Cookie Panda privacy policy
In short: Cookie Panda has no server and sends your data nowhere. It never leaves your computer except in a file or clipboard text that you create and move yourself.
What the extension handles
When you press Export, Cookie Panda reads the sites of your open tabs (all of them, or only the current tab's site, as you choose), and then you pick which sites go into the file. For those sites it reads:
- cookies, including sign-in and session cookies;
- the sites' localStorage, sessionStorage and IndexedDB;
-
the addresses of your open tabs, to find the sites. Only each site's origin (for example
https://example.com) goes into the file, never a page address or title.
The file also records when it was made, the browser's user agent, the Chrome version and the extension version, so another copy of Cookie Panda can check it can read the file.
When you press Import, it writes the contents of a Cookie Panda file into the browser you are using.
This data is sign-in information: anyone who holds it can use your accounts. That is why the extension treats it as a secret.
Where the data goes
- Nowhere over the network. The extension contains no analytics, no tracking and no server, and it never sends your data to the developer or to anyone else. It does make the chosen sites' own pages load in your browser (see "Tabs" below), just as if you opened them.
- Into a file or the clipboard, only when you ask. The file is encrypted by default (AES-256-GCM, key derived from your password with PBKDF2-SHA256, 600,000 iterations). You can turn encryption off; the extension then shows a warning, because a plain file can be read by anyone who gets it.
- Your password is never stored. It is kept only in the open panel's memory while you use it, and is gone when the panel is reset or closed.
What the extension keeps
- While an export or import runs, a progress record is kept in Chrome's session storage, which lives in memory and is cleared when the browser closes. It holds the site addresses, counts and the tabs being used, but no cookies or site data. When you press a keyboard shortcut (quick export, or open Profiles) or pick an item in the right-click menu, the window number, the time and which item you chose (this site, all sites, import, open Profiles, or the id of the profile to switch to) are kept there for a few seconds, until the panel picks the request up.
- Your choices in the panel (language, which data types to include, whether to encrypt, and similar options such as fast import, skipping Google data or the last open tab) and the named site lists you save as templates are kept in the extension's own local storage. A template holds site addresses only. If you use Profiles, the colour you give each profile and the sort order of the list are kept there too (a profile's internal id and a colour number, no name), and Chrome's extension storage keeps the ids of the profiles listed in the right-click menu so the menu can be cleaned up. None of this contains cookies or site data, and you can delete a template in the panel at any time.
- While the panel stays open after an export, it keeps the finished file in memory so you can save or copy it again (unencrypted if you turned encryption off). Closing or resetting the panel drops it.
- While the panel stays open after an import, it keeps in memory a copy of the cookies and localStorage that the import replaced on this browser, so that you can undo the import. This copy is never written to disk or sent anywhere; closing or resetting the panel drops it.
- Profiles, only if you use them. When you save a profile, the extension keeps a snapshot of this browser's cookies and the data of the sites open in tabs (Google account sites excluded, unless you turn on "Profiles include the Google sign-in") and the list of open tab addresses, in the extension's own storage on this computer (IndexedDB). The snapshot is encrypted with AES-256-GCM under a key protected by your vault password (PBKDF2-SHA256, 600,000 iterations). Profile names, save times and counts are stored unencrypted. The password is never stored. After you unlock the vault, its key is kept in Chrome's session storage, which lives in memory and is cleared when the browser closes; "Lock" clears it sooner. A deleted profile is kept in the open panel's memory only, so you can undo the delete. Switching to another profile first saves the current state into the profile in use, then closes the web tabs and clears this browser's browsing data (see "Browsing data" below) before restoring the other profile. Cookies of every site are saved first, but site data (localStorage, IndexedDB and so on) only for the sites open in tabs: the stored data of other sites is cleared and cannot be brought back. While a switch runs, a record of which profiles it goes between and how far it got (no cookies or site data) is kept in the same storage, so an interrupted switch can be continued or cancelled. "View" decrypts a profile in the panel's memory only, to list its sites and counts. You can save a profile to a .cpanda file (encrypted by default with the password you type, like an export; it holds no list of tabs) or import a .cpanda file as a new profile, which is then stored encrypted in the vault like any other. Once you unlock the vault, the names of your profiles are shown in a "Switch to profile" item of Chrome's right-click menu; locking the vault in the panel removes them, and after Chrome restarts they are removed the next time the panel opens. Picking one while the vault is locked only asks you to unlock it. While a switch runs, a short lock record (a random token, the time and the job number) is kept in session storage so two windows cannot switch at once. Nothing of this is sent anywhere.
- Before an import, the panel reads this browser's cookies for the sites in the file to show which ones are new, changed or identical. The comparison happens in the panel's memory and is not kept.
Why it asks for its permissions
- Read and change your data on all websites, cookies: to read and write the cookies and storage of the sites you export or import, which can be any site.
-
Tabs: to find the sites open in your browser. Export reloads a tab that
Chrome has unloaded, so its storage can be read. Import opens background tabs of the
imported sites (site storage can only be written from that site's page), loading the
site's
robots.txtor home page, and closes them afterwards, except a tab kept open for a site's sessionStorage. Saving a profile records the addresses of the open tabs, encrypted, inside that profile; switching profiles closes the web tabs and reopens the other profile's tabs. - Browsing data: only when you switch profiles, after the current state was saved encrypted in the vault. It clears websites' local storage, IndexedDB, Cache Storage, service workers, file systems and the HTTP cache, including the data of installed web apps (Google sites included), so the next profile starts clean; cookies are removed separately, keeping your Google account sign-in cookies unless you turned on "Profiles include the Google sign-in". It never clears the extension's own data, passwords, history, downloads or form data.
- Scripting: to run the extension's own script inside those pages.
- Debugger: only as a fallback, for tabs Chrome has frozen (which it wakes up) or pages that block injected scripts. It runs the extension's own bundled script, only on the sites being exported or imported, and detaches when done (it also detaches any of its own sessions left over after a restart). Chrome may show a "being debugged" bar for a few seconds.
- Storage, side panel: the progress record and the unlocked vault key above, and the panel itself.
- Context menus: to add "Export this site", "Export all sites", "Import a .cpanda file" and "Switch to profile" (listing your profile names once the vault has been unlocked) to the right-click menu. They read nothing from the page.
Sharing and selling
The developer does not receive your data, so it is never sold, shared, used for advertising, or used for anything other than copying your sign-in state where you choose.
Your control
Nothing happens until you press Export, Import or a profile button. "Delete every profile" removes all saved profiles. Uninstalling the extension removes its settings and saved profiles. Files you exported remain wherever you saved them; delete them when you no longer need them.
Changes and contact
If this policy changes, the date above will change with it. Questions: nguyentuan3691@gmail.com.