Introduction

Shortcuts Scanner ("the Extension", "we", "our") is a free, open-source Chrome extension that allows users to view, inspect, download, and perform AI-powered security analysis for Apple Shortcuts from iCloud.com. We are committed to protecting your privacy and being transparent about our data practices.

This Privacy Policy explains what information the Extension collects, how it is used, and your rights regarding that information.

Information We Collect

Data Stored Locally on Your Device

The Extension stores the following data locally in your browser:

  1. API Keys (Optional)
    • If you choose to use AI-powered security analysis, you may provide API keys for supported AI providers (OpenAI, Anthropic, OpenRouter)
    • API keys are encrypted using AES-256-GCM encryption with PBKDF2 key derivation (800,000 iterations)
    • Keys are bound to your specific browser installation using device-specific binding
    • Encrypted keys are stored in Chrome's local storage
  2. Model Preferences
    • Your selected AI provider and model preferences
    • Stored in browser localStorage
  3. Analysis Results Cache
    • AI security analysis results are cached locally to avoid redundant API calls
    • Results are keyed by shortcut URL
    • Stored in browser localStorage
    • Can be cleared manually via the Extension interface
  4. Session Settings
    • Session timeout preferences (5-360 minutes)
    • Device binding configuration
    • Stored in browser localStorage

Data We Do NOT Collect

How We Use Your Information

Local Data Usage

Data Transmission

When you use the AI security analysis feature:

  1. Shortcut Content: The content of the shortcut you are analyzing is sent to your selected AI provider (OpenAI, Anthropic, or OpenRouter) for security analysis
  2. API Keys: Your API key is transmitted only to the respective AI provider via secure HTTPS connection
  3. No Developer Transmission: No data is ever sent to the Extension developer or any server we control

Third-Party Services

The Extension integrates with the following third-party services. When you use these services, their respective privacy policies apply:

AI Providers (Optional - Only if you use AI Analysis)

Provider Purpose Privacy Policy
OpenAI AI-powered security analysis openai.com/privacy
Anthropic AI-powered security analysis anthropic.com/privacy
OpenRouter AI-powered security analysis openrouter.ai/privacy

Apple iCloud (Required for Core Functionality)

Service Purpose Privacy Policy
iCloud.com Fetch shortcut data from iCloud apple.com/privacy
Important: We have no control over how these third-party services handle your data. We encourage you to review their privacy policies.

Data Storage and Security

Encryption

Security Measures

Local-Only Storage

All data remains on your device:

Data Retention

Data Type Retention Period How to Delete
Encrypted API Keys Until you manually delete them Settings > Delete API Key
Model Preferences Until you manually clear them Clear browser localStorage
Analysis Results Cache Until you manually clear them Extension interface or clear browser localStorage
Session Settings Until you manually clear them Clear browser localStorage
Cached Shortcuts 2 minutes (auto-expires) Close browser tab

Your Rights

You have full control over your data:

Right to Access

Right to Delete

Right to Portability

Right to Opt-Out

No Account Required

Children's Privacy

The Extension is not directed at children under the age of 13. We do not knowingly collect personal information from children. Since we do not collect any personal information from any users, this policy applies equally to all users regardless of age.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  1. We will update the "Last Updated" date at the top of this policy
  2. We will update the version number
  3. For significant changes, we will update the Extension version

We encourage you to review this Privacy Policy periodically for any changes.

Contact Information

If you have questions about this Privacy Policy or the Extension's data practices:

Additional Information

Open Source

This Extension is open source under the Apache 2.0 License. You can review the complete source code to verify our privacy practices.

Manifest V3 Compliance

The Extension is built on Chrome's Manifest V3 platform, which provides enhanced security and privacy protections including:

Permissions Explanation

Permission Why We Need It
sidePanel Display the inspection interface
activeTab Detect when you're viewing a shortcut on iCloud.com
storage Store encrypted API keys locally
alarms Handle session timeouts
icloud.com/shortcuts/* Read shortcut data from iCloud
icloud-content.com Download shortcut files from iCloud CDN
AI Provider URLs Send shortcuts for AI analysis (optional)