stramus — Privacy Policy
Last updated: 14 August 2026
stramus works without an account, and without one it sends nothing anywhere: your collections, links, files and settings live in your own browser, on your own machine. An account is optional, and it exists for one reason — to have the same collections on your other browser. This page says exactly what an account changes, including the parts that are not flattering.
Without an account
Everything stramus knows lives in a database inside your browser's own storage (IndexedDB, the store every browser keeps for the pages it runs). That is:
- the collections, sections and cards you create — their titles, links, notes and order;
- files you save into a card, as their own bytes;
- icons of the sites you have saved, cached so that a card still shows one when offline;
- how often and how recently you have opened each page from stramus, which is what puts the pages you actually use at the top of the search box;
- your settings: theme, language, sort order, the assistant you chose, and any section PINs;
- a picture you chose as the background, if you chose one — kept, downscaled, in the browser's own preference storage rather than in the database, and never sent anywhere. Picking one of the ready-made backgrounds instead keeps no picture at all: those are drawn by your browser.
None of it is uploaded anywhere. There is nowhere for it to go: with no account, stramus talks to no server of ours at all. You can take it with you at any time — Settings offers an export to CSV and to a bookmarks file, and, under Backup, a copy of the whole database in one file (which is more than the exports: the cached icons, the counters and the PIN of a locked section are in it too, so it is a file to keep as carefully as you would the browser itself) — and removing the extension removes the database with it.
With an account
Signing in turns on synchronisation. From then on, the following is copied to our server so that your other browser can have it:
- your sections, collections, card groups and cards — titles, links, note text, the order you put them in, and when each was created and last changed;
- the bytes of files saved into cards, and the small previews shown in the grid;
- your email address, which is what the account is;
- an identifier for each browser you sign in on, so that signing out of one does not sign out of the others.
A PIN on a section does not hide it from us
A section PIN keeps a section off your screen — its collections are not even named in the sidebar until the PIN is entered, and its cards stay out of search and out of export. It is a lock against someone at your machine. It is not encryption: the cards inside a locked section are stored on your machine, and synced to our server, in plain text, exactly like any other card. If you have things you would not want on someone else's computer, a section PIN is not what will keep them off it.
Your browsing statistics are not synced unless you ask
stramus counts which pages you open from it, and how often — that is what ranks your search box. It is a record of where you have been, which is a different kind of thing from the collections you chose to keep, so it is treated differently: it stays on your machine unless you turn "Sync browsing statistics" on in Settings. It is off by default, and while it is off those rows are neither sent to the server nor accepted from your other devices.
Asking stramus to stop suggesting a page removes it here and on your other browsers, and it does not come back — the count starts from nothing if you ever open the page again.
What the server does not do
- No analytics, no telemetry, no tracking, no advertising, no profiling.
- Nothing is sold, and nothing is shared with anyone. There is no third party in this.
- The contents of your cards are not read, indexed or looked at. Searching and sorting happen in your browser; to the server a card is an opaque blob it stores and hands back.
- Your browsing history (the browser's own) is never uploaded, with or without an account.
How long things are kept
For as long as the account exists. Deleting something deletes its contents there and then — the title, the address, the text are gone from the server and are not kept back anywhere; the bytes of a file go with the next sweep, which runs daily, since a file may be shared by more than one card and it is the last card that takes it with it. What remains is a marker: this row, identified by a random id, was deleted at this time. It holds nothing of what the row said, and it is there because it is the only way your other browser can be told to stop showing something it already has. Those markers last as long as the account does. Sign-in codes die in ten minutes; sign-in sessions expire, and can be ended from any browser you are signed in on.
Your rights over this
- A copy of everything. The account dialog exports every row the server holds about you, in the same form it holds it.
- Deletion. Deleting the account erases it — the rows, the files, the devices, the sessions, the account itself. It is not a flag; nothing is kept back. What is on your machine stays on your machine, unless you tick the box beside that button, which empties this browser's database as well: the collections, the files, the counters, the cached icons. That one is off unless you ask for it, and it cannot be undone from here — take a backup first if you may want any of it back.
- Signing out. Leaves your data exactly where it was: it was yours before there was an account, and it still is.
The legal basis for storing your collections is performing the service you asked for (synchronisation); for the browsing statistics it is your consent, which is why that one is a switch you turn on and can turn off.
The permissions the extension asks for
- tabs — to list the tabs you have open, so you can save them into a collection, reorder them, and close them from the tab pane. Tab titles and URLs are read while stramus is open and are written down only for the tabs you choose to save.
- history — to power the history pane and to let a page you visited turn up in the search box. The browsing history is read from the browser as you search it; stramus keeps no copy of it and never uploads it.
- search — to send a query from the search box to your default search engine, whichever one you have set, exactly as the address bar would.
- favicon — to read site icons from the browser's own favicon store, so that drawing a link to a site you have already visited requires asking nobody at all. For a site you have not visited the browser has no icon, and the icon is fetched as described under Site icons below.
- storage — to hold a page you saved without stramus open. The keyboard shortcut, the right-click entries and the toolbar button all work from any tab, and there may be no stramus tab to make a card in at that moment, so the page waits in the browser's own extension storage — its title, its address, the address of its icon, and nothing else — until one is open. It becomes a card then, and the queue is emptied. Nothing about it is sent anywhere.
- contextMenus — for the two entries in the right-click menu, “Save page to stramus” and “Save link to stramus”. They read the page or the link you clicked, at the moment you click them, and nothing else on the page.
- notifications — to say “saved” after one of those, which is the only way you would know: there may be no stramus tab open to show it on screen. The message is the page's own title, shown by your browser and sent nowhere.
- access to the stramus server — used only when you have an account, and only to sync what this page describes.
What else leaves your machine, and only because you asked
- Opening a saved link or a tab goes to that site, as clicking any link does.
- Searching the web from the search box hands your query to your default search engine, under that engine's privacy policy.
- Asking a question of a web assistant. By default the assistant is the browser's own on-device model, where your browser has one: it answers on your machine and sends nothing anywhere. If you instead choose ChatGPT, Gemini or Claude in the settings, then asking a question opens a chat with that service in a new tab, with your question in it — so the question, and it alone, goes to them, under their privacy policy. Your collections are never part of it.
- Video previews. Off unless you switch them on (Settings → Appearance
→ “Video previews”). Switched on, a card standing for a YouTube video shows the
still frame YouTube publishes for that video: your browser loads the picture from
i.ytimg.comdirectly, the same address an embed of that video anywhere on the web loads it from. It is an ordinary image request made by your browser, so Google sees which video it is, your IP address and — as with any picture a browser loads — whatever cookies it already holds for that domain. We receive nothing and keep nothing: the frame is not stored with your card, not re-encoded, and never travels to our server. Leave the setting off and no such request is made at all. “On hover” asks only about the video you point at; “always” asks about every video on screen, each time you open the collection.
Site icons
A saved link is drawn with the site's icon, and getting hold of that icon is the one part of stramus that would otherwise quietly describe your reading to somebody else. Asking a public icon service for the icon of a host tells that service you have that host saved — one request per site, which for a list of bookmarks amounts to the list itself. So the icon is looked for in this order, and stops at the first step that answers:
- Your browser's own icon store (the extension only). Sites you have visited are already in it, and reading it involves no network and no third party.
- The stramus server, which fetches the icon on your behalf: first from the site itself, then, if the site has none to give, from the public icon services. Those services see our server asking about a host — not you, not your address, and with no way to tell whether one person or a thousand had that link. The server keeps one row per host with the icon in it, for everyone; that row records no user, and requests for it are anonymous and not logged.
- The icon services directly (
favicone.com, andgoogle.com/s2/faviconsas a last resort) — only when our server cannot be reached at all. This is the one case where a third party learns a host from your address rather than from ours, and it is the alternative to your saved links losing their icons whenever our server is down. - Nothing. A site with no icon anywhere gets a coloured tile with its first letter on it, drawn in your browser.
Icons fetched this way are cached on your machine, so the same site is not looked up again for a month — and so your links keep their icons offline.
The web app at stramus.space
The same app also runs as a plain web page, without a browser extension around it. It stores your data in the same way and syncs in the same way, and it differs in two respects worth naming:
- Having no browser icon store to ask, it starts at step 2 above — the server — for every site, including the ones you have visited.
- It is hosted on GitHub Pages, whose servers keep their own request logs. See GitHub's privacy statement.
Children
stramus is not directed at children, and asks for no personal data beyond an email address.
Changes
If this policy changes, the new version appears on this page with a new date above. Material changes will also be noted in the extension's release notes.
Contact
Questions about privacy, or anything else, are welcome in the project's issue tracker.
stramus — политика конфиденциальности
Последнее обновление: 14 августа 2026
stramus работает без аккаунта, и без аккаунта не отправляет никуда ничего: коллекции, ссылки, файлы и настройки лежат в вашем браузере, на вашем компьютере. Аккаунт — дело добровольное, и нужен он ровно для одного: чтобы те же коллекции были во втором браузере. Ниже — что именно меняет аккаунт, включая то, что нас не красит.
Без аккаунта
Всё, что известно stramus, лежит в базе данных внутри хранилища браузера (IndexedDB — то хранилище, которое браузер держит для запущенных в нём страниц). А именно:
- коллекции, разделы и карточки, которые вы создали, — их названия, ссылки, заметки и порядок;
- файлы, сохранённые в карточку, — своими байтами;
- иконки сохранённых сайтов, кэшированные, чтобы карточка не оставалась пустой без сети;
- как часто и как недавно вы открывали каждую страницу из stramus — именно это поднимает нужные вам страницы наверх в строке поиска;
- настройки: тема, язык, порядок сортировки, выбранный ассистент и PIN-коды разделов;
- картинка, выбранная фоном, если вы её выбрали, — она лежит уменьшенной в хранилище настроек браузера, а не в базе, и никуда не отправляется. Готовые фоны из списка не хранят картинку вовсе: их рисует сам браузер.
Ничего из этого никуда не выгружается — и выгружать некуда: без аккаунта stramus вообще не разговаривает с нашим сервером. Забрать свои данные можно в любой момент: в настройках есть экспорт в CSV и в файл закладок, а в разделе «Резервная копия» — вся база одним файлом. В нём больше, чем в экспортах: туда попадают и кэш иконок, и счётчики открытий, и PIN запертого раздела, так что хранить этот файл стоит так же бережно, как сам браузер. Удаление расширения удаляет базу вместе с ним.
С аккаунтом
Вход включает синхронизацию. С этого момента на наш сервер уезжает следующее — чтобы второй браузер мог это получить:
- разделы, коллекции, группы и карточки — названия, ссылки, тексты заметок, порядок, который вы им задали, и даты создания и последнего изменения;
- байты файлов, сохранённых в карточки, и их маленькие превью для сетки;
- адрес электронной почты — он и есть аккаунт;
- идентификатор каждого браузера, в котором вы вошли, — чтобы выход в одном не выкидывал вас из остальных.
PIN на разделе не прячет его от нас
PIN убирает раздел с экрана: пока код не введён, его коллекции даже не названы в боковой панели, а карточки не попадают ни в поиск, ни в экспорт. Это замок от человека, стоящего рядом с вашим компьютером. Но это не шифрование: карточки внутри запертого раздела лежат и на вашей машине, и на нашем сервере в открытом виде — ровно как любые другие. Если есть вещи, которых вы не хотели бы видеть на чужом компьютере, PIN на разделе — не то, что их туда не пустит.
Статистика посещений не синхронизируется, пока вы этого не попросите
stramus считает, какие страницы вы из него открываете и как часто, — этим ранжируется строка поиска. Это след того, где вы были, и это другая по чувствительности вещь, чем коллекции, которые вы решили сохранить. Поэтому и обращение с ней другое: она остаётся на вашей машине, пока вы не включите «Синхронизировать статистику посещений» в настройках. По умолчанию — выключено, и пока выключено, эти строки не отправляются на сервер и не принимаются с других устройств.
Если попросить stramus больше не предлагать страницу, она исчезнет и здесь, и на других ваших браузерах, и обратно не вернётся — а если вы когда-нибудь откроете её снова, счёт начнётся с нуля.
Чего сервер не делает
- Никакой аналитики, телеметрии, трекинга, рекламы и профилирования.
- Ничего не продаётся и ни с кем не делится. Третьей стороны здесь нет.
- Содержимое карточек не читается и не индексируется: поиск и сортировка живут в вашем браузере, а для сервера карточка — непрозрачный блоб, который он хранит и отдаёт обратно.
- История браузера не выгружается никогда — ни с аккаунтом, ни без него.
Сколько всё это хранится
Пока существует аккаунт. Удаление стирает содержимое сразу — название, ссылка, текст уходят с сервера и нигде не придерживаются; байты файла уходят со следующей уборкой, а она раз в сутки: один файл может быть нужен нескольким карточкам, и уносит его последняя из них. Остаётся только отметка: строка с таким-то случайным идентификатором удалена тогда-то. В ней нет ничего из того, что в строке было, и она нужна затем, что иначе второму браузеру нечем сказать: перестань показывать то, что у тебя уже есть. Такие отметки живут, пока существует аккаунт. Коды входа живут десять минут; сессии истекают и могут быть прекращены из любого браузера, где вы вошли.
Ваши права на всё это
- Копия всего. В окне аккаунта есть экспорт: сервер отдаёт всё, что о вас хранит, в том же виде, в котором хранит.
- Удаление. Удаление аккаунта стирает его — строки, файлы, устройства, сессии, сам аккаунт. Это не флажок; ничего не остаётся. То, что лежит на вашей машине, остаётся у вас — если только вы не поставите галочку рядом с той же кнопкой: она вдобавок опустошает базу этого браузера, вместе с коллекциями, файлами, счётчиками и кэшем иконок. Галочка снята, пока вы её не поставите, и отменить это отсюда нельзя — сделайте резервную копию, если что-то из этого может ещё понадобиться.
- Выход. Оставляет ваши данные ровно там, где они были: они были вашими до аккаунта и остаются вашими после.
Правовое основание хранения коллекций — исполнение услуги, о которой вы попросили (синхронизация); для статистики посещений — ваше согласие, поэтому она и сделана переключателем, который можно выключить.
Запрашиваемые разрешения
- tabs — показать открытые вкладки, чтобы их можно было сохранить в коллекцию, переупорядочить и закрыть. Заголовки и адреса вкладок читаются, пока stramus открыт, и записываются только для тех вкладок, которые вы сохранили.
- history — панель истории и поиск по посещённым страницам. История читается у браузера в момент поиска; stramus её копию не хранит и никуда не отправляет.
- search — отправить запрос из строки поиска в ваш поисковик по умолчанию, тот, который вы выбрали, — ровно как это делает адресная строка.
- favicon — читать иконки сайтов из собственного хранилища браузера: для сайта, где вы уже были, иконка берётся оттуда и спрашивать не приходится никого. Для сайта, где вы не были, у браузера иконки нет — как она добывается тогда, описано ниже в разделе Иконки сайтов.
- storage — придержать страницу, сохранённую без открытого stramus. Горячая клавиша, пункты правого клика и кнопка на панели работают из любой вкладки, а вкладки stramus в этот момент может не быть — и страница ждёт в собственном хранилище расширения: заголовок, адрес, адрес иконки, больше ничего. Как только stramus открыт, она становится карточкой, а очередь очищается. Наружу оттуда не уходит ничего.
- contextMenus — два пункта в меню правого клика: «Сохранить страницу в stramus» и «Сохранить ссылку в stramus». Они читают ту страницу или ту ссылку, по которой вы кликнули, в момент клика, и ничего больше на странице.
- notifications — сказать «сохранено» после такого сохранения: иначе вы об этом никак не узнаете, ведь открытой вкладки stramus может и не быть. В уведомлении — заголовок самой страницы, показывает его браузер, и никуда оно не отправляется.
- доступ к серверу stramus — используется только при наличии аккаунта и только для синхронизации того, что описано на этой странице.
Что ещё уходит наружу — и только по вашей воле
- Открытие сохранённой ссылки или вкладки — обращение к самому сайту, как при любом клике по ссылке.
- Поиск в вебе из строки поиска передаёт запрос вашему поисковику по умолчанию, на условиях его политики конфиденциальности.
- Вопрос ассистенту. По умолчанию отвечает встроенная в браузер модель, если она там есть: она работает на вашем компьютере и никуда ничего не отправляет. Если же в настройках выбрать ChatGPT, Gemini или Claude, вопрос открывается в новой вкладке — в чате с этим сервисом, уже отправленный. То есть к ним уходит ваш вопрос, и только он, на условиях их политики. Ваши коллекции туда не попадают никогда.
- Превью видео. По умолчанию выключены (Настройки → Оформление →
«Превью видео»). Если включить, карточка сохранённого видео с YouTube показывает кадр,
который YouTube публикует для этого ролика: браузер загружает картинку прямо с
i.ytimg.com— с того же адреса, откуда её берёт любой эмбед этого видео в интернете. Это обычный запрос картинки вашим браузером, поэтому Google видит, что это за ролик, ваш IP-адрес и — как при загрузке любой картинки — те куки, которые у него уже есть для этого домена. Мы не получаем и не храним ничего: кадр не сохраняется вместе с карточкой, не перекодируется и не попадает на наш сервер. Оставьте настройку выключенной — и запроса не будет вовсе. «При наведении» спрашивает только про то видео, на которое вы навели; «всегда» — про все на экране, при каждом открытии коллекции.
Иконки сайтов
Сохранённая ссылка рисуется иконкой сайта, и добыча этой иконки — единственное место в stramus, которое иначе тихо рассказывало бы о вашем чтении кому-то ещё. Запрос к публичному сервису иконок сообщает ему, что у вас сохранён такой-то сайт: по запросу на сайт, а для списка закладок это и есть сам список. Поэтому иконка ищется по порядку, и поиск останавливается на первом шаге, который ответил:
- Собственное хранилище иконок браузера (только расширение). Сайты, где вы уже были, там уже есть; ни сети, ни третьих лиц.
- Сервер stramus — он забирает иконку за вас: сначала у самого сайта, а если у того её нет, у публичных сервисов. Сервисы видят, что о хосте спрашивает наш сервер, — не вы, не ваш адрес, и без всякой возможности понять, один человек сохранил эту ссылку или тысяча. На сервере хранится одна строка на хост с иконкой, общая для всех; в этой строке нет пользователя, а сами запросы анонимны и не журналируются.
- Сервисы иконок напрямую (
favicone.com, в крайнем случаеgoogle.com/s2/favicons) — только когда наш сервер недоступен вовсе. Это единственный случай, когда о хосте третья сторона узнаёт с вашего адреса, а не с нашего; цена отказа от него — ссылки без иконок на всё время, пока сервер лежит. - Ничего. Сайту, у которого иконки нет нигде, рисуется цветная плитка с первой буквой — прямо в браузере.
Полученные иконки кэшируются на вашем компьютере: тот же сайт не запрашивается повторно в течение месяца, а ссылки не теряют иконки офлайн.
Веб-версия на stramus.space
То же приложение работает и как обычная веб-страница, без расширения вокруг. Данные оно хранит и синхронизирует так же, но отличается в двух вещах:
- хранилища иконок браузера у неё нет, поэтому для любого сайта — включая те, где вы уже были, — она начинает сразу со второго шага, с нашего сервера;
- страница размещена на GitHub Pages, чьи серверы ведут свои журналы запросов — см. политику конфиденциальности GitHub.
Дети
stramus не адресован детям и не запрашивает персональных данных сверх адреса электронной почты.
Изменения
Если политика изменится, новая версия появится на этой странице с новой датой сверху. О существенных изменениях будет сказано и в примечаниях к релизу.
Контакты
Вопросы о приватности — и любые другие — можно задать в трекере задач проекта.