Privacy policy
Last updated: 3 October 2026
PriceRoute is a browser extension with a small server (the “PriceRoute API”). This policy explains what PriceRoute collects, why, how long it is kept, and how you can delete it. PriceRoute collects, stores and retains the data described below on our servers (MongoDB, hosted via Vercel) while Journey Memory is enabled.
When collection happens
- Nothing is uploaded until you choose Enable Journey Memory on the first-run screen.
- If you choose Not now or later Pause, PriceRoute stops recording new pages and conversations immediately. Product detection on the current page and the search shortcuts still work locally in your browser.
Categories of data collected
Web browsing activity (Journey Memory)
- Top-level pages you visit while Journey Memory is on: sanitized URL, domain, page title, time, the referring domain, the previous page in the same tab, and how the navigation happened (link, typed, reload, in-page).
- Whether the page looks commercial (product, hotel, flight, rental, search, checkout…) and a confidence score.
- Search terms from search pages (e.g. Google, Amazon search), after removing emails, phone numbers and similar.
Products and prices
- Publicly visible product or property details on commercial pages: name, brand, SKU/GTIN/model number, price, currency, merchant, image URL, and for stays the property name, city and selected dates/guests.
- Price observations (item, merchant, price, time) so PriceRoute can show “you saw this for €249 yesterday”.
AI conversations (ChatGPT and Gemini)
- On chatgpt.com and gemini.google.com, when a conversation is about shopping or travel, PriceRoute processes and retains the text of your prompts and the assistant’s replies (from the first shopping-related message onward), turn order and time, visible citations and source links, search queries that the assistant’s interface visibly shows, links you click, and products/hotels/places mentioned.
- Conversation text is redacted in your browser before upload (emails, phone numbers, card and account numbers, common API keys/tokens) and redacted again on the server. Redaction is automated and may not catch everything, so avoid sharing sensitive personal information in shopping conversations.
- Conversations that are not shopping- or travel-related are not uploaded.
- The conversation ID is replaced by a salted one-way hash; we do not collect your OpenAI or Google account identity.
Checkout progress
- Only the stage reached (cart, checkout, payment page, confirmation), the merchant domain and time. Checkout URLs are stripped of all parameters and IDs, and page titles are not stored.
Identifiers
- A random installation ID and installation secret generated in your browser, a browser-session ID and per-tab session IDs. These are not linked to your name, email, or Google/OpenAI accounts. No device fingerprinting.
What we never collect
- Passwords, authentication tokens, cookies, authorization headers or browser storage.
- Credit-card numbers, CVVs, bank details or payment methods.
- Values you type into forms (including checkout forms), order numbers, names or addresses from confirmation pages.
- Your browser history from before you enabled Journey Memory.
Purpose and Limited Use
The data is used only to provide and improve PriceRoute’s user-facing features:
- Journey Memory (showing you your own research history);
- price comparison and showing direct or cheaper routes;
- product, hotel and property matching;
- improving those features and aggregate measurement of how they perform.
We do not sell browsing or conversation data, use or transfer it for personalised or behavioural advertising, use it to determine creditworthiness or for lending, or transfer it to data brokers or other information resellers. This applies equally to raw, anonymised, aggregated, de-identified and derived data. Humans do not read your data except with your explicit consent, for security purposes, to comply with law, or when aggregated and anonymised for internal operations.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Retention
- Journey, event, conversation, product and price records are deleted automatically 12 months after they were last updated.
- Cached comparison results are deleted after 30 days.
- You can delete any journey, or everything, at any time — deletion is immediate.
- A deletion audit record keeps only a one-way hash of the installation ID, the time and record counts (no content), for up to 400 days.
Security
- All traffic uses HTTPS. Database credentials exist only on the server and are never shipped in the extension.
- Requests are authenticated with your installation secret; the server stores only a SHA-256 hash of it.
- All input is validated; URLs and text are sanitized; server logs never contain conversation text, full URLs or secrets.
- The extension contains no remotely loaded code.
Service providers
Data is processed by our hosting provider (Vercel) and database provider (MongoDB Atlas) solely to run PriceRoute. If an optional shopping-search provider is enabled, only the product name/brand/model of the item you ask to compare is sent to it — never your browsing history or conversations.
Deletion and your choices
See Your data for step-by-step instructions to pause collection, delete a journey, or delete everything. Uninstalling the extension stops all collection; to delete server data, use Delete all my data before uninstalling, or contact us with your installation ID (shown in the extension under Data controls).
Contact
Questions or requests: eduar.vari@proton.me