back to grabbit

privacy policy

Last updated 20 August 2026

Grabbit does not collect, transmit, or store your personal data. There is no server to send it to. That is not a policy decision so much as an architectural one: the extension has no backend.

what is collected

Nothing. Specifically, and to be unambiguous about each category:

what is stored on your own machine

Two things, both local, neither leaving your computer:

Uninstalling the extension removes all of it.

network requests

Grabbit makes exactly one kind of network request: fetching the image or video file you asked it to save. It happens only when you click a save button. On every social network in the list, that request goes to the content servers of the site you are already on.

Google Images is the one exception, and it is worth spelling out. Google does not host the pictures in its results; it shows you a small cached preview and links to whoever actually published the image. So when you save one, the request goes to that publisher's server — a newspaper, a photographer's site, Wikimedia — and not to Google. Those servers see the request the same way they would if you had opened the picture in a tab yourself.

There are no requests to any server operated by the developer, because none exists.

permissions, and why each one is needed

downloads
Writes the file to your Downloads folder. This is the whole point.
storage
Remembers your filename pattern and folder between sessions.
activeTab and scripting
Lets the popup list the media on the tab you are looking at, and lets the extension reconnect to a tab that was open before it was installed.
Sites you turn on yourself
Grabbit ships able to read nine sites and nothing else. Anywhere else it stays switched off until you click the icon and let it in, and Chrome asks you about that one address specifically. Granting one site grants nothing about any other.

The extension declares that it may ask for other sites, which is what lets Chrome show you that prompt at all. Declaring it is not the same as having it: until you say yes to a particular address, Grabbit cannot read that page. Every site you have turned on is listed in the extension's settings, and each one has a button to turn it back off.
Access to the supported sites
Reads the page to find images and video, and fetches those files from inside the page so the site's cookies and referrer are attached. Media servers reject requests without them. These nine are listed one by one in the extension's manifest rather than as a blanket request, which is why the install prompt names them individually.
Google Images specifically
Google runs search, Maps, Gmail and everything else from the same address, so access to the host would in principle mean access to all of them. Grabbit checks that you are actually on an image-search results page before it does anything at all. On any other Google page it stays switched off, and reads nothing.

third parties

None. No data is sold, shared, or transferred to anyone, because none is collected. There are no third-party libraries, no CDN calls, and no remotely hosted code in the extension.

children

Grabbit is not directed at children under 13 and collects no data from anyone, of any age.

changes

If this policy ever changes, the updated date above changes with it, and the change ships alongside the extension version that caused it.

contact

Questions about this policy: