Legal
Privacy Policy
Effective 7 September 2026 · Applies to all CyberFenix browser extensions and to this website.
The short version. Our extensions do their work inside your own browser. We operate no server that receives your data, we collect no analytics, and we have no way to read your email, your viewing habits, or anything else you do. The only network requests our extensions make are licence checks to our payment provider (Gmail Bulk Extractor) and requests for public channel feeds and channel details on youtube.com (LocalTube). Neither carries your personal content.
1. Who we are
CyberFenix builds browser extensions, currently distributed through the Chrome Web Store. In this policy, "we" and "our" refer to CyberFenix, and "the extension" refers to any CyberFenix browser extension you have installed.
2. What each extension can access
Gmail Bulk Extractor
Runs on mail.google.com and works with the Gmail session you are already
signed into. When you select messages and choose an action, it reads the content and
attachments of those messages so that it can convert them into files.
That processing happens entirely on your device. The message content is held in browser memory only for as long as the export takes, then written to the download location you have configured in your browser. It is never sent to us or to any third party.
LocalTube
Runs on www.youtube.com. It adds its own follow, like and save controls
to the page, and can replace the YouTube homepage grid with a list built from the
channels you have followed inside the extension.
LocalTube does not read your YouTube account. It does not access your real subscriptions, YouTube's own watch history, or any signed-in state, and it works the same whether you are signed in or not. The lists it builds are its own, created by you, and stored only in this browser.
Neither extension uses Google OAuth, requests any Google API scopes, or has access to your Google account credentials.
3. What is stored on your device
Each extension keeps data in your browser's local extension storage
(chrome.storage.local). This never leaves your machine and is removed when
you uninstall the extension.
Gmail Bulk Extractor
| Stored item | What it is |
|---|---|
| Usage counter | A count of emails processed in the current seven-day window, and the timestamp that window began. Used to apply the free-tier allowance. |
| Preferences | Your file and folder naming templates, if you have set any. |
| Licence state | A cached record of whether your Pro licence or trial is active, supplied by our payment provider. |
No email addresses, subjects, message bodies, attachments, or file names are recorded in this storage.
LocalTube
| Stored item | What it is |
|---|---|
| Followed channels | The channel IDs and names you chose to follow, and when you added them. |
| Playlists | Your playlists, including Watch Later and Liked, and the videos you saved to them. |
| Watch history | The last 500 videos you watched on YouTube for more than ten seconds while the extension was active — title, channel and when you watched it. Recorded only while the history setting is on, which you can switch off in the extension popup, and clearable in one click from LocalTube's History page. This is LocalTube's own list; it is not read from, and never sent to, your YouTube account. |
| Preferences | Whether the LocalTube feed replaces the YouTube homepage, whether watch history is recorded, and how often channel feeds refresh. |
| Feed cache | A short-lived copy of the public channel feeds already fetched, so the page does not re-request them on every visit. It is never included in a backup export and can be discarded at any time. |
This is the data your backup export contains. It is written only when you press Export, saved by your own browser to your own download folder, and never sent anywhere.
4. What leaves your device
Neither extension sends anything to a CyberFenix server, because there isn't one. Their outbound requests are these, and only these.
LocalTube: YouTube's own endpoints
To build your feed, LocalTube requests the public upload feed of each channel you
follow, directly from www.youtube.com/feeds/videos.xml. These are the same
public feeds any RSS reader can subscribe to.
For channel details — the avatar, @handle and subscriber count of a
channel you follow — LocalTube calls YouTube's own internal endpoint
(www.youtube.com/youtubei/v1/browse), the same one the youtube.com page you
are on uses to render a channel. These calls are spaced out, made only for channels you
follow, and each answer is kept so it is never asked again.
It can also ask YouTube's public oEmbed endpoint
(www.youtube.com/oembed) for the @handle of a channel you
follow whose handle it does not know, so your subscriptions list can name channels the
way YouTube does. That request names one public video of that channel and nothing else.
All of these requests go to www.youtube.com and are sent
without cookies, so they are not associated with any YouTube account,
and they contain nothing but the channel or video being asked about. They are made only
when you are on youtube.com with the extension active. LocalTube makes no other network
request of any kind, to us or to anyone.
Gmail Bulk Extractor: licence checks
Gmail Bulk Extractor makes network requests to exactly one external service:
ExtensionPay (extensionpay.com), which handles licensing and
payment on our behalf and uses Stripe as its payment processor.
These requests occur when the extension checks whether your licence is active, when you start a trial, and when you open the checkout, login, or subscription-management pages. They carry an anonymous installation identifier and, if you have purchased, the email address associated with your licence. They never contain email content, subjects, sender or recipient addresses, attachments, or usage details.
If you choose to buy Pro, your email address and payment details are collected and processed by ExtensionPay and Stripe under their own privacy policies. We never see or store your card details. From the ExtensionPay dashboard we can see the email address on a licence and whether it is active — nothing else.
5. What we do not do
- We do not collect analytics or telemetry of any kind.
- We do not use tracking pixels, advertising identifiers, or fingerprinting.
- We do not sell, rent, or share personal information with anyone.
- We do not build user profiles, and we do not use your data to train models.
- We do not transmit, store, or have any means of accessing your email.
- We do not receive, log, or have any means of seeing which channels you follow or which videos you watch or save.
6. Browser permissions, and why each is needed
Chrome asks you to approve a set of permissions at install. Each one exists for a specific technical reason.
Gmail Bulk Extractor
| Permission | Why it is required |
|---|---|
debugger | Chrome exposes proper PDF rendering only through the DevTools Protocol. The extension uses this for a single Page.printToPDF call on a tab it opened itself. This is why Chrome shows a "started debugging this browser" banner during an export. |
downloads | To save the PDFs, attachments and archives it produces. |
storage | To keep the local data listed in section 3. |
scripting, tabs, activeTab | To add the toolbar to Gmail and to render the print view used for PDF output. |
Access to mail.google.com | To read the messages you select, using the session you are already signed into. |
Access to extensionpay.com | To check and activate your licence. No email data is involved. |
The extension requests no host permissions beyond those two domains, and cannot operate on any other site.
LocalTube
| Permission | Why it is required |
|---|---|
storage | To keep the local data listed in section 3 — your follows, playlists and preferences. |
Access to www.youtube.com | To add its controls to YouTube pages, and to fetch the channel data described in section 4. |
That is the entire permission list. LocalTube requests no downloads,
tabs, scripting or debugger permission, and cannot
operate on any site other than YouTube.
7. This website
This site is a set of static pages hosted on GitHub Pages. It sets no cookies, runs no analytics, and loads no third-party scripts, fonts, or trackers — every file it serves comes from this domain. GitHub may record standard server access logs, including IP addresses, as described in the GitHub Privacy Statement.
8. Your rights and choices
Because we hold almost nothing, there is very little to request. You can:
- Delete local data — uninstalling the extension removes everything it stored in your browser.
- Access or delete licence data — email us and we will retrieve or delete the record held for your licence, subject to any records ExtensionPay or Stripe must keep for tax and accounting purposes.
- Use the extension without giving us anything — the free tier requires no account, no email address, and no payment.
If you are in the EEA or UK, our lawful basis for processing licence data is the performance of a contract with you; we process no other personal data.
9. Children
Our extensions are general-purpose productivity tools and are not directed at children under 13. We do not knowingly collect personal information from children.
10. Data breaches
We hold no database of user content that could be breached. Should a security issue affect licence records held by our payment provider, we will publish a notice on this site and notify affected licence holders by email.
11. Changes to this policy
If this policy changes materially, we will update the effective date at the top of this page and note the change on our GitHub repository. Continued use of the extension after a change constitutes acceptance of the revised policy.
12. Contact
Questions about privacy, or a request under section 8: cyberfenix.dev@gmail.com. You can also open an issue on the GitHub repository for Gmail Bulk Extractor or LocalTube.
Verify it yourself. Both extensions are open source under the MIT licence. Every claim on this page can be checked against the published source code for Gmail Bulk Extractor and LocalTube.