Villow browser extension — Privacy Policy

Last updated: 8 September 2026

This policy covers the Villow browser extension. Villow the web application has its own policy, which covers the Google account authorization and everything stored on your instance.


The short version

The extension sends data to one place: the Villow instance whose address you typed in yourself. It has no server of its own, contacts no analytics service, and contacts no third party of any kind. Before you connect it to an instance, it sends nothing anywhere at all.

You can also choose, during setup, to run it without a Villow instance. In that mode there is nowhere for anything to go, and nothing is sent anywhere, ever. Everything below about sending applies only once you have connected one.

We do not run any central server the extension reports to. It sends only to the instance you connect it to. If you self-host, your data never reaches us. If you connect an instance we operate — for example a trial or review instance — that instance receives what is described below, and it is covered by Villow's own privacy policy.


What the extension collects, and why

Sent to your Villow instance

Videos you click on YouTube. When you click a video tile while blocking is on and the extension is connected, it reads what is already visible on that tile and sends it to your instance so the video can enter your queue:

This is the extension's core function. Nothing is sent for videos you do not click, and nothing is sent when the extension is disconnected.

Legacy screen-time fallback. The extension sends a daily screen-time total to /api/screen-time only when a Villow instance does not support the current usage endpoint and answers 404 or 501 to /api/extension-usage. The fallback remains in use for 24 hours after that response. Current Villow instances do not receive these fallback requests. Time accrues only while a YouTube tab is focused and visible.

Your pairing token, on every request, as proof the request is yours.

Received from your Villow instance

Your subscribed channel list, if the "hide subscribed channels" option is on. The extension cannot ask YouTube for this and holds no Google credentials — it asks your Villow instance, which already has it. The list is cached in your browser and refreshed every few hours.

This cache is deleted on the next rejected request. If your Villow instance answers a request with 401 or 403, the extension deletes its local copy of the list. An offline browser keeps the cache until it next attempts a request and receives one of those responses. Pressing Disconnect deletes it immediately.

Stored locally in your browser

Kept only in your browser and never transmitted

Sent to your Villow instance, and nowhere else

Your daily limit on videos watched, and the count against it, are not among these. They describe a browser that has no Villow, so there would be nothing for them to mean at the other end.

The daily statistics and limits sent to /api/extension-usage are counts and settings. They carry no video ids, no channel names, and nothing about what you looked at — a number of seconds and a number of videos, per calendar day. They are sent at most once every ten minutes and only when something has changed, plus once after midnight to close off the day. Saved videos are different: they include the identifying details needed to save the video.

Cross-browser daily limits. While a YouTube tab is focused, the extension sends a request to /api/extension-day at most once a minute. It contains today's date, a random install identifier, three contributed counts — recommendations seen, active seconds, and external saves — and your current limit settings. This lets your instance add up one account's day across multiple browsers, so, for example, a limit of five saves stays five rather than becoming ten across two browsers.

The random install identifier is generated locally for this browser profile. It keeps contributions from two browsers apart so they can be added rather than overwriting each other. It is a random value; it is not derived from your device, and it is not a fingerprint.

With both /api/extension-usage and /api/extension-day, the extension also sends your browser's configured time zone (for example, Australia/Brisbane), extension version, and browser name. The time zone assigns totals to the correct calendar day. It is a browser setting, not GPS or precise location.

Your limits travel one way. The extension is the only thing that can change a limit; there is no endpoint by which Villow could set one.


What the extension never does


Where your data goes and who can see it

To your Villow instance, over HTTPS, and nowhere else. If you self-host Villow, you are responsible for who can access that server; access depends on your hosting provider and server configuration. The extension does not choose that destination — you do, by pasting in your own connect link.


Retention and deletion

In your browser: removing the extension deletes everything it stored. You can also clear it at any time without uninstalling:

On your Villow instance: deletion is handled there, under Villow's own privacy policy. Deleting data on your instance, or revoking access, also causes the extension to discard its local copy of anything derived from it.


Children

The extension is not directed at children under 13 and does not knowingly collect their data.


Limited Use

Villow's handling of user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.


Changes

If the extension's data handling changes, this policy will be updated and the change described in the extension's release notes before the new version collects anything new.


Contact

Contact: nuciforan+villow@hotmail.com


Villow is not affiliated with, endorsed by, or sponsored by YouTube or Google. YouTube is a trademark of Google LLC.