Summary
Everything the extension stores stays in your browser. There are no accounts, no servers of ours, no ads, no analytics and no telemetry. Saving and searching bookmarks never sends anything off your computer.
No data is sold, shared with third parties or used for advertising. This website also uses no cookies or trackers. The intro video only loads from YouTube (privacy-enhanced mode) when you click to watch it; before that, no third-party resources are used.
Data handled
| Data | Purpose | Where it is kept |
|---|---|---|
| URL, title and icon of pages you save or import | list and search your bookmarks | browser local storage |
| Text of saved pages (or excerpts only, if you choose) | meaning-based search, tags, summary, grouping | local storage, on your computer |
| Tags, collections, notes, summaries | organization | local storage |
| Visit counters — only if you turn on “Suggest pages”: distinct days and reading time per page, under an identifier that does not reveal the address, for up to 30 days | suggest what is worth saving | local storage, on your computer |
| Titles and addresses from the last 90 days of history — only if you turn on “Include my history in search” | find pages you visited but did not save | local storage; turning it off deletes everything |
| Preferences | configure the extension | the browser's own sync storage, protected by your browser account |
Banking and health sites are never captured automatically (configurable list), and incognito windows are never captured.
Network access
The extension only connects to the internet in these cases:
- Downloading your bookmarked pages to read their content, when you grant site access. Only the pages you saved, without cookies or credentials.
- Downloading the AI model once, from Hugging Face (huggingface.co). The model runs on your computer.
- Checking for broken links, only when you ask. Only each bookmark's address is requested.
- Site icons come from the browser's own cache — the extension never fetches them from the sites.
- Search engine lookup (optional, off by default). If you turn it on, for bookmarks without readable content (login screens, dashboards), it sends DuckDuckGo (html.duckduckgo.com) only a few words of the title or the site name, never the full address or page content. Turning it off stops the lookups.
- AI services with your own key (optional, off by default). If you connect a service
(Anthropic, OpenAI, Ollama or a compatible service you enter), the extension sends data only to the
address you configured and only for the purposes you allowed, one by one, after the
consent screen:
- Organize: page title, address and text (up to 6,000 characters) and the names of your tags and collections;
- Answer: your question and excerpts from up to 8 relevant bookmarks (up to 600 characters each).
Permissions
Only what is needed is requested. Permissions marked optional are asked for at the moment you use the feature and can be denied without affecting the rest. The browser's bookmark tree is only read, never modified.
| Permission | Why |
|---|---|
| Storage (unlimited) | keep bookmarks, page text and the search index on your computer; the library grows with use |
| Bookmarks | import and follow the browser's bookmarks (read-only) |
| Context menu | “Save to Tessera” and “Save link to Tessera” on right-click |
| Active tab and page reading | read the content of the tab you are saving, and of the open tab to show related bookmarks |
| Background document | run the local AI model without slowing down browsing |
| Alarms | periodic tasks: empty the trash, recalculate topics, resume processing |
| Side panel | search and bookmarks related to the open page |
| Site icons | show each site's icon from the browser's cache, without requests to the sites |
| Site access (optional) | only when you ask: import with content, download pages without opening them, check links, related bookmarks and the address of the AI service you configured |
| Tabs (optional) | only if you turn on “Suggest pages worth saving”: know the active tab's address to count visits |
| History (optional) | only if you turn on “Include my history in search”; given back when you turn it off |
Your control
- Export everything as JSON (Settings → Data).
- Delete: the trash is emptied after 30 days, or immediately with “Empty trash”. Uninstalling removes all local data.
- Choose what content is kept: full text or summary and excerpts only, by default or per site.
Changes and contact
Changes to this policy will be published on this page with the new extension version. Future features that send data elsewhere (for example, sync across devices) will only work with your explicit consent and will be described here before release.
Contact: github.com/casheiro/tessera/issues. Don't include personal data or API keys in public messages.