Emojery collects the minimum needed to make a reaction count. Full policy: https://emojery.app/privacy (effective 24 August 2026).
WHAT LEAVES YOUR BROWSER
- To show counts, the public target keys of supported items on the page, before you react. The count lookup itself is anonymous; while you are signed in, a second request asks which of those items you have already reacted to and carries your session token.
- The reactions you submit, with the canonical URL and the public identifier of the item you reacted to.
- Your email address at sign-in, transiently: sent over TLS, used once to deliver a 6-digit code, then discarded. What remains as your account identifier is a one-way keyed hash of it.
- A session token, a random installation identifier that lasts as long as the installation, and a session identifier that rotates every 24 hours.
- A bug report, only when you send one from the Report tab: your note, the page it is about, and, while Community insights is on, the browser's user-agent string and the extension version.
- With the optional "Community insights" setting on: coarse country/city, language, browser and OS alongside a reaction.
WHAT IS NEVER COLLECTED
Real names, stored email addresses, hardware or high-entropy fingerprints, advertising cookies or tracking pixels, and passwords. Raw IP addresses are never stored: the network layer sees your address the way any web server does, and what the service keeps is a salted hash that rotates daily and is used to rate-limit abuse. The extension loads no analytics SDK.
STORAGE AND RETENTION
Sign-in code: 10 minutes or until used. Session token: 30 days, in extension storage. Account record and active reactions: until you delete them. Aggregate per-item counts: indefinitely. Public transparency-log entries: permanent and append-only, so a deletion is recorded as a public revocation rather than an erasure.
WHERE YOUR REACTIONS LIVE
Your device keeps the browsable history, including page titles, in the browser's IndexedDB, and it is never uploaded. The service keeps your current reaction per item and the pseudonymous entries in the public log.
SUBPROCESSORS
Cloudflare (infrastructure, bot check, coarse country/city), Neon (managed database, EU or US), Resend (delivery of the one-time code; the address is not retained). The public transparency log is published to GitHub and anchored through Sigstore Rekor and the OpenTimestamps calendars; the entries it carries are pseudonymous. Changes to this list are dated and published before they take effect.
YOUR RIGHTS
Delete your account from the extension's Account tab. This removes your account record and your active reactions, and reverses their contribution to the totals. Pseudonymous log entries and their revocations remain permanent, and a suspended account keeps its email hash so the suspension survives a re-registration. Access, rectification, restriction, portability and objection under GDPR/UK GDPR/CCPA/PIPEDA/PIPA. Contact: privacy@emojery.app