App Stores

Privacy Policy for Chrome Extensions

The Chrome Web Store requires a privacy policy for any extension that collects or transmits user data, and you must certify your data use in the developer dashboard. Extensions get extra scrutiny because they can access browsing content.

Create My Privacy Policy

Last updated July 8, 2026

Why this affects your privacy policy

Extensions often request broad permissions — reading page content, accessing tabs, or storing data. Google’s program policies require you to disclose what you collect, limit use to the single stated purpose, and provide a privacy policy when handling personal or sensitive user data. The Web Store listing also asks you to declare data practices that must match your policy.

Data typically processed

Data type Details
Web content Page content or form data the extension reads to do its job.
Browsing activity URLs or tab data, if your permissions include them.
User settings Preferences stored locally or synced.
Authentication data Tokens if the extension signs into a service.

What to disclose

  • What data the extension accesses and why, tied to a single clear purpose.
  • Whether data is sent to a remote server or stays on the device.
  • That you do not sell user data or use it for unrelated purposes.
  • The permissions requested and the reason for each.
  • A privacy policy URL entered in the Web Store developer dashboard.

Example wording

What the Extension Accesses. To provide its features, this extension accesses the content of pages you use it on. This data is processed only to deliver the feature you requested and is not sold or used for advertising. Where data must leave your device, we transmit only what is necessary and describe it below. You can remove the extension at any time to stop all data access.

Sample language only — adapt it to your actual data practices.

Best practices

  • Request the narrowest permissions possible; broad host permissions increase review friction.
  • Keep processing on-device where you can, and say so — it’s a strong trust signal.
  • Match your Web Store data-use certification exactly to your written policy.
  • Comply with the Limited Use requirements if you touch Google user data.

Generate a policy that already covers Chrome Extensions and host it at a permanent URL.

Host Your Policy

Frequently asked questions

Does my Chrome extension need a privacy policy?

If it handles personal or sensitive user data — including web content and browsing activity — yes. Google requires a privacy policy and a data-use disclosure for such extensions.

Where do I put the privacy policy URL?

In the Chrome Web Store developer dashboard under your item’s privacy tab. It must be a working, publicly accessible URL.

My extension stores everything locally — do I still need one?

If it accesses personal or sensitive data at all (even locally), a privacy policy is expected. It can simply state that data stays on the device.

Related guides

This guide is for general informational purposes only and is not legal advice. Your privacy policy should reflect your actual data practices and applicable legal requirements, which vary by jurisdiction and platform.

Create and host your privacy policy

Fill out a short form, get a permanent HTTPS URL for your app submission.

Create My Privacy Policy