The short version
Pluck stores its working data in your browser. Licensing contacts Lemon Squeezy, and a trial-start marker can sync through Chrome. It contacts the sites and services you configure. Optional cloud AI sends selected source content to your chosen provider after consent. This showcase has no analytics, advertising scripts, or account system.
1. Overview
Pluck is a Chrome extension by Built by Kris. It reads a source value, performs a configured website or webhook lookup, and makes returned values available for dragging or filling into a page. This policy describes the data behavior of version 0.2.0.
The extension does not include a Built by Kris data-collection server, advertising SDK, or analytics tracker. Data can still leave your browser as part of the lookups, API requests, optional AI features you configure, or Pro license activation and validation.
2. What is stored in your browser
Pluck uses Chrome’s local extension storage for configuration and working data. The trial-start timestamp is an exception: it is also written to Chrome sync storage when available, so a used trial can be recognized across browsers signed into the same Google account. Some temporary state uses session storage, and sidebar display preferences use local browser storage.
| Data | Purpose and retention |
|---|---|
| Profiles and settings | Source sites, selectors, lookup URLs, field mappings, request configuration, themes, and AI preferences are retained until you change or remove them. |
| Inputs and current results | Manually entered values and extracted results are stored to support the sidebar and reuse. Kept cards remain until removed. |
| Result history | New successful runs retain the last 5 result histories on Free or 30 on Pro, including returned values and any associated AI evidence. History is enabled by default and can be disabled or cleared. |
| Run log | Up to 50 recent runs, with profile names, timing, statuses, errors, step details, and, where used, AI token usage. Logs can contain input snippets and lookup URLs; they do not intentionally store entire AI source documents. |
| Batch results | The batch table, including inputs, returned values, and errors, remains until cleared or replaced. |
| Credentials and model lists | AI API keys, webhook authentication values, and cached model lists are stored locally. Local storage is not a dedicated encrypted secret vault. |
| License and trial | The license key and activation/status metadata are stored locally. A trial-start timestamp is stored locally and, when available, in Chrome sync. It is retained to enforce the one-time trial. |
| Temporary state | Pending auto-run prompts and identifiers of lookup tabs are held in session storage. Sidebar tab and filter preferences are remembered locally. |
3. When information leaves your browser
Website lookups
A profile can open a website, include the source value in its URL, type values into fields, click controls, and read results. The destination website receives the resulting requests and interactions. A website opened in Chrome may use your existing signed-in session and its own cookies.
Webhooks and APIs
A webhook receives the configured URL, source value, query parameters, headers, authentication values, and request body. Test requests in Settings also send real requests. Webhook requests omit browser cookies, but explicitly configured authentication is still sent. Receiving services apply their own policies.
Optional AI extraction
If a profile uses AI extraction or an AI fallback, Pluck can send page text or a selected region, or the webhook response, along with the reference value, field descriptions, and instructions, to your configured provider. Supported connections include Ollama, Anthropic, OpenAI or a compatible endpoint, and OpenRouter.
Cloud extraction requires consent for the profile. The AI setup helpers separately ask for acknowledgement before sending page element descriptions or response content to a cloud provider. Connecting a provider to load models also contacts that provider. AI API keys are used to authenticate these requests.
Ollama’s default address is on your computer. Processing stays local only when the configured server is local; if you change it to a remote server, that server receives the requests. Cloud and remote services may retain or process data under their own terms. Pluck does not control their retention.
You can preview the page text for extraction in Settings. Evidence badges indicate whether a quote or value appears in source content, not a guarantee of accuracy.
Pro checkout and license checks
Pro checkout takes place on Lemon Squeezy. Information you enter there is handled by Lemon Squeezy under its own terms and privacy practices. This static website does not collect payment details or activate a subscription.
Activating a license sends the license key and a generated device label to Lemon Squeezy’s license API. The label includes the browser/platform description and a short random suffix. Validation and deactivation send the license key and activation instance identifier. These licensing requests do not include your scraped page content or lookup results.
The extension stores the returned license status, activation instance ID and name, product/variant names, device allowance and usage, expiration if supplied, and last validation time locally. It attempts to recheck an activated license after seven days when server access is permitted. If it cannot validate, the current implementation allows up to fourteen days from the last successful validation before Pro access becomes stale; an expired license is handled separately.
Deactivating this device contacts Lemon Squeezy to release its activation and then removes the local license record. It does not by itself cancel a subscription. Simply uninstalling the extension does not call the deactivation API.
Exports and the clipboard
Exported configuration and CSV files are saved where you choose. Copying a batch table places its contents on your system clipboard. Files and clipboard content can be accessed by other applications or people with access to them.
AI API keys are excluded from configuration exports. Dedicated webhook authentication values are blanked by default unless you choose to include them. Other text you put in URLs, query parameters, request bodies, or profile instructions may still be exported, so review files before sharing.
4. Browser permissions
Side panel displays Pluck beside your page. Storage saves configuration and results. Scripting performs the page operations your workflows require.
Website access is optional and requested for the sites and provider endpoints you use. On authorized sites, Pluck can inject its drag-and-drop support and read or interact with page elements for configured workflows. Remove site access under Settings → Sites to revoke the permission.
Automatic lookup requires Pro or an active Pro trial and is enabled per profile. It uses matching pages and a trigger element. By default, automatic mode asks you before running. Unattended runs require a separate setting, an active tab, and the necessary granted permissions.
5. Your controls
- Remove profiles and revoke site access in Settings.
- Clear current result cards, including any kept cards you no longer need.
- Disable future result history or clear existing history under General. Turning history off does not by itself delete prior entries.
- Clear the saved batch table under General and clear diagnostic entries under Run log.
- Remove saved API keys or webhook authentication values in their configuration fields.
- Disable AI fields and fallbacks or withdraw a profile’s cloud consent to stop future cloud extraction for it.
- Pause automatic mode globally or disable it for individual profiles.
- Deactivate your license from Settings → License before uninstalling if you want to release the device activation. Uninstalling removes extension-managed local data, but does not automatically deactivate the license or cancel billing. The trial marker may remain in Chrome sync and be restored after reinstalling. Previously exported files, billing records, and data already received by services must be managed separately.
Use your browser and device’s access controls to protect locally stored information. Only configure destinations you trust with the content your workflow sends.
6. This showcase website
The static website at pluck.builtbykris.com contains no analytics, advertising trackers, third-party font requests, newsletter forms, or login system. Its fonts and images are served with the website.
The interactive demo uses fictional data. Values entered in the demo exist only in the current page’s memory and are not sent or saved by the website. Reloading resets the demo.
The hosting and network providers necessarily receive connection information, such as your IP address, requested URL, and browser request headers, when serving pages. Any server access logs are governed by the hosting configuration and provider; this static site does not set their retention. External links take you to websites with their own privacy practices.
7. Changes and questions
This policy will be updated when Pluck’s data practices change. The effective date above identifies the current version.
For information about the maker and available contact channels, visit Built by Kris. For billing and licensing records, refer to Lemon Squeezy. For data already sent to a configured website, webhook, or AI service, contact that service directly about its handling and deletion options.