Privacy

Nothing leaves your browser.

JarFlip is a cookie editor. Cookies are sensitive, so the extension is built to be unable to send them anywhere — and this page says exactly what that means.

Last updated October 8, 2026

The extension

  • No network access. The extension’s content security policy sets connect-src 'none', so the browser blocks every request it might attempt. Our build checks fail if network code appears in the extension.
  • No accounts, no servers. JarFlip has no sign-in, no sync and no backend. We never receive your cookies, jars, settings or usage.
  • No analytics or crash reporting. There is nothing to opt out of.
  • No ads or affiliate links. Never.

What is stored on your device

Everything below lives in the browser’s local extension storage and is deleted when you uninstall the extension.

DataWhy
Jars (saved cookie sets)So you can flip between signed-in states. You create them; you can rename, export and delete them.
SettingsSwitches such as “reload the tab after a flip”.
Onboarding answersOptional name, role and first site, used to personalise tips. Stays local.
Short-lived undo snapshotHeld in memory for 10 seconds after a flip or delete so you can undo. Not written to disk.
Recovery journalWhile a flip, delete or import is running, a copy of the site’s current cookies is written to local storage so the browser can be put back if it is interrupted. It is removed when the operation finishes.

Jars contain live session cookies, and JarFlip does not encrypt them on disk. They sit in the extension’s local storage next to the rest of your browser profile (an optional passphrase lock is planned). Anyone with access to your browser profile or an exported file can use them. Treat exports like passwords, and prefer the encrypted export when you share a file.

Permissions

  • cookies — read and write cookies, but only on sites you allow.
  • storage — keep jars and settings on this device.
  • activeTab — know which site the current tab is on.
  • sidePanel — show the side panel (Chromium browsers).
  • Site access is optional. No website permission is granted at install. You approve each site when you first use JarFlip there, and you can revoke it from the dashboard or the browser’s extension settings at any time.

This website

The website is static pages. It sets no cookies, loads no third-party scripts, fonts or trackers, and has no analytics. Like most web servers, ours may keep standard request logs (IP address, time, page requested) for security and troubleshooting; we don’t use them to profile visitors and don’t share them.

Sharing files

When you export a jar, the file is created on your device and saved by your browser. If you encrypt it, it uses AES-GCM with a key derived from your passphrase (PBKDF2-SHA256); we cannot recover a forgotten passphrase. Where you send the file is up to you.

Changes and contact

If this policy changes, we’ll update the date above and describe the change. Questions: support@pointerapps.net — PointerApps.