SiteSkin Privacy Policy
How the SiteSkin website and extension handle themes, account data, AI prompts, permissions, analytics, and user choices.
Last updated: July 30, 2026
SiteSkin provides a website, AI skin editor, skin library, and browser extension. This policy explains what each part processes and why.
The browser extension
SiteSkin does not sell browsing history and does not require access to every website. The extension requests permission separately for each supported site that you choose to enable.
The extension processes the current supported page locally so it can apply visual styles and built-in focus controls. Installed Skin Manifests, active-skin choices, appearance preferences, signed selector-adapter updates, and selected font and background files are stored in Chrome extension storage on your device. Downloaded appearance files are checked against their published size and SHA-256 hash before use.
The extension downloads the same public official-theme catalog for every user when it is installed or the browser starts, when the popup or Studio needs a missing or stale catalog, and every six hours while Chrome keeps the extension active. Catalog requests do not send an account identifier, browsing history, current page URL, or page content. Installed official themes may be updated automatically when the catalog advertises a newer signed version.
The extension also contacts siteskin.net when you explicitly install a skin from the catalog and may check for signed selector-adapter updates for websites you have enabled. It validates this structured data before storing it locally. It does not download or execute remote JavaScript.
If you explicitly connect a SiteSkin account, the extension stores a restricted device token and the connected account's display name and email address in Chrome local extension storage. The name and email are used only to show which account is connected and are not included in theme-library sync. The token can read and update your theme library and revoke only its own device connection; it cannot change your password, subscription, or billing details. Passwords are entered only on siteskin.net and are never sent to the extension.
Optional sync transfers validated Skin Manifests, active skin and appearance-asset IDs, per-site appearance and focus preferences, version numbers, and timestamps. It does not transfer page content, browsing history, private messages, passwords, or payment information.
The website and accounts
When you create an account, we may store your name, email address, profile image, authentication records, subscription status, support requests, and account settings. Authentication providers may process information under their own policies.
If you upload a background image, SiteSkin stores it as a private account asset so your connected extension and other connected devices can retrieve it. It is not published in the official gallery. You can delete uploaded backgrounds from the appearance page.
Payment details are processed by the payment provider selected at checkout. SiteSkin stores order and subscription records, but does not store complete payment-card numbers.
AI skin generation
The editor sends your target-site choice and theme prompt to the SiteSkin server. If an OpenAI API provider is configured, that prompt is sent to the configured provider to create a restricted design draft. If no provider is configured or the request fails, SiteSkin uses local safe rules instead.
Do not include passwords, private conversations, payment information, or other sensitive page content in a theme prompt. SiteSkin does not need a copy of the target webpage to generate the MVP themes.
Analytics and advertising
siteskin.net may use configured analytics tools and Google AdSense on content and skin-detail pages. These providers may process device, cookie, and interaction data under their own policies. The SiteSkin browser extension does not display ads inside third-party websites.
For official themes, the extension sends anonymous install, activation, and uninstall events containing only the event type, theme ID, supported site ID, theme version, and extension version. These events do not contain an account identifier, IP field, page URL, browsing history, or page content and are used only to measure theme reliability. Optional visual-breakage reports reject page URLs and personal page content.
Security and retention
We use access controls, encryption where configured, structured Manifest validation, and least-privilege extension permissions. No system is completely secure.
SiteSkin's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Chrome API data is used only to provide or improve user-facing website customization features. It is not used or transferred for personalized advertising, creditworthiness, lending, or sale, and it is not made available for humans to read except with affirmative consent for support, for security purposes, to comply with law, or after aggregation and anonymization for internal operations.
Account and transaction records are retained while needed to provide the service, meet legal obligations, resolve disputes, and prevent abuse. Local extension data remains on your device until you remove it or uninstall the extension.
Your choices
You can disable a skin, revoke a site's extension permission, disconnect account sync, revoke a connected device, clear extension storage, stop using AI generation, or request deletion of your SiteSkin account. Some transaction records may need to be retained where required by law.
Children
SiteSkin is not directed to children under 13, or a higher minimum age where local law requires it.
Contact
Questions or privacy requests can be sent to support@siteskin.net.