Nothing leaves your browser.
JarFlip is a cookie editor. Cookies are sensitive, so the extension is built to be unable to send them anywhere — and this page says exactly what that means.
Last updated October 8, 2026
The extension
- No network access. The extension’s content security policy sets
connect-src 'none', so the browser blocks every request it might attempt. Our build checks fail if network code appears in the extension. - No accounts, no servers. JarFlip has no sign-in, no sync and no backend. We never receive your cookies, jars, settings or usage.
- No analytics or crash reporting. There is nothing to opt out of.
- No ads or affiliate links. Never.
What is stored on your device
Everything below lives in the browser’s local extension storage and is deleted when you uninstall the extension.
| Data | Why |
|---|---|
| Jars (saved cookie sets) | So you can flip between signed-in states. You create them; you can rename, export and delete them. |
| Settings | Switches such as “reload the tab after a flip”. |
| Onboarding answers | Optional name, role and first site, used to personalise tips. Stays local. |
| Short-lived undo snapshot | Held in memory for 10 seconds after a flip or delete so you can undo. Not written to disk. |
| Recovery journal | While a flip, delete or import is running, a copy of the site’s current cookies is written to local storage so the browser can be put back if it is interrupted. It is removed when the operation finishes. |
Jars contain live session cookies, and JarFlip does not encrypt them on disk. They sit in the extension’s local storage next to the rest of your browser profile (an optional passphrase lock is planned). Anyone with access to your browser profile or an exported file can use them. Treat exports like passwords, and prefer the encrypted export when you share a file.
Permissions
cookies— read and write cookies, but only on sites you allow.storage— keep jars and settings on this device.activeTab— know which site the current tab is on.sidePanel— show the side panel (Chromium browsers).- Site access is optional. No website permission is granted at install. You approve each site when you first use JarFlip there, and you can revoke it from the dashboard or the browser’s extension settings at any time.
This website
The website is static pages. It sets no cookies, loads no third-party scripts, fonts or trackers, and has no analytics. Like most web servers, ours may keep standard request logs (IP address, time, page requested) for security and troubleshooting; we don’t use them to profile visitors and don’t share them.
Sharing files
When you export a jar, the file is created on your device and saved by your browser. If you encrypt it, it uses AES-GCM with a key derived from your passphrase (PBKDF2-SHA256); we cannot recover a forgotten passphrase. Where you send the file is up to you.
Changes and contact
If this policy changes, we’ll update the date above and describe the change. Questions: support@pointerapps.net — PointerApps.