Français

Privacy policy

Effective 2026-09-29. Draft awaiting the publisher's approval (OA-07, OA-B2-4). Items marked [PO decision] await the publisher's approval.

In short

  • Our extensions do their work on your device. The tables, snippets, PDFs and images, blocked sites, design tokens, watched pages, highlights and notes, technology scans, recordings and translated pages you work with are processed in your browser and are not sent to us. On the sites where you turn Catchword's typed shortcuts on, this includes the last characters you type in text fields, which are processed on your device only.

  • There is no account to create, no advertising, and no analytics on our website or in our extensions.

  • If you buy Pro, Lemon Squeezy handles the payment. To check your license, our license service keeps a small record that does not contain your name or e-mail address.

  • We do not sell or share personal data.

Who is responsible

RISEVA, 33 boulevard Mendès France, 77600 Bussy-Saint-Georges, France ("we") publishes the extensions Gridlift, Bollard, Catchword, Calque, Tidemark, Bonefolder, Cartouche, Assay, Pantograph and Diglot and the website https://burin.riseva.fr. We are the controller of the personal data we process ourselves, described here: license records, support e-mails and website logs. The content you work with in our extensions — for example your snippets, highlights and recordings, or the pages you scan or translate — stays on your device unless you send it to us yourself (for example in a support e-mail): we never receive it, we never have access to it, and you decide how it is used. [PO decision — wording for the lawyer's review, compliance check G-3] Contact: contact@riseva.fr.

What applies to all our extensions

Stored on your device only

Your settings, a random installation identifier created when you install an extension, and — if you use Pro — your license key and the signed license token our service returns. They stay in the extension's storage in your browser until you remove them (Settings → Privacy → Reset) or uninstall the extension. If we publish the final version of a product that no longer checks licenses (terms of use and sale, section 7), that version deletes the stored license key and token, and any usage statistics not yet sent, when it first runs.

License service

This applies only if you use Pro. When you activate or remove a license, and about once a day while a license key is saved in the extension and you are online, the extension sends our license service: the product name, your license key and the installation identifier. Like any internet request, this also reveals your IP address to our servers. If a check cannot reach our service, for example while you are offline, Pro keeps working for up to 30 days after the last successful check; after that, it pauses until the next successful check.

What we keep:

  • a keyed hash of your license key and its last 4 characters (to show you which key is active);

  • a keyed hash of the installation identifier;

  • the payment provider's order, product, variant (one-time or monthly offer) and license identifiers, the status of your license and the related dates;

  • if you subscribe monthly: the provider's subscription identifier (with its order, product and variant identifiers), the subscription's status (for example active, cancelled, past due, expired) and its renewal and end dates, so that Pro stays on while the subscription is paid and stops when it ends.

We do not keep your name, e-mail address, billing address or payment details, and we do not keep your IP address: it is used only for rate limiting, as a keyed hash that is deleted within a day.

Why: to provide the Pro features you paid for and to prevent abuse of license keys. Legal basis: performance of our contract with you; our legitimate interest in preventing fraud.

Purchases

Pro is sold by Lemon Squeezy (Lemon Squeezy LLC), acting as merchant of record: it collects your name, e-mail, billing address and payment details, handles the taxes included in the price and sends your license key. It does so as an independent controller under its own privacy policy. When you start a purchase from an extension, the checkout link includes the product name and the installation identifier so the purchase can be linked to your browser.

Lemon Squeezy notifies our license service when an order, a subscription or a license changes (for example a renewal, a cancellation or a refund). These notifications contain customer details; we keep only the status described above and discard the rest. Cancelling a subscription, changing its payment method and invoices happen in Lemon Squeezy's customer portal, under its privacy policy.

Support

If you write to us, we use your message and e-mail address to answer. We delete support e-mails 24 months after the conversation ends. Legal basis: our legitimate interest in answering you, or our contract with you when the request is about a purchase.

Usage statistics

The current versions collect no usage statistics. If a future version offers them, they will stay off unless you turn them on, will contain only feature counts and error codes — never page addresses, page content or anything you type — and this policy will be updated first. Legal basis if introduced: your consent, which you can withdraw at any time in Settings.

When you uninstall

Chrome opens our goodbye page. Its address contains the product name and version, nothing else.

Permissions

Each product page lists the Chrome permissions the extension uses and why, in plain language. None of our extensions asks for access to all your websites at install. Some ask Chrome for access to a site, or to all sites, only when you turn on a feature that needs it; each product's section below says when.

Gridlift

Gridlift reads the current page only when you click its icon (Chrome's "activeTab"). It finds the tables on that page, shows a preview and exports the table you choose to your clipboard or to a file. When a table cell has no text, Gridlift uses the value of a visible form field in it (never a password or hidden field) or an image's text description. It also reads the tab's address, in memory only, to recognize pages where Chrome does not allow extensions. Tables, page titles and addresses are processed in memory; Gridlift stores none of them and never sends them to us or to anyone else. Stored locally: export preferences and the daily counter of Pro trials.

Bollard

Bollard stores the sites you block or allow, your schedules, your current focus session and your settings in your browser. It asks Chrome for access to a site only when you add that site to your block list, so Chrome can block it; access to all sites is requested only if you turn on the Pro allow-list mode. It does not read the pages you visit or Chrome's history. When you open its popup, it reads the current tab's address to offer "Block this site", without storing it. When you open a page on a blocked site, Bollard reads its address to show the site name on the block page and to take you there after "Allow for 1 minute"; when blocking starts, it moves tabs already open on those sites to the block page. These addresses stay on your device and are not stored. To apply the wait before you can allow a site, it notes the time of your last visit to that site's block page, in memory until Chrome closes. The intention you type on the block page is checked and discarded. With Pro, weekly counts of blocked attempts per site are kept on your device for 8 weeks (in allow-list mode, this includes any site outside your allow list that you tried to open while blocking was on); you can turn them off and clear them.

Catchword

Catchword stores in your browser your snippets, folders and tags, how often you use each snippet (to list the most used first), daily totals of what it typed for you (never per site), the list of sites where you turned typed shortcuts on, your settings and up to five restore points (copies of your library saved before an import, a restore or an upgrade, as long as they fit in your browser's storage).

Typed shortcuts. Catchword has no access to any website when you install it. When you turn typed shortcuts on for a site, Catchword first explains what it does, then Chrome asks you to allow that site; the advanced "Everywhere" option, off unless you turn it on, has its own explanation and Chrome prompt. On the sites where you turn on typed shortcuts, Catchword checks the last characters you type in text fields (never more than your longest shortcut plus two) to spot your shortcuts, like ;thx, and replaces them with your snippet. These characters are processed in memory on your device and are never stored and never sent; between two keystrokes Catchword keeps only a count and a one-way fingerprint of them, to make sure you typed the shortcut yourself. Catchword skips the password, card and one-time-code fields and the sign-in and payment forms it can recognize, and never runs on the payment and sign-in sites on its built-in list (shown in Settings). You can pause a site, pause everywhere or remove a site at any time; removing a site, or resetting Catchword, gives Chrome's access back.

The palette. When you open the palette with its shortcut or the Catchword icon, Catchword looks at the current page only to find the text field you were typing in, and writes the snippet there. It also reads the tab's address, in memory only, to recognize the site, pages where Chrome does not allow extensions, and Google Docs; the address is never stored or sent.

With Pro, a snippet can include your clipboard's contents: Chrome asks for your permission the first time, and the clipboard is read only at the moment you insert that snippet. Values you type in fill-in forms are used for that insertion only, unless you save them as a preset. Backups are files you export yourself. Your snippets, what you type and the sites you turn on are never sent to us. The only request Catchword makes is the license check for Pro.

Calque

Calque reads the styles of the current page (colours, fonts, spacing, radii, shadows and the CSS variables it declares) only when you ask it to scan that page, after a click on its icon or on a site you allowed. It never keeps the page's text: it counts the characters of each text style inside the page and keeps only the counts. It never reads form-field values, images or cookies. It reads the tab's address, in memory only, to recognize pages where Chrome does not allow extensions. In the free version the result stays in memory until you close the panel. Names you give to tokens are kept per site, and with Pro the scan history (last 10) and site sets are kept with each page's address and title — all in your browser. Nothing about the pages you scan is sent to us.

Tidemark

Tidemark stores in your browser the pages you ask it to watch (address, title and the part of the page you picked), the latest text it saw on each (up to 50,000 characters), the history of changes (the last change in the free version, the last 30 with Pro) and the status of each check. To check a page, your browser requests it directly from that website at the interval you chose, only for sites you granted access to, and only while Chrome is running. These requests go to the website, not to us, and carry no cookies unless you turn on the Pro option "use my login cookies" for a page; Tidemark never reads or stores cookies. Access to a site is given back when you stop watching its last page. Change notifications are shown by Chrome on your device. When you open its popup, it reads the current tab's address and title to offer "Watch this page", and keeps them only if you save the page. While you pick part of a page, it follows the pointer and the ↑ ↓, Enter and Esc keys to highlight and choose an element, shows the text under the pointer, and keeps only a short preview of the part you choose; nothing else about the picking is recorded.

Bonefolder

Bonefolder opens the PDF and image files you choose in an extension tab and processes them in memory on your device. Files are never uploaded and never stored by the extension; they are cleared when you start a new job or close the tab.

  • Passwords. When a file is protected, the password you type is used in the tab to open that file. Passwords are then forgotten: they are never stored, logged, sent to us or saved in presets.

  • Hidden data and camera data. Bonefolder reads document properties, comment authors and similar hidden data, and the camera data of photos (camera model, date taken, GPS location), on your device only, to show them to you and to remove them when you ask. The camera data and location of photos are always removed before a photo goes into a PDF, including the extra images and video some phones store in the same file. None of this is sent to us.

  • What is stored on your device. Your settings and, if you use Pro, the presets you save. Presets contain tool settings only (numbering, watermark text, size and hidden-data options) — never documents, images or passwords. They stay in the extension's storage until you delete them or uninstall Bonefolder.

  • Where your files go. Only where you save them: your Downloads folder, or the file or folder you pick in Chrome's own window. Bonefolder keeps no access to that location after the save.

Cartouche

Cartouche reads a web page only when you use it there — a click on its icon, its keyboard shortcuts or "Highlight with Cartouche" in the right-click menu (Chrome's "activeTab") — or on sites where you turned on "Always show my highlights": Cartouche first tells you what it will do there, then Chrome asks for your permission for that site (or for every site, if you choose that in Settings). It does not change the words or the markup of the page: highlights are painted over the text, and the note box is a single isolated element that Cartouche adds to the page only while it is open.

When you highlight a passage, Cartouche stores in your browser the passage itself, up to 32 characters of text around it and its position in the page (so it can find it again), your note, tags, colour and collection, and the page's address, title and site name. The address is kept without the part after "?", which can contain sign-in or password-reset codes, and never with tracking parameters such as utm_…; to tell apart pages that differ only after "?", Cartouche keeps a one-way fingerprint of that part, from which it cannot be read back. If the sites you use need that part to find a page again, you can turn on "Keep the full address of pages" in Settings. A page is remembered only while it has at least one highlight. On pages you did not highlight, nothing is kept. While Cartouche runs in a tab, that tab's address (without the part after "?") and title are held in memory only and forgotten when the tab closes, goes to another page, or Chrome closes.

PDFs open in Cartouche's own reader. The file is read in that tab and never stored or uploaded; with your highlights Cartouche keeps its file name, page count, title and two identifiers computed from it (a SHA-256 fingerprint of the file and the PDF's internal id), so any copy of the same PDF gets its notes back — plus its web address (without the part after "?") if you opened it from a tab. A web PDF is downloaded again by your browser directly from its own site, when you ask.

While your highlights are shown on a page, that website's own scripts could technically see which of its passages are highlighted, as with any highlighter. Your notes are never written into the page's content: they appear in Cartouche's note box, which the page's scripts cannot open. What you type in that box on the page can, however, be observed by the page's scripts, like any typing on a website; write a note you want kept away from a site in the side panel, which the page never reaches.

The sites you turned on, and the sites you allowed the PDF reader to download from, are listed in Cartouche's settings, where you can remove them; "Reset all data" removes them too.

Your highlights are never sent to us or to anyone else. Exports (Markdown, CSV, JSON-LD) and backups are files you save yourself; encrypted backups (Pro) use a passphrase that is never stored. Uninstalling Cartouche erases everything it stored in your browser, so keep a backup file.

Assay

Assay reads a page only when you ask it to: after a click on its icon (or its keyboard shortcut) in that tab, or during a "Scan open tabs" run you start. From the page it reads technical markers — the addresses of the scripts, stylesheets and other files the page loads (without their query strings, except a version number or a tool's tag id such as G-…), the names of some <meta> tags (and their content only when it names a technology, such as a "generator" tag), known page variables (their name, and a short value such as a version number) and element markers, and the fonts it declares — to recognize the technologies the page uses. It never reads the page's text or title, form fields, cookies or stored data.

A scan sends nothing over the network and makes no request to the site: Assay does not download the page again and does not read the site's response headers. Detection happens on your device; nothing is sent to us.

The results are kept in your browser: your last 5 scans in the free version, and with Pro a notebook of up to 1,000 scans with the notes and tags you add. A scan keeps the page's address without its query string, the date, and for each technology its name, confidence, version and up to five short lines of evidence (for example the address of the script that revealed it). You can delete any scan, any site or everything from the notebook or the settings, and download a full backup at any time. When a site's last scan is deleted, its note and tags are deleted with it.

"Scan open tabs" first explains what it reads, then asks Chrome for access to all sites for that run only, reads the tabs you have open, and removes the access as soon as the run ends (if the run is interrupted, within 10 minutes or at the next start of Chrome). Tabs in private windows are left out and only counted, and Assay never saves a scan made in a private window.

Pantograph

What it does. Pantograph records the tab, window, screen or camera you choose, with your microphone if you want, lets you trim and export the video, and keeps your recordings on your device.

What it records, and when. Only what you start: the tab you record with one click, or the screen, window or tab you pick in Chrome's own window, plus your microphone and camera if you switch them on. Recording happens only between your Record and your Stop (or until the tab closes or the sharing stops); the toolbar badge shows REC, or a pause mark, the whole time. There is no hidden or background recording.

Where recordings are kept. In Pantograph's private storage in Chrome on your device (the extension's own file system), in this browser only. They are never uploaded to us or to anyone. Exports go where you save them (your Downloads folder, or the file you choose with Save as); the temporary copies Pantograph makes while exporting are deleted once they are more than 2 hours old, the next time you open the editor or Chrome starts, and with Delete all recordings or Reset all data.

What else is stored on your device. Your recording settings (including the identifiers Chrome gives your chosen microphone and camera), a list of your recordings (date, length, size, picture size, format — never a web address or page title), the live recording state (in memory, cleared when Chrome closes), a marker that lets Pantograph recover a recording interrupted by a crash, a counter of the Pro exports you have tried, whether you have seen the "recording other people" notice, whether this computer can record MP4 (with the Chrome version it was checked on), and your license state.

What leaves your device. Nothing, unless you activate Pantograph Pro: then your license key, the product id and a random installation id are sent to our license service to verify the license (see "License service" above). Usage statistics follow "Usage statistics" above: none are collected today, and if they are ever offered they will never contain recordings, sounds, images, web addresses, titles, file names or device names.

Microphone and camera. Chrome asks you once, from Pantograph's setup page. Pantograph uses them only while you record, and while you test them: the microphone level meter (in the popup, the settings or the setup page, when you click Test microphone or have just allowed it) and the camera preview (in the settings or the setup page, when you click Show preview or have just allowed it). Opening the popup or the settings does not turn them on. What you hear or see while testing is not recorded or stored.

Other people. Your recordings may capture other people's voices, faces or information. Recording other people? Tell them before you start and get their consent where the law requires it. In a video call, the others cannot see Pantograph's REC badge. Pantograph shows this before your first recording. We never receive your recordings: what you record, and what you do with it, is under your control.

Deleting. Delete a recording in the editor, or all of them in Settings (an interrupted recording waiting to be recovered included). Discard deletes an interrupted recording. Reset all data also deletes every recording. Unfinished files that nothing refers to any more (a recording that could not start, or had nothing in it) are deleted automatically. Uninstalling Pantograph deletes everything it stored, recordings included: download the ones you want to keep first.

Permissions. Storage and background documents (no install warning); unlimited storage, so long recordings are not evicted; and, only if you allow it the first time you record a tab, tab recording (Chrome words it "Read and change all your data on all websites"). Pantograph does not read the content, address or title of any page, and injects no script into pages.

Diglot

Diglot reads the text of a page only when you click its icon on that page (Chrome's "activeTab"), or, with Pro, on the sites you chose to always translate (Chrome asks you to allow each of them). Diglot sends the text of the page to the translator built into Chrome, which runs on your device. The text is never sent to us: page text, translations and the text you select are not sent to anyone and are not stored. Translations are shown in the page, marked as machine translation, and removed when you stop or leave the page. The first time you use a language pair, Chrome may download a language pack from Google; that download contains none of your pages. Stored locally: your settings, the list of sites you chose to always translate (site addresses only), and until you close the browser the progress of a language pack download and the numbers of the tabs where Diglot is running. A bilingual copy of a page is saved only when you choose Copy or Download, to your clipboard or to a file, for your personal use.

Website

https://burin.riseva.fr sets no cookies, runs no analytics and loads nothing from third parties. Our host, Cloudflare, Inc., processes technical logs (IP address, browser type, requested page, time) to deliver the site and protect it against attacks, and keeps them for no more than 30 days. Legal basis: our legitimate interest in operating a secure website.

Who receives data

RecipientRoleData
Supabase Inc. (database and functions, EU region)Our processorLicense records described above
Cloudflare, Inc.Our processorWebsite logs
Lemon Squeezy LLCIndependent controller (merchant of record)Purchase and billing data
Google (Chrome Web Store)Independent controllerInstalls and store reviews, under Google's policies
Google (Chrome)Independent controller, under Google's policiesDiglot only: the language packs Chrome itself downloads from Google the first time you use a language pair. The request is Chrome's own, is not made by Diglot and contains none of your pages

We never sell personal data, share it for advertising, or use it to decide creditworthiness.

International transfers

Supabase and Lemon Squeezy are companies based in the United States. Where personal data is transferred outside the European Economic Area, it is protected by the European Commission's Standard Contractual Clauses or the EU-U.S. Data Privacy Framework, as offered by these providers.

How long we keep data

DataRetention
License records (with the subscription status and refund records linked to them)While the license exists, then deleted on request or 3 years after it ends (for a subscription, after the subscription and its license have ended)
Installation recordsUntil the license is removed from that browser, then 90 days
Rate-limit hashes1 day
Webhook receipts (hash of the notification, event name)90 days
Support e-mails24 months after the conversation ends
Website logs30 days maximum

What our extensions keep on your device never reaches us and is not in this table: it stays in your browser until you delete it, reset the extension or uninstall it, unless the product's section gives a shorter period. Catchword also keeps its daily totals for 365 days at most, and only its five most recent restore points (4 MB together at most).

Your rights

You can ask to access, correct or delete your data, to restrict or object to its use, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. Write to contact@riseva.fr. Because we do not store your name or e-mail with your license, please include your license key so we can find the matching records; we answer within one month.

You can also lodge a complaint with CNIL (Commission nationale de l'informatique et des libertés), www.cnil.fr or with the data protection authority where you live.

California residents: we do not sell or share personal information, and we do not use sensitive personal information. You can ask what we hold and ask us to delete it; we will not treat you differently for doing so.

Security

Connections use HTTPS. License tokens are signed by our server and verified by the extension; signing keys and database credentials exist only on the server. Records are pseudonymised with keyed hashes, and database access is limited to the license service. Our extensions contain no remote code.

Children

Our products are not directed to children under 16, and we do not knowingly collect their data.

Chrome Web Store Limited Use

The use of information received by our extensions adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes

We will publish any change here with a new effective date. If a change affects what an extension collects or how it uses data, the extension will explain it and ask for your agreement before the change applies.