Privacy Notice

Last updated: June 22, 2026 · Version 2026.06.22

This Privacy Notice explains how Praxis LLC ("Praxis", "we", "us") collects, uses, discloses and protects personal data in connection with the Data Crumbs browser extension, the website at datacrumbs.store, and the Data Crumbs Pro subscription (collectively, the "Service"). Praxis LLC is the data controller (and "business" under the CCPA) for the personal data described here, except where Paddle.com is identified as the controller for payment data.

1. Summary (TL;DR)

2. What stays on your device (always)

Scans, privacy scores, per-site summaries, your settings (including Sensitive Site Protection), your silenced sites list and your scan history (capped at the most recent 100 entries) are stored only in your browser's local storage. They are not transmitted to us.

Sensitive Site Protection. By default, Data Crumbs does not scan pages it classifies as sensitive (banking, healthcare, government identity, email inboxes, password managers, insurance, tax, payment, billing, checkout or account pages). The scanner only inspects cookies, local/session storage keys, tracker domains, request metadata and known script indicators. It does not read, store, summarize or transmit page content, form values, passwords, emails, messages, financial balances, health information or account details.

3. Personal data we collect

CategoryExamplesPurposeLegal basis (GDPR)Source
Account dataemail, hashed password, account creation dateauthenticate you, contact you about the Service, security and abuse preventionContract performance; legitimate interests (security)You
Consent recordterms version accepted, timestampprove acceptance of these Terms / this NoticeLegal obligation; legitimate interests (evidence of consent)You
Usage counters (Pro)event type (scan / cleanse / block), domain acted on, timestampgenerate your weekly footprint report; measure Service usageContract performanceExtension
Billing referencePaddle customer ID, subscription ID, plan, status, renewal dateprovision and manage your subscriptionContract performancePaddle
Support dataemail content, attachments you sendrespond to support requestsLegitimate interestsYou
Server logstruncated IP address, user agent, request path, timestamp, error codesoperate and secure the Service, troubleshoot, detect abuseLegitimate interests (security and integrity)Automatic

We do not knowingly collect special-category data (such as health, biometric, racial, religious, sexual-orientation or precise geolocation data) and we do not knowingly collect personal data from children under 13 (or the applicable age of digital consent). If you believe a child has provided us personal data, email privacy@datacrumbs.store and we will delete it.

4. Payments — Paddle is the Merchant of Record

Payments are processed by Paddle.com Market Limited and its affiliates ("Paddle"), which is the Merchant of Record for the transaction. Paddle collects your billing name, billing address, payment instrument data, tax identifiers where required and IP address directly from you, and is the data controller for that payment data. Praxis receives only the billing reference data listed in Section 3. See Paddle's privacy notice at paddle.com/legal/privacy.

5. How we use personal data

We do not use your personal data for advertising, profiling that produces legal or similarly significant effects, or automated decision-making.

6. Who we share data with

We do not sell or "share" your personal data within the meaning of the CCPA/CPRA, and we do not engage in cross-context behavioural advertising.

7. International transfers

Our infrastructure is located in the United States and the European Union. Where personal data is transferred from the United Kingdom or the European Economic Area to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses and equivalent UK safeguards, and implement supplementary measures as appropriate.

8. Retention

We keep account data while your account is active and delete or irreversibly anonymise it within 90 days of account deletion, except where we are required to keep it for longer to comply with a legal obligation (for example tax records kept by Paddle for the statutory period). Usage counter events older than 12 months are aggregated and de-identified. Server logs are kept for up to 30 days for security and troubleshooting unless a longer period is required for incident investigation. Consent records are kept for as long as the related account is active, plus a reasonable period to evidence consent.

9. Security

We use appropriate technical and organisational measures including TLS in transit, encryption at rest of the account database, role-based access control on the principle of least privilege, hashed passwords, audit logging and regular dependency updates. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

10. Cookies and similar technologies

Our website uses only strictly-necessary cookies for sign-in and session management. We do not use analytics, advertising or social-tracking cookies on the website or in the extension. The extension itself does not set cookies.

11. Your rights

Depending on where you live you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; receive a portable copy of your data; withdraw consent at any time (without affecting prior lawful processing); and lodge a complaint with your local supervisory authority. We will respond within the period required by law (one month under GDPR, 45 days under CCPA, extendable as permitted).

California (CCPA/CPRA). California residents have the right to know, delete, correct and to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information.

EEA / UK (GDPR). You can object to processing based on legitimate interests on grounds relating to your particular situation; we will stop unless we have compelling legitimate grounds that override your interests, rights and freedoms.

To exercise these rights, email privacy@datacrumbs.storefrom the email associated with your account. We may need to verify your identity before responding.

12. Do Not Track & Global Privacy Control

Because we do not engage in cross-site tracking, "Do Not Track" and "Global Privacy Control" signals do not change our practices, but we honour them as a matter of policy.

13. Changes to this Notice

We may update this Notice from time to time. Material changes will be notified by email or in-product notice at least 14 days before they take effect; non-material changes take effect when posted. The "Last updated" date and version above always reflects the current version.

14. Contact

Praxis LLC — Privacy contact: privacy@datacrumbs.store
Legal notices: legal@datacrumbs.store
EEA/UK representative requests: privacy@datacrumbs.store