.)
   - Connection to user-specified custom API endpoints

4. **Declarative Net Request Permission (`declarativeNetRequest`)**:
   - Used only to remove the `Origin` header from requests to the Ollama server the user has configured
   - Works around Ollama's default CORS rejection; scoped strictly to the configured Ollama host
   - Does not inspect request content or change the destination (header removal only)

**Important**: All data processing is based on your explicit configuration. The developer does not collect any data.

---

## 権利 / Rights
すべてのデータはローカルに保存されており、拡張機能のアンインストールやObsidian内のノート削除によっていつでも破棄できます。

### データ削除権 / Right to Erasure (GDPR Art. 17 / CCPA)

ダッシュボード → プライバシー設定 → 「データ管理」セクション → 「すべてのデータを削除」ボタン

Dashboard → Privacy Settings → "Data Management" section → "Delete All Data" button

個別の閲覧履歴エントリは物理的に削除されます（GDPR Art.17 対応）。WAL チェックポイントにより、削除後にディスク領域も確実に解放されます。

Individual browsing history entries are physically deleted from the database (GDPR Art.17 compliance). WAL checkpoint ensures disk space is released after deletion.

All data is stored locally and can be deleted by uninstalling the extension or manually deleting notes in Obsidian.
