Bump Around
PRIVACY POLICY
Effective date: 26 August 2026
Bump Around helps people discover approved websites and manage those discoveries in Chrome. Its optional Community tools let people vote on approved websites, browse aggregate charts, submit websites for moderation, and report catalogue problems. No account or sign-in is required.
1. INFORMATION STORED BY THE EXTENSION
Bump Around uses Chrome extension storage for the information needed to provide its features.
• Selected topics are stored with chrome.storage.sync. Chrome may synchronize them between browsers where the user has enabled Chrome sync.
• Recent Bump destinations, the previous destination, Likes, blocked sites, Saves, review-reminder state, the last tutorial version shown, Community disclosure state, the installation's own Community vote list, and the random Community installation token are stored with chrome.storage.local.
• A prepared next destination may be held temporarily in chrome.storage.session and disappears when the browser session ends.
Bump Around does not request Chrome's browsing-history permission. It does not read unrelated browsing history, arbitrary browser URLs, page contents, passwords, personal files, emails, or messages.
2. NORMAL DISCOVER REQUESTS
When Bump Around prepares or requests a destination, it sends the following over HTTPS to the Bump Around service hosted on Cloudflare:
• the selected topic or topics, or a topic derived locally from a previous Like; and
• an exclusion list containing up to 250 URLs previously opened or blocked through Bump Around.
The exclusion list is used only to avoid unwanted repeats. The service groups exclusions by hostname when selecting a destination and returns one approved website URL. Bump Around does not send unrelated Chrome history or arbitrary pages the user visits outside the extension.
Likes, Saves, the local Library, and the full local reaction records are not uploaded. A Like may influence which topic is sent in a later Discover request; a blocked Bump URL may be included in the exclusion list.
3. OPTIONAL COMMUNITY ACTIONS
The extension shows a privacy notice before enabling the first Community write action.
PSEUDONYMOUS INSTALLATION TOKEN
Before the first Community vote, submission, or report, the extension creates a random token in chrome.storage.local. The token is not a name, account, email address, advertising identifier, or device fingerprint.
The token is transmitted over HTTPS only with a Community write action. The Community service immediately hashes it with SHA-256. The raw token is not stored in the Community database or forwarded to the moderation system; only its hash is stored or forwarded. The hash is used for duplicate prevention, vote removal, rate limiting, and abuse protection.
COMMUNITY VOTES
For a vote, Bump Around processes the approved website's normalized canonical URL, the hashed installation token, and timestamps. Public leaderboards show website domains, approved category tags, and aggregate vote totals. They do not expose installation tokens or individual voting histories. A vote can be removed by selecting Bumped again.
WEBSITE SUBMISSIONS
For a submission, Bump Around processes the normalized website URL, between one and four selected approved categories, the hashed installation token, the source value community, timestamps, and moderation status. Known tracking parameters are removed before submission. A submitted website never becomes public automatically; it enters a human moderation queue.
REPORTS
For a report, Bump Around processes the approved website URL, one selected report reason, the hashed installation token, timestamps, and moderation status. Reports flag a website for human review and do not remove it automatically.
Reading public Community charts does not require an installation token.
4. TECHNICAL REQUEST DATA
Cloudflare may process normal network and security information, such as an IP address, user agent, request time, and request metadata, when delivering and protecting the service. Bump Around does not use this technical information to build advertising profiles or track people across unrelated websites.
5. HOW INFORMATION IS USED
Bump Around uses the information described above only to:
• return a website matching the chosen discovery signal;
• prevent recently opened or blocked Bump destinations from repeating;
• provide the user's local Library, reactions, previous destination, tutorial, and review reminder;
• prevent duplicate Community votes and allow vote removal;
• calculate public monthly and all-time leaderboards;
• enforce vote, submission, and report limits;
• detect duplicate submissions;
• place submissions and reports into the moderation workflow; and
• investigate abuse, spam, unsafe content, broken links, paywalls, and category errors.
6. SHARING, SERVICE PROVIDERS, AND HUMAN REVIEW
Cloudflare delivers Discover and Community requests and stores Community records in Cloudflare D1. Google Apps Script and Google Sheets receive submitted and reported URLs, their selected categories or report reasons, timestamps, moderation status, and the hashed installation identifier. These services process information only as needed to operate Bump Around.
The developer or an authorized moderator may read submitted and reported URLs and their moderation details to approve catalogue additions, investigate reports, and maintain the approved website list. Individual Community voting histories are not published.
When Bump Around opens an external website, that website receives the normal information involved in a browser visit and applies its own privacy policy. If a user opens the optional Buy Me a Coffee page, payment or account information is handled by Buy Me a Coffee; Bump Around does not receive or store it.
Bump Around does not sell or rent user data. It does not use or transfer data for advertising, cross-site tracking, data-broker activity, credit decisions, or purposes unrelated to its user-facing features, security, abuse prevention, or legal obligations.
7. RETENTION
• Extension data remains in Chrome storage until the user changes or clears it, uninstalls the extension, or Chrome removes it, subject to the user's Chrome sync settings.
• The local Community installation token remains until extension data is cleared, the extension is uninstalled, or the token is otherwise reset.
• An active Community vote remains until the user removes it or the Community service is retired. Removing a vote deletes the vote record; a short-lived rate-limit event may remain for up to 48 hours.
• Community rate-limit events are automatically deleted after approximately 48 hours.
• Community submissions, reports, their hashed installation identifiers, and associated moderation records are retained for no more than 24 months. Automated cleanup runs in the Community service and moderation intake.
• Aggregate leaderboard totals change when votes are removed. Infrastructure backups and technical service logs, if any, expire under the applicable service provider's normal lifecycle.
8. USER CHOICES AND DELETION REQUESTS
Users can remove a Community vote by selecting Bumped again. They can remove local Likes, Saves, and blocked sites inside the extension. Clearing the extension's Chrome storage or uninstalling the extension removes its locally stored information, subject to Chrome sync behavior.
Clearing the local installation token does not by itself identify or delete an earlier submission or report. To request deletion of a submission or report, use the Bump Around feedback form at https://forms.gle/HLfskgNnssJ7t15E6 and write “Privacy deletion request”. Include the submitted website URL, approximate submission or report date, category or report reason, and any other detail needed to locate the record. Requests will be verified and processed unless retention is required for security, abuse prevention, or legal obligations.
9. SECURITY AND CHROME WEB STORE LIMITED USE
Bump Around uses HTTPS, server-side URL and category validation, pseudonymous token hashing, duplicate constraints, rate limits, and a shared secret between the Community service and moderation intake. No system can guarantee absolute security.
Bump Around's use and transfer of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Information is used only to provide or improve user-facing extension features, maintain security, prevent abuse, or comply with legal obligations.
10. CHANGES AND CONTACT
Material changes to this policy will be published with an updated effective date before the corresponding extension release.
Questions or privacy requests can be sent through the Bump Around feedback form at https://forms.gle/HLfskgNnssJ7t15E6 or by email to ciao@editwebagency.com.
Operator: The Polo Lab