Privacy Policy
Updated: September 13, 2026
Ryft LLC operates Tiler. This policy explains how the Tiler Chrome extension handles data. The Ryft website has a separate privacy policy.
1. Bookmarks and productivity data
Tiler reads and changes Chrome bookmarks to display, organize and open them. Folder order, settings, workspaces, scheduled rules, notes, tasks, tile appearance, screenshots and deleted-bookmark recovery data are stored in your browser. Some settings use Chrome Sync; Chrome may synchronize bookmarks and settings according to your browser and Google account configuration.
Tiler does not upload your bookmark tree, screenshots, notes, tasks or local usage statistics to its Firebase billing backend. Exported backup files may contain private settings and tile data; you control where you save or share them.
2. Local statistics and Privacy Mode
Tiler keeps per-bookmark visit counters locally. The Usage Dashboard separately records clicks, bookmark identifiers, domains and active time for tabs opened through Tiler. Dashboard analytics and its time-tracking option are enabled by default and can be disabled in Settings. Navigating an already tracked tab can change the domain attributed to its active time. Turning off Dashboard analytics does not erase existing statistics or disable the separate per-bookmark visit counters.
Dashboard records use the retention period selected in Settings: 30, 90 or 180 days, with 90 days as the default. Old Dashboard records are removed when local data is compacted. The extension does not use Google Analytics or read Chrome's complete browsing-history database.
Privacy Mode masks content on the New Tab page and blocks interaction with concealed controls. It does not encrypt stored data, delete account records, enable Incognito, or stop all network requests.
3. Google sign-in and Pro purchases
Google sign-in is optional for local bookmark organization. When you sign in, Chrome obtains a Google OAuth token and Firebase Authentication exchanges it for an authenticated session. Google/Firebase handles account identifiers and profile information, such as your email address, name and profile image when supplied by your account. Authentication state is cached in your browser.
Tiler links your Firebase user ID to a Stripe customer. Its Firestore backend stores customer and subscription identifiers, plan and entitlement status, expiry and billing-check timestamps. Private checkout attempts and processed-event identifiers support failure recovery and prevent duplicate processing. These are server-side account and billing records operated for Tiler.
Stripe hosts Checkout and the Customer Portal and processes the payment and billing information you enter there. Tiler receives identifiers and payment/subscription status needed to grant, restore or revoke Pro access. Its extension and Firestore schema do not store full card numbers or card security codes. Signing out or uninstalling does not cancel a subscription or delete these records.
4. Website requests and screenshots
Site-hosted favicons are requested from the relevant website. YouTube previews may be requested from i.ytimg.com using the video ID. Those hosts receive ordinary network information, including your IP address and the requested resource.
Screenshot capture loads the selected website in a temporary browser window and saves an image locally after you grant the necessary permission. The website may use your existing browser session and applies its own privacy practices. Screenshots may contain personal information visible on the page. Automatic screenshot refresh repeats these visits when enabled.
5. Permissions
- Bookmarks: display, create, edit, move and remove bookmarks and folders.
- Storage: save settings and extension data locally or through Chrome Sync.
- Tabs and windows: open links and groups, manage capture windows, and measure active time for tracked tabs when enabled.
- Alarms: scheduled opening, screenshot refresh and usage-time updates.
- Identity: Google sign-in for account and Pro features.
- Google API access: authentication, token renewal and account/entitlement data.
- Optional website access: capture supported pages after you grant access. The permission may cover many websites; revoke it through Chrome extension settings if no longer needed.
6. Purposes, providers and safeguards
Data is used for bookmark organization, user-selected productivity features, authentication, purchase administration, access restoration and operational troubleshooting. Tiler does not sell extension data, use it for advertising, or use it to determine creditworthiness.
Google/Firebase and Stripe process information required for their services. Website and image hosts receive the requests described above. Information may also be disclosed when required by applicable law or necessary to protect legal rights. Providers may process data outside your country under their applicable transfer arrangements. See the Google Privacy Policy and Stripe Privacy Policy.
Account and billing communications use HTTPS. Access to server-side account records is restricted; extension clients can read their own account summary and cannot write billing state. Operational logs may include account/event identifiers, request metadata and error details. No security measure eliminates every risk.
Tiler's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
7. Retention and deletion
- Browser data: remains under your control until deleted, replaced or removed with the extension, subject to Chrome Sync behavior. Dashboard retention is described above. Other visit counters do not share the Dashboard's age limit. Local diagnostic logs keep at most 200 entries; there is no age-based expiry for those entries.
- Account and entitlements: retained while needed to operate your account, restore purchases and provide paid access. A valid Lifetime entitlement is not removed merely because you have not signed in recently.
- Checkout recovery and event records: retained for billing recovery, duplicate-event protection, refunds and disputes. The current service does not automatically expire these records; deletion requests are reviewed against those purposes and applicable obligations.
- Payment and tax records: retained for the applicable recordkeeping period. For ordinary US tax records this is generally three years after the relevant return is filed; longer periods can apply to particular records or circumstances. A legal obligation or unresolved dispute may require retaining a limited subset longer.
- Requests to close an account: contact us below. We verify ownership using proportionate information, review retained billing obligations and remove account data no longer needed. We aim to complete eligible deletion within 30 days and respond to privacy-rights requests within one calendar month, or any shorter applicable deadline. If an applicable law permits an extension, we explain it within the initial deadline. We explain any data we must retain and why.
Uninstalling does not delete Chrome bookmarks, downloaded exports, Firebase/Stripe records or every synchronized copy. No automatic account-deletion control is currently provided in the extension; requests are handled by an operator. You can delete bookmarks in Chrome, remove local entries/screenshots, clear Dashboard data and revoke website permissions separately.
8. Your rights
Depending on your location, you may request access, correction, deletion, restriction, objection or portability of your personal data, and withdraw consent where processing relies on it. Withdrawal does not affect earlier lawful processing. You may complain to your competent data-protection authority. California users may exercise applicable rights to know, correct and delete information without unlawful discrimination; Tiler does not sell or share extension data for cross-context behavioral advertising.
Where applicable, we process account and billing information to perform our agreement with you, retain required transaction records to meet legal obligations, and process proportionate operational/security information for legitimate interests. Consent is used where required for optional processing. Installing the extension alone is not treated as blanket consent to unrelated uses. Mandatory consumer and privacy rights remain unaffected.
9. Children and policy changes
Tiler's account and paid services are not directed to children under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
We update this policy when our practices change and show the revision date above. Material changes will be communicated through an appropriate product or website notice, with consent requested where required. We do not treat a policy edit alone as consent to a new unrelated use of data.
10. Contact
Ryft LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.
Email: office@ryftcorp.com. For privacy requests, include “Tiler privacy” in the subject. Do not send passwords, full card numbers or security codes.