Privacy Policy

Last updated September 4, 2026.

AppCaddy makes small browser tools. This policy explains what each one does and does not do with your data. It covers the AppCaddy suite and the standalone tools: NoBait, QuickerTicker, MeetMark, WhichCard, WatchPost, PagePulse, and LinkLasso, plus CardClip and CookieCall, which ship switched off while they are in development.

The short version

What each tool does with data

PagePulse

Runs entirely in your browser. Your interval settings and each tab's timer state are stored locally. The only network request is the optional feedback form (see Feedback reports below).

MeetMark

Runs entirely in your browser. Screenshots, page text, and transcripts are read and built on your device and saved where you choose. There are no external calls for the capture or export itself. Your preferences are stored locally. The only network request is the optional feedback form (see Feedback reports below); your captured content is never sent.

WhichCard

WhichCard never sees or stores a full card number. A card is identified only by the SHA-256 hash of the last four or five digits you enter. Your card nicknames, those hashes, and your preferences are stored in your browser's storage. If your browser has settings sync turned on, that data rides your own browser account's sync, the same way your bookmarks do. It does not pass through any AppCaddy server. If you turn on the optional CVV field, that value is stored with your cards and syncs the same way, so enable it only on a browser you alone use. A PIN, if you set one, is stored on your device only and never syncs. The only outbound request is the optional feedback form (see Feedback reports below).

WatchPost

Your monitors, baseline snapshots, and history are stored on your device. Outbound requests go only to the pages you choose to monitor, to any Discord, Slack, webhook, or email relay endpoint you set up yourself, and to the optional feedback form (see Feedback reports below). An exported backup file includes any webhook URL and relay credentials you saved, so keep that file private.

QuickerTicker

Your watchlist and settings are stored locally. To show prices, charts, and news, QuickerTicker fetches data using the ticker symbols on your list from Yahoo Finance, with Stooq as a backup. If you turn on the optional AI move summary, only the ticker symbol and asset name are sent to the AppCaddy summary relay, which returns the text. Your headlines are fetched locally for display and are not sent. If you enter your own Finnhub API key, it is stored locally and sent only to Finnhub.

NoBait

When you hold-click a link, NoBait resolves its redirect chain by fetching the link in your browser, which contacts the same sites you would have opened. When a site blocks direct resolution, NoBait can fall back to public services to find or read the destination: Google News, the Wayback Machine (web.archive.org), archive.today, a reader proxy (r.jina.ai), and a DuckDuckGo search for the same story. In those cases the link's address, and for a search the headline text, is sent to that service. When you turn on the optional AI summary, the extracted article text of the link you hold-clicked is sent to the AppCaddy summary relay, which calls a language model and returns a short answer. NoBait stores only your settings and excluded sites, locally. No API key is stored in the extension.

LinkLasso

LinkLasso runs entirely in your browser. The links you select with a drag, and whatever you chose to do with them, never leave your device: tabs are opened by your browser, a copy goes to your own clipboard, and a bookmark is saved by your browser. Your gesture and action preferences, and a short record of your last selection so the panel can show it, are stored locally. The only outbound request is the optional feedback form (see Feedback reports below).

CardClip and CookieCall

Both ship inside the suite but stay switched off while they are in development. They appear in Preferences marked as in development with no toggle, and none of their code runs, so neither one reads a page, stores anything, or makes any request. This policy will describe each of them before either is switched on.

The AppCaddy suite

The suite runs the tools above inside one extension, and each tool behaves exactly as described. Only the tools you switch on can do anything. Because NoBait can read page content, the suite declares website content data collection to the browser.

Feedback reports

Every tool has an optional Send feedback control. A report contains the short message you type, a diagnostic summary the form shows you in full before you send (recent steps in the tool, recent errors, version, browser), and up to three screenshots if you choose to attach them. It is sent to the AppCaddy feedback service, a Cloudflare worker that files the report as an issue in a private AppCaddy repository. Nothing is sent until you press Send, and reports are rate limited. NoBait's in-tooltip "Report an issue" panel uses the same service.

Third-party services

AppCaddy runs relay workers on Cloudflare for the two optional AI features (NoBait summaries and QuickerTicker summaries). These relays hold the model provider's API key so it never ships in the extension, pass your request to the model provider, and return the result. They are not used to profile you and do not require an account. The public services NoBait may contact to resolve a blocked link (listed above) are operated by their own providers under their own policies.

No ads, offers, or affiliate links

AppCaddy extensions contain no ads, no offers, and no affiliate links, and they make no offer-related network requests. Each tool has a Support button that opens plain links to our donation options and to appcaddy.io/contribute; you can hide the button with its own toggle. There are no referral or affiliate links anywhere in the tools or on this website.

Data you can control

Each tool lets you export a full backup, import one, or wipe all of its data from your browser. Uninstalling a tool removes its local data.

Children

AppCaddy tools are general-purpose utilities and are not directed at children.

Changes

If a tool's data behavior changes, this policy is updated and the date above changes. Where a store requires it, a change to what a tool collects is also disclosed in the extension before it takes effect.

Contact

Questions about this policy: hello@appcaddy.io.