Politică de confidențialitate pentru Eclipser — Dark Mode & Night Theme, Media Dimming
Eclipser — Dark Mode & Night Theme, Media Dimming de Huzk
Politică de confidențialitate pentru Eclipser — Dark Mode & Night Theme, Media Dimming
Publisher: Huzk Ltd
Effective date: 2026-08-28
Eclipser transforms the appearance of web pages on the user's device. Page content, page text, form values, passwords, browsing history, screenshots, and media pixels are not sent to the Eclipser or Huzk Ltd product/licence server. Optional account, promotion, and licence operations use a separate service only after the in-product disclosure is accepted and the user starts an action.
- Computed color, font-size, media-element type/visibility, and whether a DOM or pseudo text node is a readable candidate are processed in device memory only for immediate appearance conversion.
- The global master and
0%–80%media default; normalized-host site activation,75%–200%text scale, global-media inheritance or a0%–80%site media override; and site or page profiles are stored in the browser's local storage area. - Page or form text is not stored, and canvas, image, or video pixels are not read or copied. Media dimming is applied only through CSS.
- The text and media engines run in the top document and only when every parent hop from a child frame to the top document is same-origin. Those engines do not access cross-origin embedded UI or closed Shadow DOM; the color engine can have a different scope in permitted frames.
- In system
forced-colors/high-contrast mode, the color and media engines turn off; text scaling may remain active while the site is enabled. The browser-controlled Picture-in-Picture window is not changed. - When CSSOM hides a stylesheet, the extension background page may re-request that same stylesheet — a file your browser already loaded for that page — without cookies (
credentials:"omit") and without a referrer. It only ever re-requests a URL the page itself loaded, so it contacts no server your browser has not already contacted. Cross-origin recovery is HTTPS-only, refuses loopback, private and link-local hosts, refuses any response that is nottext/css, and refuses a redirect that would change the request's origin policy. The bytes are used only to compute colours on your device and are never sent anywhere. Raw CSS up to 1 MiB and the final URL can be kept in memory-only the extension's memory-only session storage (storage.session), reused for at most one hour, and retained until earlier bounded eviction or the browser/extension session ends. Page content is not sent to the product/licence service. Rules from a stylesheet that stays unreadable are skipped fail-closed. If a rule affects a very large generic feed without another visibility or lifecycle signal, the surface may wait until the next high-signal page change or refresh. - To reduce repeat processing and first-paint flash, the background page can keep the exact web origin, up to 300 KiB of generated appearance CSS, and a dark background/foreground hint in memory-only the extension's memory-only session storage (
storage.session) for no more than one hour. This state is limited to 60 origins and 8 MiB in total, is unavailable to page scripts, is never written to the visited site's storage, persistent extension storage, Firefox Sync, or the product/licence server, and is ignored then removed when stale or invalid. - Firefox does not grant the extension access to
file:URLs, so local files are not themed. - A page profile key contains only the origin and path; user information, query parameters, and fragments are removed.
- If the user enables Firefox Sync, supported settings and web profiles are written to the browser's Firefox Sync storage area. Eclipser does not operate its own sync server.
- The automatic PDF redirection preference and optional navigation permission remain local to that device.
- Account, promotion, and Checkout network requests stay disabled until the user affirmatively accepts the separate in-product disclosure. The consent record remains only in browser local storage and is not included in settings export or Firefox Sync.
- While a Checkout is pending, the extension keeps a versioned recovery marker in the extension's local storage (
storage.local) for no more than 24 hours. Its exact data is an opaque attempt ID, an opaque customer reference, the target plan, the pre-Checkout baseline plan/status/issued timestamp, start/expiry/next-poll timestamps, and a bounded poll-attempt counter. It contains no account e-mail, Stripe Checkout URL, payment-card data, or signed licence JWT, and it is excluded from settings export/import and Firefox Sync. The marker survives extension/browser-worker restarts and pending or transient results for safe recovery; it is removed after verified completion, confirmed cancellation, a handled terminal or other non-transient outcome, or expiry. Exhausting one bounded automatic-poll window pauses polling but retains the marker until explicit recovery or expiry. - When the user requests a sign-in code, verifies it, redeems a promotion, refreshes a licence, manages a device, or opens the billing portal, the extension can send the normalized e-mail address, entered one-time authentication or promotion code, a randomly generated opaque device identifier, and an optional user-provided device label. During promotion redemption it can also send the local trial's end timestamp, bounded to no more than seven days ahead, solely so a code that would not extend current access is rejected before being consumed; that timestamp cannot grant or lengthen server access. The device identifier is not derived from hardware or browsing activity and is not a fingerprint.
- The licence service stores the normalized e-mail address; opaque customer, device, and random admin-summary references; optional device labels; device creation, last-seen, and revocation times; licence and billing entitlement state; promotion and complimentary-access grant metadata; protected-support-case purpose, requested and approved field groups, status, duration, timestamps, actor hash, and current account/device generations; and replay-protection identifiers. A complimentary-access record also contains a controlled reason, a bounded support ticket reference, access dates, and creation or revocation audit metadata. Plain authentication and promotion codes are not stored in its database: bounded, domain-separated hashes are stored instead.
- A signed licence JWT contains opaque customer and device identifiers, plan/status, and validity times. It is kept only in the background page's private IndexedDB vault (
eclipser.private.v1) and is presented to the licence service for authorized refresh, device, and portal operations. Content scripts and extension pages receive only a bounded, secret-free entitlement/account snapshot. The legacyeclipser.licenselocal-storage key is migration-only and is removed only after an exact durable read-back succeeds. A short device-recovery session is kept only in the extension's memory-only session storage (storage.session). Licence, session, e-mail, and promotion data are excluded from settings export, import, and Firefox Sync. - The licence service receives the network IP address and technical request headers needed to serve and protect the request. Rate limits use short-lived counters keyed by derived hashes of the IP address, e-mail address, or promotion code rather than raw values. Application logs are designed to omit or redact full e-mail addresses, one-time codes, promotion codes, JWTs, authorization headers, and service secrets. Cloudflare processes request IP addresses and technical/operational logs while hosting this service under its own terms.
- Aggregate operational metrics available to a short-lived admin session with
customers:readinclude total customers, Pro customers, active devices, automatic billing retries, and billing issues that need operator action. The same permission can open a bounded, cursor-paginated routine customer summary roster. Each summary contains only a masked e-mail, a random opaque customer reference, creation time, effective Free/Pro entitlement, bounded licence status/interval/current-period-end/cancel-at-period-end state, whether billing is linked, active-device count, and whether billing is being retried automatically, needs operator action, or has no issue. It never returns a full e-mail address, Stripe or other provider identifiers, device labels, raw client device identifiers, promotion records, or case detail. Exact-e-mail summary search uses a protected POST body; the e-mail is not placed in a URL or audit subject and the response is the same masked summary. For exact customer detail or a sensitive mutation, an authorized administrator creates a random, 24-hour pending support, security, or legal case that names the requested field groups and a 5, 15, or 30 minute access duration. The customer enters that case ID in Account, reviews the requested groups, may reduce them, and explicitly approves. The admin session, role permission, administrator identity hash, case status and expiry, purpose, approved fields, customer, and current account/device generation are revalidated fail-closed on every detail request; the access is audited and can be closed early. Account/device generation changes, suspension, deletion restriction, device revocation, case closure, or expiry invalidate access. Older compatible extension versions may use the equivalent short-lived signed authorization flow; its authorization stays only in the admin page memory and is revalidated to the same purpose, fields, customer, time, and account/device generation boundaries. An optional sanitized device label or masked device reference is visible only when the customer explicitly approves thedevicesfield group. A separateaccounts:securityincident queue exposes only opaque incident/customer references and minimized security state when strictly necessary to investigate or recover a security incident; it never exposes customer e-mail, device, licence, or promotion detail. There is no general legal-access roster; any legal access is limited to what applicable law requires. Global promotion redemption views remain aggregate-only and promotion-code inventory remains separate. Admin audit events have a configured 180-day cleanup limit, subject to production deployment evidence.
The Eclipser view accepts only credential-free HTTPS documents; on Firefox, local files are not supported. HTTP and credential-bearing PDF URLs stay in the browser's original PDF flow. An accepted document loads directly from its original host; Eclipser does not copy it to a developer server. The source host can receive the IP address and technical headers from the normal network request. If embedding is blocked, the user can open the original document in a new tab.
Data is not sold, used for personalized advertising, or shared with third-party analytics services.
- Cloudflare hosts the licence Worker, D1 database, rate-limit storage, and operational security logs.
- Resend receives the requested destination e-mail address and one-time-code message so it can deliver that message. It is contacted only after the user requests a code.
- Stripe Managed Payments and Link/Onelink services receive a server-created Checkout session only after the user selects a plan. Stripe acts as merchant of record and Checkout may display “Sold through Onelink”; Huzk Ltd is the extension publisher and product-support provider, and Mozilla is not the seller. Stripe’s Link/Onelink services process checkout, transaction-level support, payment, subscription, refund, and billing-portal operations. The extension and licence service do not receive or store card numbers or card security codes. Stripe sends signed billing events containing the customer reference, e-mail address, price/payment/subscription references, and entitlement status needed to issue or revoke access.
- To recover safely from a lost Stripe response, the licence service keeps the immutable URL-encoded provider request contract and its secret-keyed HMAC-SHA-256 for 30 days as minimized billing-operational metadata. It can contain the Checkout customer e-mail or existing Stripe customer ID, canonical return URLs, and opaque customer/attempt metadata. The full contract is not exposed through the admin API/UI or account-data export; recovery backup evidence receives only a peppered digest.
- When Firefox Sync is enabled, Mozilla stores the supported settings and profiles under its Firefox Sync terms. A selected PDF host and a stylesheet's requested or redirect-final host receive the direct network requests described above; page content is not routed through the product/licence server.
Eclipser follows Mozilla's Add-on Policies on data disclosure, collection and use: data use and transfers are limited to the disclosed appearance/readability and account-entitlement features, account and entitlement operations, user-requested support, security and abuse prevention, and legal obligations. Data is not used for advertising, creditworthiness, or unrelated purposes. Human access is limited to the policy exceptions: aggregate operational metrics and the bounded masked summary roster described above are available only to authorized roles; the routine roster excludes full e-mail addresses, provider identifiers, device labels, raw device identifiers, promotion records, and case detail; exact-e-mail summary search returns the same masked result through a protected POST request; exact customer detail and sensitive mutations require the user's explicit, specific, short-lived approval of the exact field groups for a named support, security, or legal case; minimized incident access is allowed only when strictly necessary for security; and legal access occurs only when required by law. Every customer-specific access is role-bound, time-bound, generation-bound, revocable, and audited, and separate promotion inventory does not expose customer details.
Settings, profiles, the local consent record, and the local licence record remain in browser storage until the user removes the relevant browser data, resets settings where supported, or uninstalls the extension. When Firefox Sync is disabled, sync chunks created by Eclipser are removed. Users can export settings as JSON and delete profiles from the settings page; closing the browser session clears the bounded recovery session. Exact-origin CSS cache entries are eligible for reuse for no more than one hour, but an expired entry can remain ignored in memory-only the extension's memory-only session storage (
storage.session) until bounded eviction or the browser/extension session ends.Authentication codes expire after 10 minutes and expired records are removed by service cleanup. Rate-limit counters use one-hour windows and expire or are removed after their security window. A protected customer case is removed 30 days after it is closed or its pending/approved access expires. An expired or revoked complimentary-access record, including its controlled reason and bounded ticket reference, is removed after 180 days. Audited owner-console events and resolved billing-review history are deleted after 180 days. Completed data-rights request, step, and event history and webhook-integrity and erased-identity anti-resurrection records are deleted after 400 days. Removing a device revokes it but retains the opaque device row while the account remains active so the five-device limit and abuse controls remain reliable. Customer, licence, active promotion or complimentary grant, and billing-reference records are retained while needed to provide an active account or entitlement and for refunds, fraud prevention, accounting, legal obligations, and dispute handling.
The separate deletion-journal R2 bucket stores stable opaque request/customer ids, domain-separated hashes of e-mail, provider-customer and rate-limit subjects, provider-step states/evidence hashes, and authorization/retention times solely to reapply an authorized erasure after D1 Time Travel. A daily verified cleanup and a prefix-scoped R2 lifecycle rule delete each checkpoint 180 days after authorization. The separate operations R2 bucket stores the current recovery epoch and incident/actor/code hashes and times until superseded. Its incident snapshots contain stable opaque customer/device/table-row ids, lifecycle/security state, event/reference/time fields and peppered row/identity digests. This is linkable operational data, not anonymous or “PII-free.” Under the owner-approved exceptional retention policy, an open, failed, or incomplete incident snapshot is kept only until the incident can be safely sealed because blind age deletion could make recovery unverifiable. Once safely sealed, its snapshot objects are deleted 180 days after closure by daily semantic cleanup.
The in-product account-data workflow can submit and track requests for Eclipser-controlled live records. Stripe/Link data-rights fulfillment is a separate provider process: customers can use the Stripe Privacy Portal, and Eclipser does not mark Stripe/Link deletion complete from local fulfillment alone. Cloudflare backup aging is also tracked separately from live-row erasure. A completion claim requires the local fulfillment record, the applicable Cloudflare backup-aging receipt, the Stripe Managed Payments provider notice, and the approved provider runbook evidence.
The exact full account-data export scope and verified request flow are published at <https://eclipser.app/data-access>; the verified account-deletion flow is published at <https://eclipser.app/account-deletion>. A verified deletion request erases live account data that is no longer required and has no active scoped legal hold. The completed D1 request graph is then retained for exactly 400 days solely to evidence fulfillment, prevent stale-provider resurrection and fraud, and resolve disputes; daily cleanup removes it once no active identity tombstone or retention hold remains. Open requests and active, time-bounded legal holds are never removed by this terminal-history cleanup. Processors may retain records they must keep under their own legal obligations and apply their separately disclosed request channels.
- Access to all websites: Apply color, text-size, and media appearance changes locally to supported pages; if CSSOM hides rules, re-request without cookies only a stylesheet the page already loaded.
- Storage: Save the global master and media default, site activation/text/media preferences, and profiles and, when requested, use Firefox Sync; keep the bounded CSS cache in memory-only session storage.
- Alarms: Apply scheduled appearance changes at the correct boundary.
- Context menus: Offer site appearance and PDF actions.
- Optional navigation: Redirect PDF navigation to the local viewer only when automatic PDF opening is enabled.
- Support page: <https://eclipser.app/support>
- Email: help@eclipser.app
- Permanent policy URL: <https://eclipser.app/privacy>
If this policy changes materially, the updated text will be published at the same permanent address and the store disclosures will be updated. Existing appearance settings remain active, but a new in-product data-practice version requires a new consent choice before optional account, promotion, or Checkout network requests resume. A fresh installation remains inactive until its initial disclosure is accepted.