Chrome Web Store disclosure
Chrome Web Store disclosure of Dreamdrive, operated by Synthetic White AB. Version 1.0, effective 3 October 2026.
1. Purpose of this page
This page collects the statements we make to Google when publishing the Dreamdrive extension in the Chrome Web Store: the single purpose of the extension, why it needs each permission, what data it handles, and our commitment to Google's limited-use rules. It is published so that users and reviewers can read the same text. The full Privacy Policy governs; if anything here conflicts with it, the Privacy Policy prevails.
2. Privacy policy URL
https://www.dreamdrive.ai/privacy-policy/
3. Single purpose
Dreamdrive keeps a personal record of what the user makes with generative AI tools. On platforms the user explicitly connects, it reads the user's own generations (prompt, model, settings, references, result image addresses, time) and saves them to the user's Dreamdrive library, where they can be searched, organised into projects and exported as a usage sheet. Every feature of the extension serves this one purpose. The extension is read-only: it never clicks, types, submits or generates anything on any site, and it does not read pages the user has not connected.
4. Permission justifications
| Permission | Why it is needed |
|---|---|
| storage | To keep the user's sign-in token, settings (which platforms are connected, current project, theme), a queue of captures waiting to be sent, a local cache of recent captures so the side panel loads quickly, and the remote configuration (platform list and page selectors). Nothing in storage is shared with websites. |
| identity | To let the user sign in to their Dreamdrive account with Google using chrome.identity (launchWebAuthFlow). We receive only the OpenID profile fields email, name and picture. Users may instead sign in with an email code, in which case this permission is not exercised. |
| alarms | To schedule periodic background work: sending queued captures to the user's library, refreshing the remote configuration, and refreshing the sign-in session. Alarms run no more often than every few minutes and do nothing when the user is signed out. |
| sidePanel | The side panel is the extension's main interface: it shows today's captures, lets the user search, pick the project they are capturing into, confirm a capture started from the right-click menu, and turn capture on or off per platform. |
| contextMenus | To add a single "Save to Dreamdrive" item to the right-click menu on images, so the user can record an image from any connected platform that has no automatic adapter. |
| activeTab | When the user chooses "Save to Dreamdrive" from the right-click menu or clicks the extension's hover save button, activeTab gives temporary access to the current tab so that the extension can read the chosen image's address, the page address and title, and any embedded metadata. Access ends when the user leaves the tab. It is never used without a user gesture. |
| scripting | To inject the read-only content script into pages on platforms the user has connected via optional host permissions, and to run the one-off read triggered by the right-click menu or hover button on the active tab. The injected code only reads the page and shows the small status chip and hover button; it never submits forms, clicks controls or changes site data. Scripts are bundled in the extension package; no remote code is loaded or executed. |
| Host permission: the Dreamdrive API origin | To send the user's captures to, and read their library from, the user's own Dreamdrive account at our API. This is the only host the extension requires at install. |
| Optional host permissions: each supported AI platform | Capture is opt-in per platform. When the user turns on capture for a platform (for example midjourney.com), Chrome asks the user to grant that site and only then can the content script read that site's pages to record the user's own generations. The user can revoke each site at any time in the extension or in Chrome's site settings. The extension does not request access to all sites. |
5. Remote code
The extension does not load or execute remote code. All JavaScript is bundled in the package. The extension does fetch a configuration file from our servers that contains data only: the list of supported platforms, their hostnames and terms URLs, and the CSS selectors used to read each platform's pages. This lets us repair a broken adapter when a platform changes its layout without a new store release. The configuration is parsed as JSON and never evaluated as code.
6. Data use disclosure
6.1 Data the extension collects
| Chrome Web Store category | Collected | Detail |
|---|---|---|
| Personally identifiable information | Yes | Email address, name and profile picture URL from sign-in, to create and operate the user's account. |
| Authentication information | Yes | A Dreamdrive session token stored locally. We never receive the user's Google or other passwords. |
| Website content | Yes | Only on platforms the user has connected: the user's own prompts, negative prompts, model names, settings, reference links, result image URLs, page URL and title, timestamps and small thumbnails. Embedded metadata read from image files the user chooses to import. Nothing is read from sites the user has not connected, and nothing is read from pages showing other people's work. |
| User activity | Yes | Which Dreamdrive features were used and when, extension version and install events, used to run and improve the extension. We do not record browsing history, keystrokes, mouse movements or activity on sites other than the capture events described above. |
| Web history | No | The extension does not collect the list of pages visited. Page URLs are stored only as part of a capture the user made on a connected platform. |
| Location | No | No location data. Server logs contain IP addresses for a short period for security, as described in the Privacy Policy. |
| Health information | No | |
| Financial and payment information | No | Payments are made on pages hosted by Stripe; the extension never handles card details. |
| Personal communications | No |
6.2 Certifications
We certify that the extension's handling of user data complies with the Chrome Web Store Developer Programme Policies and in particular that we:
- do not sell user data to third parties;
- do not use or transfer user data for purposes unrelated to the extension's single purpose;
- do not use or transfer user data to determine creditworthiness or for lending purposes.
7. Limited use statement
Dreamdrive's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The only Google data we receive is the OpenID profile (email, name, picture) used to sign the user in. We use it solely to provide and improve the user-facing features of Dreamdrive; we do not transfer it to others except as necessary to provide those features, to comply with the law, or as part of a merger or acquisition with notice to users; we do not use it for advertising; and we do not allow humans to read it except with the user's consent, for security purposes, to comply with the law, or in aggregated, anonymised form for internal operations.
8. User data handling in the extension
- All data sent by the extension travels over TLS to our API hosted on Cloudflare with EU data location.
- The user can view, edit, export (images, CSV, JSON) and delete any capture, and can revoke any platform's permission at any time.
- Account deletion deletes all captures within 30 days and from backups within 90 days.
- Uninstalling the extension removes everything stored locally. It does not delete the account; the user can request deletion by email or in the product.
- Full details, retention periods and the list of subprocessors are in the Privacy Policy.
9. Non-affiliation
Dreamdrive is an independent product and is not affiliated with, endorsed by or sponsored by Midjourney, OpenAI, Google, Adobe or any other platform it can connect to. Platform names are trademarks of their owners, used only to identify where a capture came from. See the Non-affiliation and Trademark Notice.