EN
NaviCube · Antho
Antho Privacy Policy
1. Local data and purpose
NaviCube, Antho's developer (“we”, “us”), is the personal-information handler for this policy. We describe local processing even where data never leaves your device. Antho keeps workspace pages, categories, link names and URLs, icons, widgets, notes, tasks, appearance, search and export settings, consent records, caches, and task state in extension local storage. Larger images and wallpapers use extension-only IndexedDB.
Only after you choose to import current browser bookmarks and grant permission, Antho reads bookmark titles, URLs, and folders and converts them locally into workspace records. It does not alter bookmarks or read them in the background. AI provider type, HTTPS endpoint, model, API key, capabilities, and rate-limit information are encrypted together with AES-GCM in the separate local record antho-ai-credentials-v1. The unlock password is never stored. A password-derived key wraps a random local master key; only that master key is held in access-restricted, memory-backed chrome.storage.session during the current Chrome session and is cleared when Chrome fully closes. The Weather widget stores two-decimal coordinates, an approximate place name, time zone, and cache.
Chrome Web Store user-data categories
- Authentication information: the optional AI API key, encrypted locally and sent only to the user-configured HTTPS AI endpoint when saving or testing that configuration or running an AI task.
- Location: two-decimal coordinates, an approximate place label, and weather cache, handled only after the user invokes and consents to the Weather location action.
- Web browsing activity and website content or resources: the current tab title and URL after a toolbar quick-add click; bookmark titles, URLs, and folders after user-invoked import; saved link targets during a user-started link check; and cleaned link titles, hostnames, path keywords, source folders, and limited title evidence during user-invoked AI organization. Antho does not request Chrome history, read page bodies, forms, cookies, or browser storage, or monitor browsing in the background.
- User-generated content: workspace names, categories, link names and URLs, notes, tasks, search queries, and AI prompts. These stay local except for the specific query, prompt, or site data required by a network feature the user invokes.
Antho has no dedicated fields requesting identity, health, financial, payment, or personal-communication data. If you voluntarily put such information in a user-generated field, Antho handles it as part of that field. Avoid unnecessary sensitive data and information about others that you are not entitled to handle.
2. Network recipients
Requests go from your device directly to recipients, not through a server operated by us. Apart from search and opening links, fixed services, AI, and link checks need origin access. New-tab network features also use their in-product consent flow; link checks require confirmation each time. The toolbar's online-icon flow requests icon-service access and makes a request only when you actively choose it.
| Recipient / feature | Data sent | When and why |
|---|---|---|
asd.li recommendations | Ordinary transport metadata; not saved links, searches, or usage records | After recommendations are enabled, to update catalogue and icons; later checks are at most every three days |
favicon.im, a.favicon.im | The hostname from the link you entered and transport metadata | When you actively choose an online icon, to download and cache it locally |
picsum.photos, fastly.picsum.photos | Wallpaper seed, requested size, transport metadata | When you select or rotate a Picsum wallpaper |
uapis.cn | Date, resolution, transport metadata | When you select Bing daily wallpaper |
api.open-meteo.com | Two-decimal coordinates, forecast parameters, transport metadata | To fetch weather when adding or refreshing Weather |
api.bigdatacloud.net | Newly acquired two-decimal coordinates and transport metadata | Once after location, to obtain an approximate city name; never automatically for stored coordinates |
| Selected search service | Your submitted search query and transport metadata | When you submit a search or invoke a configured search shortcut |
| Your configured AI HTTPS endpoint | API key, model, and text required by the requested task | When saving/testing configuration or actively running an AI task |
| A site you start checking | The request for its full URL and transport metadata | After confirmation, limited HEAD and, if required, GET checks; page content is not parsed |
Transport metadata can include public IP address, receipt time, request host and path, response status, and browser/OS headers such as User-Agent, Accept, Accept-Language, Origin, and Sec-Fetch-*. Antho uses credentials: omit and referrerPolicy: no-referrer, so it does not attach browser cookies, HTTP credentials, or a referrer. An AI authorization header contains only the credential you configured. Third parties process data under their own policies and may be outside your country; review their terms before enabling a feature.
Custom image URL: HTTPS only. No request is made while typing. Saving contacts that image server with the full image URL to download and store the icon locally, without cookies or referrer.
Online-icon consent is requested once and shared by the toolbar and sidebar. Once granted, selecting online icons downloads them directly while browser permission remains granted.
3. Browser permissions
storage: saves workspace, settings, caches, and AI configuration locally.activeTab: after you click the extension button, reads the current tab title and URL to quick-add it.sidePanel: opens widget editors without reading the adjacent page.geolocation: provides weather only when you choose current location; it does not continuously locate you.search: passes a query to the browser default provider only when you submit it.- Optional
bookmarks: reads bookmarks only when you initiate an import. - Optional
http://*/*andhttps://*/*: requested at runtime only for an exact origin needed by a network feature, a configured AI endpoint, or a user-started link check.
4. AI
AI is off by default. Saving a new endpoint, model, or credential, or testing a connection, can send small prompts to check output parameters, JSON/structured output, and reasoning controls, and can read same-origin model details and rate-limit headers. Smart organization sends locally cleaned titles, hostnames, path keywords, source folders, and limited evidence; content generation sends the topic and details you provide. Antho does not run an AI proxy. AI providers can retain or otherwise process requests under their policies. Do not submit passwords, identity documents, health, financial, trade-secret, or unauthorized information.
5. Location and weather
Only after you choose “Use current location” or “Relocate”, confirm the notice, and allow browser location does Antho request a non-high-accuracy position. It rounds coordinates to two decimals before storage and transmission and does not retain accuracy, altitude, speed, or movement history. Weather data is fresh for two hours and can be used as stale fallback for up to three hours.
6. Retention and security
Local data usually remains until you edit, reset, clear extension data, or uninstall. Turning off recommendations stops catalog refresh and revokes its consent and origin access; cached data can remain until removed. Locking local protection clears the session master key but retains the encrypted AI record for the next unlock; removing AI configuration deletes that encrypted record. Wallpaper cache keeps only current and previous copies within a size limit. Third-party retention is governed by each recipient.
Antho uses Manifest V3, packages all executable code locally, does not execute remote code, restricts script sources, validates imports and URLs, and uses HTTPS, timeouts, and response limits. Antho-controlled services and user-configured AI, image, and search endpoints use HTTPS. A navigation or link-check request can use HTTP only when the user explicitly saves an HTTP target; that connection is not protected by HTTPS. Protected local records, currently including AI configuration and credentials, are encrypted at rest with AES-GCM using a random master key. The unlock password is processed with PBKDF2-SHA-256 and a random salt to encrypt that master key and is never stored or transmitted. Other chrome.storage.local and IndexedDB data is not separately encrypted. This encryption does not protect data from malware, a compromised browser profile, an untrusted AI endpoint, or someone controlling the device while Antho is unlocked. Protect your device and backups, and contact us about a security concern.
7. Your controls
You can view, edit, export, or delete local data in Antho; reset selected categories; or remove all local data by uninstalling or clearing extension storage. You can turn off recommendations, remove AI configuration, select local appearance, or revoke location, bookmarks, and site access in browser extension settings. Because we do not possess your local data, we normally cannot find or delete it remotely, but can provide guidance. Minors must use Antho with a guardian; a guardian must provide required consent before a child under 14 enables network features.
8. Store Limited Use commitment
We use information received through browser extension APIs only to provide or improve Antho's disclosed single purpose: a local-first new-tab navigation workspace and its user-facing organization, search, display, backup, weather, optional AI, and link-maintenance features. We transfer user data only when necessary for a feature the user invokes and only to the recipient disclosed in section 2. We do not use or transfer it for personalized, retargeted, or interest-based advertising; data brokerage or resale; creditworthiness or lending; or any unrelated purpose.
No developer-operated server receives workspace or AI data, so our personnel cannot read it. If a user voluntarily includes specific data in a support request, people may read only that submitted data as necessary to provide the requested support, protect security, or comply with law.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
9. Changes and contact
We update this policy when features, permissions, recipients, or law change and provide prominent notice where required. New processing that needs consent starts only after consent. Personal-information handler: NaviCube (Antho developer).
Privacy, support, and security contact: snodgrassmupzbm@gmail.com
This policy applies together with the Antho User Agreement.