Privacy Policy

Sugar Tracker - UK Grocers Chrome Extension

Last Updated: August 1, 2026

Recent updates

Overview

Sugar Tracker - UK Grocers ("the Extension") is a browser extension that displays nutritional sugar, salt, saturates, and calories content information on UK grocery websites. This privacy policy explains how we handle your data.

Data Collection

We do not collect any personal data.

The Extension operates entirely within your browser and does not transmit any information to external servers owned or operated by us.

Data Storage

The Extension stores the following data in Chrome's built-in storage APIs on your device:

  1. Cached Nutrition Data: Nutrition values (sugar, salt, saturates, calories) for products you've viewed, stored in chrome.storage.local to improve performance and reduce repeated page loads. Each entry carries a small schema-version stamp so a future update can discard incompatible shapes cleanly.
  2. User Preferences: Your settings such as whether the extension is enabled, which nutrients to display, and your chosen colour theme, stored in chrome.storage.sync.
  3. Technical Diagnostics: A small, capped ring buffer of the most recent extension errors and rate-limit events (origin and pathname only — no query strings, no cookies, no personal content), stored in chrome.storage.local under a dedicated key. This is what the “Copy Diagnostics” button in the popup footer exports for you to paste into a bug report. The ring never transmits on its own.
  4. Selector-Health Telemetry: A per-site tally of which CSS selector matched each product container, stored locally so the popup can show a “Needs review” chip when a grocer's page layout drifts. No product URLs or content are stored with this.
  5. Viewed-Product Record: A list of identifiers for products you have already seen on the supported grocers, stored in chrome.storage.local and capped at 5,000 entries (oldest dropped first). Each identifier is the retailer's own product code where the page exposes one, otherwise a normalised product name, otherwise the product page's URL with any query string and fragment stripped. The extension uses it only to tell a product you have seen before from one you have not, so first-seen badge animations do not replay on every visit. It records which products, not when, how often, or in what order, and it never leaves your device.

This data:

Website Access

The Extension requires access to the following websites to function:

This access is used solely to:

The Extension does not:

For the same reason, the Extension's Chrome Web Store listing declares the Website content and Web history data categories. Google requires disclosure of data an extension handles “even when data is processed or stored locally on a user's device and is not transmitted to external servers or third parties”. Reading nutrition text from a retailer's page is website content, and the bounded viewed-product record is a local record of grocery product pages you have opened. Both stay on your device. The declaration describes what the Extension reads and stores; this policy describes what happens to it afterwards, which is nothing beyond your own browser.

Third-Party Services

The Extension does not use any third-party analytics, tracking, or advertising services.

Data Requests to Grocery Websites

When you browse grocery websites with the Extension enabled, it may make requests to those websites' pages or APIs to retrieve nutrition information. These requests:

Authenticated API Requests (Ocado, Sainsbury's)

Some retailers (currently Ocado and Sainsbury's) only expose complete nutrition data through JSON APIs that require an authenticated session. When the Extension cannot read nutrition values from the visible HTML, it falls back to these APIs and sends the retailer's own session cookies with the request — the same cookies your browser already sends when you navigate the site normally. Specifically:

Permissions Explained

Permission Purpose
storage Store cached nutrition data locally and save extension settings in Chrome storage
alarms Schedule a daily background sweep that prunes stale selector-health and diagnostics-ring entries from local storage. The alarm runs only on your device and never communicates externally.
Host permissions Access the 8 supported grocery domains to read and display nutrition data

Children's Privacy

The Extension does not knowingly collect any information from children under 13 years of age.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be reflected in the "Last Updated" date at the top of this policy.

Your Rights

Since we do not collect any personal data, there is no personal data to access, modify, or delete. You can remove all locally stored data by:

  1. Clearing the extension's local and sync storage
  2. Uninstalling the extension

Contact

If you have questions about this privacy policy, please use our feedback form.