FreeSpace Privacy Policy
Effective and last updated: August 9, 2026
The short version: Your workspaces, tabs, notes, passwords, and backups stay in Chrome on your device unless you explicitly use Chrome Sync. A small hosted service verifies PayPal subscription access and temporary Chrome Web Store reviewer access using opaque installation identifiers and minimal entitlement records. FreeSpace does not include analytics, advertising, tracking scripts, or remote code.
What FreeSpace handles
To provide workspace features, FreeSpace handles browser-provided tab URLs, domains, titles, favicons, pinned and active state, discarded state, window membership, and Chrome tab-group names, colors, and collapsed state. It also handles recently closed tab and window entries when you use session recovery.
Workspace names, notes, custom tab titles, assigned tab colors, preferences, and backup files are information you create or choose inside FreeSpace. To place a custom title on a compatible live Chrome tab, FreeSpace asks for optional access to that site and injects a local script that only sets and observes the page's <title> element. It does not read webpage bodies, form fields, messages, passwords entered on websites, account data, or network traffic. Chrome Web Store and browser-internal pages cannot be modified.
When you select open tabs in the side panel, FreeSpace temporarily keeps each selected Chrome tab identifier, expected URL, and expected window identifier so it can revalidate the selection locally. The destination must be an unlocked workspace that is not open in a Chrome window. Save copies leaves source tabs open. Move & close persists newly saved records before closing only those newly saved source tabs. Tabs that changed, closed, or were already present in the destination are skipped and are not closed by the operation.
Where information is stored
FreeSpace stores its library and preferences in Chrome extension storage on your device. Workspace names, tab URLs and titles, notes, groups, colors, password material, and backups are not sent to the FreeSpace entitlement service.
If you explicitly enable Chrome Sync, FreeSpace copies a compressed backup through the signed-in Chrome profile's chrome.storage.sync area. Chrome Sync is optional and off by default. Google's handling of synced data is governed by your Chrome and Google account settings and Google's policies.
Password-protected workspaces
You may protect an individual workspace with a password. FreeSpace derives a 256-bit encryption key from that password using PBKDF2 with SHA-256 and a unique random salt, then encrypts the workspace's saved tabs and notes using AES-GCM. The password is never stored or transmitted. The derived key is kept only in Chrome's in-memory session storage while the workspace is unlocked and is removed when you lock the workspace or the browser session ends.
The workspace name, color, modified time, lock status, and saved-tab count remain visible so you can identify a locked workspace. Browser tabs already open in Chrome are outside the encrypted record; locking FreeSpace does not close or conceal those tabs.
There is no password recovery. If you forget the password, FreeSpace cannot decrypt or recover the protected workspace's saved tabs and notes.
Portable exports and imports
FreeSpace creates a JSON file only after you choose an export action. A full backup includes workspaces and supported preferences; a settings-only backup excludes workspaces and browsing data. Both formats exclude Workspace Trash. Protected workspace contents remain encrypted in full exports. Exported files remain under your control.
Import reads only the FreeSpace JSON file you select. A settings-only import does not silently enable Chrome Sync. Window-to-workspace bindings are device-specific and are not included in portable backups. Subscription activation tokens, recovery codes, reviewer codes, and signed access leases are also excluded; raw recovery and reviewer codes are never stored by the extension.
Subscription, reviewer access, and entitlement information
Where production checkout is enabled, FreeSpace uses PayPal for an eligible 30-day trial followed by a recurring $1.99 USD monthly subscription. Checkout is available to United States residents only. Each Chrome profile creates a random 256-bit activation token on your device. The hosted service stores only a one-way SHA-256 hash of that token, not the token itself. One subscription may have up to three non-revoked Chrome profile activations.
Checkout uses a two-phase quote-and-start contract before a PayPal approval page is opened. FreeSpace first requests the currently enabled region choices. Before you request a quote, FreeSpace discloses that the hosted service will compare your selected region with the network-derived country, region code, and postal-code classification supplied to the request by the hosting provider under the configured regional policy. A successful quote shows the selected region label, trial or restart status, USD base price, inclusive or exclusive tax treatment, tax rate and amount, exact recurring total, amount due immediately, plan, disclosure, and expiry. You must accept those exact terms. The separate start request then rechecks the policy, location decision, eligibility, expiry, plan, and accepted disclosure before asking PayPal to create a subscription. Unsupported, unavailable, ambiguous, changed, or unaccepted decisions fail before provider action. Expiry blocks every new provider create or reseed; if an exact create was already attempted, the service may reconcile only that original provider result after expiry and never authorize another mutation.
The checkout record contains the selected regional profile and human-readable region label; regional-policy and adapter identifiers; the quoted plan, trial, base-price, tax, recurring-total, due-now, and disclosure fields; one-way activation hashes; a random decision identifier; creation and expiry times; and, after a successful start, its subscription binding. FreeSpace does not store the raw hosting-provider country, region, or postal-code values, a postal address or postcode, or a raw IP address in checkout records. Regional selections and checkout decisions are not copied to Chrome Sync or included in portable workspace or settings exports.
To verify access, the service also stores the PayPal subscription and plan identifiers, normalized subscription status, opaque device identifiers, device creation and last-use timestamps, trial and billing timestamps, entitlement-lease timestamps, and minimal webhook identifiers needed for replay protection. It does not intentionally store PayPal payer names, email addresses, postal addresses, full webhook bodies, card or bank information, browser fingerprints, device names, or workspace content. PayPal processes payment credentials and executes an accepted subscription under its own privacy policy. PayPal is the payment processor, not FreeSpace's tax-determination engine; Amma Software LLC remains the seller and configures the regional and tax treatment.
The extension periodically sends its activation token directly to the FreeSpace HTTPS entitlement endpoint in a JSON request body. The service hashes it for lookup and returns a short-lived digitally signed access lease. The raw token is not placed in URLs, Chrome Sync, portable exports, or the hosted database.
If you choose to create a subscription recovery code, FreeSpace generates 256 random bits locally and shows the code only for you to save. The extension sends only the new code's SHA-256 hash while configuring or rotating recovery. During a recovery, the old raw code is sent once in an HTTPS JSON body as proof, compared with the stored hash, and not retained. A successful recovery immediately replaces the stored recovery hash. FreeSpace cannot display or reset a lost recovery code.
For Chrome Web Store review only, the publisher may issue a one-time, high-entropy confidential reviewer code. An offline issuance helper displays the raw code once to the publisher for entry in the Chrome Web Store's confidential reviewer notes. The reviewer submits it over HTTPS. The extension and hosted service do not retain the raw code, write it to application request logs, or place it in Chrome storage, Chrome Sync, portable exports, or the hosted database. The service stores only the code's SHA-256 hash, an opaque installation-activation binding, environment, grant status, expiry, audit timestamps, and short-lived signed-lease records. A grant lasts no more than 14 days and returns a signed lease labeled Review access.
Review access does not create a PayPal subscription, contact PayPal, or send workspace or payment data. Codes are supplied only to authorized reviewers through the Chrome Web Store's confidential reviewer notes; they are not public credentials, promotions, or a packaged entitlement bypass. When Review access expires, productive features pause while local read, unlock, export, delete, and Workspace Trash restoration capabilities remain available.
To reduce automated abuse, the hosted service may keep short-lived counters keyed by a secret-keyed, pseudonymous representation of the network address supplied by the hosting provider. It does not store the plain address in the application database or use the counters for advertising, profiling, or workspace analytics.
Data sharing and sale
FreeSpace does not sell user data, share it with advertisers or data brokers, use it for personalized advertising, use it to determine creditworthiness, or use it for any purpose unrelated to operating the extension, qualifying regional checkout, administering subscriptions, and verifying temporary reviewer access. PayPal and the hosting provider process the limited data needed to provide payment, regional qualification, and entitlement services. No FreeSpace employee or contractor reviews user workspace data.
Retention and deletion
Deleting one or several workspaces creates a SHA-256 integrity-sealed operation in local Workspace Trash. The integrity seal detects changes; it does not encrypt a workspace that was unprotected when deleted. Trash retains an operation for up to 30 days and keeps at most the 50 most recent deletion operations; expired operations and older operations beyond that limit are removed. You can use the immediate Undo action or Recovery to restore an intact operation even without productive subscription access. A failed integrity check blocks restoration. Delete forever and Empty Trash permanently remove the selected local records after explicit confirmation.
A Trash operation contains the deleted workspace records and their associated local snapshots. A protected workspace remains AES-GCM ciphertext in Trash, its in-memory key is removed on deletion, and it restores locked. Trash is device-local and is excluded from Chrome Sync and portable exports. Before applying a deletion, FreeSpace clears the previous Chrome Sync backup so a stale synced copy cannot silently restore the deleted workspace. If entitled Sync remains enabled, its replacement backup contains the current library but still excludes Trash.
Other local data remains in Chrome extension storage until it is replaced through import, extension storage is cleared, or FreeSpace is uninstalled. Enabling password protection removes older unencrypted rolling backups for that workspace, and FreeSpace does not create plaintext rolling backups for a protected workspace.
Portable exports remain wherever you saved them until you delete them. Chrome Sync copies are managed through the signed-in Chrome profile and Chrome's synchronization behavior.
An unbound checkout quote expires after 15 minutes and becomes eligible for best-effort routine deletion after expiry when no subscription start is pending. A decision bound to a subscription may remain with the related billing and entitlement records for administration, disputes, compliance, and legal obligations. Other billing, device, and subscription-entitlement records are retained only as long as reasonably necessary to administer access, resolve payment disputes, prevent abuse, provide support, and meet legal obligations. A reviewer grant expires no later than 14 days after issuance. Its reviewer-access record, code hash, activation binding, and related lease-audit records become eligible for deletion 30 days after the grant expires or is revoked and are deleted during the next successful routine cleanup triggered by service activity. Active grants are never deleted by cleanup. Short-lived abuse counters expire automatically. A device activation can be revoked so no new lease is issued. Contact support for a hosted-data deletion request; some transaction-related records may need to be retained where law or PayPal requirements apply.
Children
FreeSpace is a general productivity tool and is not directed to children. The developer does not knowingly collect children's personal information.
Policy changes
If FreeSpace's data practices materially change, this policy and the Chrome Web Store disclosures will be updated before the changed behavior is released. The effective date at the top identifies the current version.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact
Privacy or support questions can be sent to amma.software.llc@gmail.com.