Privacy Policy

1. Who This Covers

This policy describes how Canopy — the Safari extension for macOS and iOS, its companion application, and this website — handles information. It applies to everyone who installs or uses Canopy.

2. Information We Collect

None. Canopy has no backend. We operate no servers that receive data from the extension, and there is no telemetry, crash reporting, advertising identifier, analytics script, or tracking pixel anywhere in the software or on this website.

Specifically, we do not collect:

3. What Canopy Stores, and Where

On your device

Canopy saves your branches, folders and links in the extension's own local storage, provided by Safari. It also caches the site icons it finds, so they display instantly and are not re-fetched. This data is managed by Safari and removed when you uninstall the extension.

In your iCloud

To keep your devices in step, Canopy writes the same data — without the cached icons — to Apple's iCloud key-value storage under your own Apple account. This is your personal iCloud, governed by Apple's privacy policy. We have no access to it. Canopy has no more visibility into your iCloud than any other app installed on your device.

If you do not want this, sign out of iCloud or turn off iCloud for Canopy in your device settings; the extension continues to work entirely locally.

4. Why Canopy Asks for Access to Every Website

When you enable Canopy, Safari asks whether to allow it on the sites you visit, and Canopy asks for Always Allow on Every Website. This deserves a plain explanation, because it sounds far broader than what it does.

Canopy's whole purpose is to activate the tab you already have open instead of opening a second copy. To do that it has to be able to read the addresses of your open tabs. Safari deliberately withholds a tab's address from an extension that does not have permission for that site — so an extension permitted only on example.com sees a blank address for every other tab. Without broad permission Canopy would be blind to most of your tabs and would open duplicates every time.

What Canopy does with that access:

What it does not do: it does not record, store, or transmit your tabs or browsing history anywhere. Comparisons happen in memory and the result is discarded. Canopy does not read page content beyond looking for an icon on a page you have chosen to pin, and it never runs on pages you have not pinned.

5. Network Requests

Canopy makes network requests to two destinations, and to nothing else.

The sites you have pinned

To fetch their icons. This is the same request your browser makes when you visit them, and it tells those sites nothing they would not learn from an ordinary visit. Canopy sends them no information about you.

The icon library, only when you search it

Canopy lets you pick an icon by hand for any link, from a searchable library of brand logos, app icons, emoji and symbols. There are two ways in: Settings › Look › Choose icons, for working through several links at once, and Search in a link's own editor, for the one link already in front of you. Both use the same library, Iconify, and Canopy queries it only while you are searching.

What is sent is what you type into the search box, as you type it, and nothing else. Results appear while you type, so a partial word may be sent before the whole one. Canopy never sends your links, your hostnames, your titles, or how many links you have. Both places suggest search terms taken from a link's address, but they are worked out on your device and shown as buttons: a request happens when you tap one, not before. If you never search for an icon, Canopy never contacts Iconify at all.

The icon you choose is then downloaded and stored on your device like any other icon. There are no requests to any server operated by us, because there are none.

6. Sharing

We do not share, sell, rent, or disclose your information to anyone, because we do not have it. Canopy embeds no analytics, advertising, or tracking SDKs, and no processor handles your data on our behalf. The one external service it can contact is the icon library described in section 5, which it queries only with words you type and only while you are searching for an icon.

7. This Website

These pages are plain static HTML with no scripts, no cookies, no web fonts, no embedded content, and no analytics. Nothing is stored on your device by visiting them. Standard web server logs may exist at the hosting layer, and are not used to identify or track anyone.

8. Your Control Over Your Data

Because we hold nothing about you, there is no data for us to access, correct, export or erase on your behalf — requests of that kind are satisfied entirely by the controls above.

9. Children's Privacy

Canopy is not directed at children under 13 and collects no information from anyone, including children.

10. Changes to This Policy

If this policy changes, the revised version will be published here with a new date at the top. If Canopy ever began collecting anything at all, that would be stated here prominently and in advance.

11. Contact

Questions about privacy: canopy@sabi.me