Scope of this policy
This policy explains how the ClickLoop service and its browser extension handle the data needed to provide a user-controlled repetitive-clicking tool and its supporting in-extension utilities.
Account data
When you create an account or pair the extension, we use your email address, display name, preferred language, and plan status. If you choose Google sign-in, we may receive your name, email address, and profile image from Google. Security logs may include an IP address, browser type, and request time.
Authentication and extension pairing
When pairing begins, the extension sends the device operating-system name, extension version, language, and a temporary pairing token. After approval, the extension stores a device authentication token locally so it can validate the account and plan, while the server keeps a one-way hash of the session token. A pairing code is valid for ten minutes. Only one active device is allowed per account; pairing a new device revokes the previous session. An unused device pairing expires after 30 days. The extension does not store your ClickLoop password or passwords for other websites.
Data stored in your browser
The selected click region and coordinates, page viewport size, interval settings, operating mode and state, click count, reminders and notes, saved-link titles and URLs, language, and preferences are stored locally. Under the current features, click-region details, counters, reminders, and saved links are not sent to ClickLoop servers. This data remains until you delete it, clear the extension data, or uninstall the extension.
Browsing activity and website content
The extension handles the origin of a website that the user chooses for region selection. When the user explicitly chooses to save the current tab, the extension reads its page title and URL and stores them locally. The extension does not monitor browsing history in the background or collect complete browsing history, and it does not extract or transmit page-body text, images, forms, screenshots, or keystrokes. During operation, it handles only the selected region position and the element at the click point to perform the function requested by the user.
Browser permissions
The extension uses activeTab and scripting to access the user-selected tab, display the visual region selector, and run code included in the extension package. Storage preserves local settings, alarms schedules click cycles and reminders, notifications displays user reminders, and offscreen plays the locally generated reminder sound. Site access is requested when the user chooses to use the extension on that site. Standard mode does not use Chrome Debugger. Only when the user explicitly enables Advanced mode does the extension temporarily attach to the selected tab to dispatch mouse input inside the chosen region, then detach after the operation. Debugger access is not used to monitor network traffic or read passwords, page content, or unrelated tabs.
Communication with ClickLoop servers
The extension communicates with ClickLoop servers exclusively over HTTPS for account pairing, session and plan-status validation, and logout. These requests exchange JSON data only; the extension does not download JavaScript or WebAssembly from a remote server for execution.
Sale and sharing
We do not sell or rent user data, and we do not use it for targeted advertising, creditworthiness, or lending purposes. Data is shared only as necessary to operate and secure the service, when requested by the user, or when required by law. We do not use data for purposes unrelated to ClickLoop’s disclosed functionality.
Third-party services
We may use PayPal for payment processing, Google for optional sign-in, and Cloudflare for security, Turnstile, DNS, and security analytics. Data processed by these providers is governed by their respective policies. ClickLoop does not receive full payment-card numbers or card details from PayPal.
Retention and security
We retain account data while the account exists or as needed to provide the service and meet security and legal obligations. Support and payment records may be retained as necessary. We use HTTPS in transit and appropriate access and storage controls, but no electronic method is 100% secure.
Your choices
You can delete locally stored data through the extension settings or by uninstalling it. You may also ask us to correct or delete account data or disconnect the extension by contacting us. We may retain minimal records when required by law or for fraud prevention.
Chrome Web Store Limited Use
ClickLoop’s use and transfer of information received from Chrome and Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements, and with the Google API Services User Data Policy where applicable. We use this information only to provide, maintain, and secure the extension’s disclosed functionality.
Contact
For privacy questions or data requests, contact support@clickloop.fun. Last updated: September 14, 2026.