Image Save — WebP to JPG & PNG Privacy Policy
Last updated: September 21, 2026. Applies to Image Save 0.1.0.
Purpose and contact
Image Save is developed by extenup. Contact: extenup@gmail.com.
The extension converts a still image you explicitly select through Chrome’s image context menu into a JPG or PNG file saved by Chrome. You do not need an Image Save account. It has no advertising, analytics service or developer-operated image conversion server.
What the extension handles
For a save you initiate, the extension handles the selected image’s bytes and source URL, the source page or frame URL, the selected output format, proposed and final filenames, image dimensions, and temporary job identifiers, timestamps, status and error codes. URLs may include query parameters, temporary access tokens or other information supplied by the source website. Filenames and images may themselves contain personal information. The extension does not interpret image content to identify people, read text or build profiles.
It uses the selected tab/frame and document identifiers to retrieve the intended image and detect navigation. It does not read Chrome’s browsing-history database or continuously record websites you visit. It does not enumerate unrelated downloads. To reconcile its own save, it queries Chrome for the matching download ID or unique generated Blob URL; Chrome may return the local file path, from which the extension retains only a bounded final filename for its status display.
Source requests and local conversion
Conversion is performed locally by packaged code using the browser’s image decoder and canvas. The extension may fetch the selected image from its original website or image host. This is a source download, not an upload to the developer or a third-party converter. No proxy or alternate conversion service is used, and redirects are rejected.
An initial fetch in the selected page/frame uses the browser’s same-origin credential behavior: the browser may send existing cookies or authentication credentials to that same origin. The extension does not read the browser’s cookie store or ask for your password. Cross-origin fetches in that page and fallback/recovery fetches from the extension do not include cookies or HTTP authentication credentials. A source URL may itself contain an access token, which remains part of the request to that source.
The original site receives the requested URL and the browser’s ordinary request/network information, such as your IP address and applicable request headers. Browser and site rules determine additional details such as referrers and caching. HTTPS requests use the browser’s encrypted transport; an explicitly selected HTTP source is requested over unencrypted HTTP. Do not use an HTTP source for sensitive images or credentials. Image Save does not upgrade, proxy or promise to secure that site’s connection.
Supported inline data images and accessible page-owned Blob images can be processed without a remote image request. Original metadata is not copied to the newly encoded file; this is not a guarantee that the image’s visible contents or saved filename contain no personal information. Original color-profile or archival fidelity is not promised.
Storage and retention
- Image bytes and converted Blob data are held temporarily in browser memory for processing and saving, not in a persistent extension image library. The converted Blob is released when the job finishes, fails, is cancelled or expires. An offscreen backstop also releases jobs older than 15 minutes from creation while that context is running.
- The selected source/page URLs and retrieval state are stored in Chrome’s extension session storage while needed to prepare or retry the save. Inline data-image contents are held in memory rather than written to that session record. Source/page URLs are removed when conversion is ready for saving or when the job becomes terminal. Preparation and permission-retry jobs have a five-minute expiry from creation.
- Active download-tracking state has a 15-minute expiry from job creation. After completion, cancellation, error or expiry, a reduced record containing request names, format, dimensions if available, identifiers, timestamps and status/error codes remains in session storage with a five-minute expiry from that terminal event.
- Cleanup runs periodically while Chrome and the relevant extension contexts are running. Suspension can delay cleanup; the expiry values are not a promise of exact wall-clock erasure. Session records are not synchronized to other devices or intentionally persisted across browser sessions.
- The “Download immediately” preference is stored locally until changed, extension data is cleared or the extension is uninstalled. Optional image-host grants are kept by Chrome until you remove them or uninstall the extension; they are not one-use grants.
- Saved image files and Chrome’s download history are separate from the temporary extension records. They remain under your control and Chrome’s normal behavior. Expiry, revoking a host grant or uninstalling Image Save does not delete downloaded files or erase Chrome’s download history.
The extension adds no separate encryption layer to local browser storage or downloaded files; their protection depends on Chrome, your operating system and device settings. The extension has no telemetry or explicit source-URL logging, but Chrome’s own network/error diagnostics, caches and the original website’s logs can retain information under their respective behavior and policies.
Permissions and your controls
contextMenus supplies the image commands. activeTab and scripting allow bundled code to access the selected accessible page/frame after your action. downloads starts and reconciles the extension’s own image saves. storage holds the preference and temporary jobs. offscreen supports the packaged image worker and Blob resources. alarms schedules cleanup and download reconciliation.
There is no required persistent all-websites host grant at installation. If the selected image on another host cannot be read, the extension may offer an optional Chrome permission request for that source’s scheme and exact hostname. The displayed pattern, for example https://images.example/*, covers all paths and ports on that hostname for that scheme; it is not limited to the single image, and it does not include subdomains automatically. The extension uses saved access only for image saves you initiate. Approval does not guarantee that a site will provide a readable image.
You can decline access or choose “Cancel this save”. Declining stops that job without an automatic retry or another permission request for it. In the extension’s panel, “Previously granted image-host access” lists grants and offers “Remove previously granted access”. Chrome’s extension site-access settings also control grants. Removing a grant does not cancel a save already in progress or delete an existing file. Cancel a pending native Save As dialog in Chrome’s dialog itself. An already-started page fetch may finish after cancellation, but a cancelled preparation job does not save a late result.
You can change immediate-download behavior in the panel. To remove persistent extension preferences and access, uninstall the extension. Manage saved files and Chrome download-history entries separately using your file manager and Chrome.
Use, sharing and other services
The local data above is used only to perform, control and report the image save you requested. Image Save complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. It does not sell user data, use or transfer it for advertising, creditworthiness or lending, or use it for unrelated profiling. The developer does not receive image contents, source/page URLs, save-job records or download paths from the extension and cannot inspect these local records remotely.
The source website and Chrome continue to operate under their own policies; Image Save does not change their data handling. Opening this public policy page makes an ordinary request to its hosting provider, separate from the extension’s image-processing operation. The extension does not automatically fetch the policy page.
If you choose to email support, the developer and email providers receive what you send. Support correspondence is separate from automatic extension operation and is used to address your request. Do not send passwords, access tokens or private images when a general description is sufficient. You may request deletion of support correspondence by email, subject to applicable retention obligations.
Changes
If a future version changes the information handled, permissions, retention, purpose or recipients, this policy and the Chrome Web Store disclosures will be updated to describe that version.