Control Deck · Privacy Policy · Version 1.0

Local controls.
Local data.

This policy explains what Control Deck can access, what it stores, what it does not collect, and what happens when you use a captured webpage control.

Server collection None in version 1.0.0
Storage Local Chrome extension storage
Site access User-invoked active tab only

1. Scope of this policy

This privacy policy applies to Control Deck version 1.0.0, a Chrome extension that lets a user select controls and visible values from the webpage they are actively using and place representations of those items in a floating deck.

Control Deck is designed as a browser-local utility. It does not require a Control Deck account, developer-operated cloud service, or remote database to provide its core functionality.

This policy describes Control Deck itself. It does not govern the privacy practices of websites you visit. A website can have its own accounts, cookies, analytics, forms, network requests, and privacy terms independently of this extension.

2. What Control Deck does

When you invoke Control Deck on the current tab, the extension injects its packaged interface into that page. You can then enter Pick Mode and choose a supported page element.

Supported elements include buttons, links, text inputs, text areas, select menus, checkboxes or switch-like controls, range sliders, and visible text that can be represented as a read-only live value.

The resulting module is connected to the original element. Interactive modules act on the original webpage control; read-only modules display text from the original element. The extension periodically refreshes the module state in response to page mutations and normal input or change events.

Control Deck does not create a separate copy of the website's business logic. A deck module is a local interface to the page element you selected.

3. Information processed on the page

To capture and reconnect a module, Control Deck processes information about the selected DOM element inside your browser. Depending on the element, that can include its tag name, input type, identifier, name attribute, accessibility label, role, stable data attributes, visible label text, nearby label text, selected value, link destination, and structural context.

For a live-value module, Control Deck reads the visible text of the selected element so that it can show the current value in the deck. For form controls, it reads the control state necessary to keep the deck synchronized with the page.

This processing occurs locally in the tab where you invoked the extension. Version 1.0.0 does not send these page details to a developer server.

Control Deck does not intentionally crawl the entire website, build a browsing profile, or collect unrelated page content. It examines DOM information as needed for picking an element, resolving saved bindings, and keeping captured modules current.

4. Local data saved by the extension

Control Deck uses chrome.storage.local to remember a deck for each website origin. The storage key is derived from the page origin so configurations for different origins remain separate.

A saved site deck can contain:

  • module type and user-facing module label;
  • candidate selectors used to locate the original element again;
  • a structural fingerprint used to validate candidate matches;
  • limited page-path context used by the reconnect logic;
  • module order;
  • the floating deck position;
  • whether the deck is collapsed;
  • a local last-updated timestamp.

The extension also saves its installed version number locally. This is operational extension state, not an analytics identifier.

Version 1.0.0 does not upload this saved configuration to a Control Deck cloud account because no such account or synchronization service is used.

5. What is not collected

Control Deck version 1.0.0 does not operate analytics, advertising, telemetry, crash-reporting, or behavioral-tracking endpoints.

It does not intentionally transmit or centrally collect:

  • your browsing history;
  • the list of websites on which you create decks;
  • captured form values;
  • captured live-value text;
  • saved selectors or DOM fingerprints;
  • keystrokes entered outside the captured controls;
  • personal profile information;
  • advertising identifiers;
  • location data;
  • payment information.

There is no developer-operated remote storage for Control Deck data in version 1.0.0.

6. Chrome permissions

The extension requests activeTab, scripting, and storage.

activeTab grants temporary access to the current tab when you explicitly invoke the extension. Control Deck uses this temporary access rather than requesting broad persistent access to every website.

scripting is used to inject the packaged Control Deck content script into the active page. This script creates the capture interface, binding engine, synchronization behavior, and floating deck.

storage is used to save the local site deck, binding information, layout state, and extension version information.

The production manifest for version 1.0.0 does not request host permissions such as <all_urls>.

7. User activation and site access

Control Deck is intentionally user-activated. The extension is not configured with a content script that automatically runs on every webpage at browser startup.

When you click the extension action, Chrome's active-tab permission allows the service worker to inject the packaged script into that specific active page. If the deck is already present, another invocation toggles its visibility instead of creating duplicate instances.

Chrome itself restricts extension scripting on certain browser-internal pages, protected pages, and other contexts where extension injection is not permitted. Control Deck does not attempt to bypass those restrictions.

8. Capture Mode

Pick Mode temporarily listens for pointer movement and selection events so you can choose an element. It visually outlines the candidate and labels the detected module type.

Selection is designed not to activate the underlying control during capture. The extension intercepts the selection event so picking a button does not intentionally submit a form, picking a checkbox does not intentionally toggle it, and picking a link does not intentionally navigate away.

Pick Mode ends after a successful capture or when you cancel it. The temporary capture event listeners are then removed.

9. Binding and reconnection

Websites can change their DOM structure between visits or while a single-page application is running. To remain useful without binding to arbitrary elements, Control Deck stores multiple selector candidates together with a fingerprint of the chosen element.

When reconnecting, candidate elements are scored against characteristics of the saved element. A candidate must meet the extension's confidence rules before it is treated as connected.

If Control Deck cannot identify the intended element confidently, the module is displayed as disconnected. The extension does not intentionally use a weak match merely to keep a module looking active.

You can manually reconnect a disconnected module by entering reconnect mode and selecting the intended element again. The module's placement can remain while its binding is replaced.

10. Interacting with captured controls

For buttons and button-like elements, using the deck can trigger the original element's normal click behavior. For links, the original page link is activated. For toggles, the extension uses the page control's normal click behavior where appropriate.

For text, select, and range controls, Control Deck updates the original element through browser-native value setters and dispatches the normal input or change events needed for many websites and JavaScript frameworks to observe the change.

Because the original website receives these interactions, the website can respond exactly as it normally would. That response can include saving a record, submitting a form, navigating, or making a network request to the website's own servers.

A website request caused by activating its original control is website activity, not a hidden Control Deck telemetry request. Use deck controls with the same care you would use the original page controls.

11. Network behavior

Control Deck version 1.0.0 contains no fetch-based service, XMLHttpRequest client, WebSocket connection, EventSource stream, analytics SDK, advertising SDK, or remotely loaded executable script.

The extension's own functionality therefore does not require a developer endpoint or third-party API.

The webpage underneath Control Deck remains free to make its normal network requests. If you type into a site's search field through the deck and that site performs live search requests, those requests belong to the site's existing behavior.

12. Remote code and third-party libraries

All executable JavaScript used by Control Deck version 1.0.0 is packaged with the extension. The extension does not fetch JavaScript from a remote server and does not use eval or equivalent mechanisms to execute downloaded code.

The production build does not depend on a remote UI framework, font service, analytics package, or CDN asset in order to render the deck.

As a result, there is no third-party library provider receiving Control Deck usage data through an embedded remote SDK in this version.

13. Data retention

Saved deck configuration remains in Chrome's local extension storage until it is changed or removed through user action, browser data management, extension data clearing, profile removal, or extension uninstallation.

There is no separate server-side retention period because version 1.0.0 does not upload these configurations to a Control Deck server.

If Chrome synchronization or browser-profile features outside this extension move browser data between devices, those features are governed by the browser provider's behavior and settings. Control Deck itself does not implement cloud synchronization in version 1.0.0.

14. Deleting your data

You can remove individual modules from a deck using the module menu. This updates the saved local site configuration.

You can also remove Control Deck's extension data through Chrome's extension or site-data management facilities, depending on the controls offered by your browser version.

Uninstalling the extension removes its extension-owned local storage according to Chrome's extension lifecycle behavior.

Because Control Deck does not maintain a developer account or remote database in version 1.0.0, there is no separate developer-server deletion request required for deck configuration.

15. Security design

Control Deck uses a Shadow DOM host for its own interface so ordinary page styles are less likely to alter the deck and deck styles are less likely to alter the page.

The extension limits saved decks to 24 modules in version 1.0.0. This places a practical bound on UI and refresh work even if a user repeatedly captures values.

Element reconnection uses validation rather than blindly trusting the first selector match. A changed page can therefore cause a module to disconnect instead of being silently attached to an unrelated control.

No software can guarantee that every third-party website will behave identically forever. Users should review disconnected modules after a site redesign and should avoid triggering consequential controls unless the displayed binding is the one they intend.

16. Sensitive pages and sensitive fields

Control Deck is a general-purpose page-control utility, so users may encounter sensitive forms on websites they visit. The extension does not need a developer server to process captured controls.

Users should decide carefully which controls they pin. A module can display the current value of a supported field because synchronization is part of the product's purpose. That value remains subject to the privacy and security of the local browser session and the underlying website.

Control Deck does not advertise itself as a password manager, secrets vault, payment wallet, or secure credential-storage system. Users should use dedicated security products for those purposes.

17. Children

Control Deck is a general browser utility and is not designed as a service directed to children. Version 1.0.0 does not run an account system, social network, advertising profile, or developer-operated data collection service.

If a parent, guardian, school, or organization manages a Chrome environment, that administrator may also control extension installation and website access independently of Control Deck.

18. Analytics and advertising

There is no analytics or advertising integration in Control Deck version 1.0.0.

The extension does not sell user data, does not use captured page data to create advertising audiences, and does not insert advertisements into the webpages on which the deck is used.

If a future version introduces a material analytics or service dependency, the privacy policy and permission disclosures would need to be updated before representing that version's behavior.

19. Website privacy remains separate

Using a webpage through Control Deck does not change who operates that webpage. The website can continue to receive the same information it normally receives when you type, select, click, navigate, or submit its controls.

For example, if a captured Publish button normally sends content to the website's server, pressing the corresponding Control Deck module can cause that normal publish action. Control Deck does not proxy or anonymize the website request.

You should review the website operator's privacy notice when you need to understand how that website handles the data submitted to it.

20. Browser and administrator controls

Chrome provides controls for enabling, disabling, uninstalling, and in some environments managing extension access. Organizational administrators can impose policies that restrict extension execution or installation.

Control Deck does not attempt to bypass browser-managed restrictions. If Chrome does not permit scripting on a page, the extension cannot create its deck there through the normal active-tab flow.

21. Changes to this policy

This policy may be updated when Control Deck's behavior, permissions, storage model, or service dependencies materially change.

A revised policy should describe the behavior of the corresponding extension version rather than relying on this version 1.0.0 document for features that did not exist when it was written.

Material changes that introduce new data collection or external services should be disclosed through the product's applicable distribution and privacy channels.

22. Contact

For privacy questions about Control Deck, use the developer or support contact published with the extension's Chrome Web Store listing.

Please do not include passwords, authentication tokens, private page contents, or other unnecessary sensitive information in a support request.

23. Version statement

This document describes the production behavior of Control Deck 1.0.0: local per-origin deck storage, user-invoked active-tab scripting, seven supported module categories, confidence-based reconnection, and no developer-operated network service.

Last policy revision: September 3, 2026.