Summon — Privacy Policy
This policy explains what data Summon collects, stores, and transmits, and why. It's written to be read in full — there's not much to hide because there's not much happening off your device.
the short version
Summon does not have an account system, does not run a server, does not sync your data anywhere, and does not track you. Everything Summon needs to work lives locally in your browser. The only exception is a single, opt-in call to a third-party license API, and only if you enter a Pro license key.
what Summon stores, and where
Summon stores the following locally, in your browser's extension storage. None of it leaves your device:
- Your curated bookmark list, along with any renames or aliases you set (Pro)
- Your theme preference and new-tab-page settings (background image or color, drop shadow, fullscreen mode, date/time display)
- Your Pro license state, if you've activated a license key
Summon also reads data that already exists in Chrome, live, without copying or exporting it anywhere:
- Your Chrome bookmark tree — read so bookmarks can appear as searchable results in the command palette. Free users see this reflected in an auto-synced curated shortlist; Pro users can additionally search the full bookmark tree. Summon does not create, delete, or reorganize your native bookmarks.
- Your open browser tabs (title, URL, recency) — read so tabs can appear as searchable, switchable results in the palette. This is what lets Summon act as a cross-window tab switcher.
what Summon does not do
- No account or login of any kind.
- No cloud sync. Nothing about your bookmarks, tabs, or settings is uploaded anywhere.
- No backend that we operate. There is no Summon server sitting between you and your data.
- No telemetry, no analytics, no usage tracking, in the codebase.
- No reading, modifying, or transmitting the content of the pages you visit. The command palette is injected as a self-contained overlay; it does not inspect or alter page content.
the one external call Summon makes
If — and only if — you enter a Summon Pro license key, Summon calls Polar.sh's public license-key API to activate and periodically revalidate that key. This is a direct, no-auth API call made from the extension itself; there is no Summon-run server in the middle. It happens roughly once every 24 hours to revalidate an active license, with a 7-day offline grace period so Pro continues working without a connection. If you never enter a license key, this call is never made.
No bookmark, tab, or browsing data is included in this call — only what's needed to validate the license itself.
permissions Summon requests, and why
| Permission | Why it's needed |
|---|---|
bookmarks |
Read your bookmark tree so it can be searched from the palette. |
storage |
Store your curated list, settings, and license state locally. |
scripting |
Inject the command palette overlay onto the current page. |
tabs |
List and switch to your open tabs from the palette. |
alarms |
Schedule periodic Pro license revalidation. |
| Host access (all sites) | Let the palette overlay appear on any page you're browsing. |
Host access — api.polar.sh |
Validate a Pro license key, only when one is entered. |
children's privacy
Summon is not directed at children and does not knowingly collect data from anyone, children included — since it does not collect data from anyone at all.
changes to this policy
If Summon's data handling ever changes — for example, if telemetry or analytics were ever introduced — this policy will be updated first, before the change ships, and the update will be reflected in the Chrome Web Store listing.
contact
Questions about this policy or how Summon handles data can be sent to:
privacy@kuronaut.com
This policy applies to the Summon Chrome extension only. It does not apply to third-party sites you may visit or link to through Summon, including Polar.sh, whose own privacy policy governs the license-key API call described above.