Why First Privacy Policy
Effective date: 2026-09-18Last updated: 2026-09-22
Why First is a local-first browser extension: what you browse never reaches us. This policy describes the four things that do leave your device or reach our services — the Pro license requests, the optional AI reader, the account and order records created when you buy something, and the payments our merchant of record processes on our behalf.
What stays in your browser
By default everything the extension keeps stays in your browser's local extension storage (browser.storage.local), and none of it is sent to us:
- The list of sites and URL rules you configure.
- The short intent notes ("reasons") you optionally write during a check-in.
- Raw usage statistics: visit counts and time spent per rule, per day.
- Local-only extras: your judgement ratings, the day's exception allowance, and the signed Pro credential described below.
We do not operate a browsing-data backend: we receive no domains, no URLs, no notes, no page content and no statistics from the extension, and we hold no browsing history about you.
What the extension can see
When you navigate to a site you have configured a rule for, the extension sees the domain and URL path you are heading to, in order to decide whether to show the check-in page. It never reads page content, form fields, cookies, or anything you type into other websites.
The AI reader (optional, off by default)
The AI reader judges whether the note you typed matches the site you are opening. It is off by default, and nothing is sent while it is off — the local checks run instead. When you switch it on and a note is being judged, the extension sends your note, the domain, and any site note you wrote for that site to the AI endpoint you chose:
- Your own provider or endpoint (you supply the API key): the request goes straight from your browser to that provider, and never passes through Why First.
- The AI endpoint Why First ships (
api.typesafe.ai) or a judgement run through your Why First account: the request reaches our AI judgement service and is forwarded to our AI provider.
Our judgement service stores the accounting of a judgement — how many judgments it spent, when it ran, which provider answered — and deliberately does not store the note text, the prompt or the verdict. The extension shows you which of these destinations is in force before anything is sent, and never sends your browsing history, a URL, or a page's contents.
What we keep when you buy something
Buying Pro or AI intent judgments requires a Why First account, identified by your email address and protected by a password. An account exists so that an order, an entitlement and a judgment balance can belong to someone. It holds:
- Account details: your email address and the name you gave at sign-up.
- Sign-in sessions: a session record per sign-in, with the IP address and user-agent string it was created from, so a session can be revoked.
- Orders: one row per completed payment — the product, the amount and currency, the payment partner's transaction and customer identifiers, and whether the order was refunded or charged back.
- Entitlements: which purchase (or manual grant) currently grants you Pro.
- AI intent judgments: your balance, an append-only ledger of every movement (grants, spends, reversals), and the usage accounting of judgements that ran through us.
- Payment events: the payment partner's own webhook payloads, kept verbatim for audit and cleared to an empty payload 30 days after the event is settled; a hash of the original payload is kept.
- Operator audit records: which member of staff took an action, on whose account, and why — required for balance adjustments and account suspensions.
None of it contains a domain, a URL, an intent note, a page or a visit. Deleting a rule, a note or your statistics never touches these records, and vice versa.
Payments and the merchant of record
Pro and AI intent judgments are sold through a payment partner acting as the merchant of record. It sells to you on its own hosted checkout page, collects and remits tax, issues the receipt, and keeps the order, customer and refund records that consumer and tax law require it to keep; that processing is governed by its own privacy policy. We never see or store your card details.
When our checkout can prefill the payment page, we send the partner the email address on your account. The payment partner's records and ours are joined by the order and transaction identifiers, so a refund reported by the partner is matched to the purchase it belongs to — which is how a refund reverses the entitlement and any judgments the purchase granted.
Pro license verification
Buying Pro gives you a license key that the extension activates. Activation is the only time the raw key leaves your device: an activation request contains the license key, an anonymous install ID generated on your device (not a hardware fingerprint), the product ID, the app version, and the browser family. It never contains a domain, URL, note, statistic or page content, and no payment or billing details.
Our license service verifies the purchase with the payment partner and returns a signed credential, which is stored in your browser's local extension storage. The extension does not keep the raw key after activation; every later request — the background refresh and deactivation — sends the signed credential and the app version instead, and nothing else. The license service keeps no browsing data and no account: it answers a license question about a purchase the payment partner already holds.
The signed credential carries an offline grace period — 60 days by default, configurable between 30 and 90 days, counted from the last successful issue. While you are offline, Pro keeps working for that period. Past it, and until the next successful check, Pro features switch off and the extension falls back to Free; your rules, statistics and notes are never deleted, and one successful check or re-activation restores Pro.
While you are online, the extension refreshes the license in the background, normally about once a week or two. If you deactivate Pro in Settings, the extension sends the same signed credential and app version so the license service can release that activation. Refunded or revoked keys stop working at the next successful check, which is why we do not promise an exact revocation time.
Cross-device sync
The extension's optional cross-device sync of rules and settings is built but not offered in this release, so no rules or settings leave your device for another one today. If we enable it, it will use your browser's own sync service (Google for Chrome, Mozilla for Firefox) under your browser account's terms, it will carry rules and settings only, and browsing history, intent notes and statistics will never be part of it. Why First is not part of that exchange and cannot read the synced data.
Third parties
- Our merchant of record sells Pro and AI intent judgments, collects tax, and keeps order and customer records as tax and consumer law requires. It receives the email address on your account when its checkout can prefill it, and nothing about your browsing.
- Our AI provider receives the note, the domain and any site note for judgements that run through Why First, in order to answer them. We have no agreement with it that would let us identify you by your browsing, and we send it no account identifier.
- Your own AI provider or endpoint, which you configure yourself and which receives your note directly from your browser. You supply its key, and its own terms govern that request.
- Your browser vendor, only if cross-device sync is ever switched on.
Retention
- Browsing data: never on our servers, so there is nothing for us to retain.
- Account, order, entitlement and judgment records: kept while your account exists, and order records for as long as tax and consumer-protection law requires.
- Payment event payloads: cleared 30 days after the event settles; the payload hash remains.
- The judgment ledger and operator audit records are append-only by design: a correction is a new entry, never an edited one.
- Sign-in sessions: until you sign out, the session expires, or an operator revokes it.
Your controls and your rights
- Delete any rule, note, statistic or rating from the extension's settings at any time.
- "Clear all local data" in Settings removes everything the extension has stored, including the local Pro credential.
- Uninstalling the extension removes all locally stored data.
- Write to privacy@shiquda.com to ask about your account data: a copy of what we hold, a correction, or the deletion of your account. We will answer within 30 days. Where an order must be kept for tax or consumer law, we will say so and keep only that record.
Changes
We may update this policy. Material changes will be noted in the extension's changelog and on this page with a new "Last updated" date.