Privacy Policy
Last updated: 11 September 2026
Who is responsible
Auto Refresh | Page Monitor is a product of Xeviora, a brand operated by LIU HU, a sole proprietor, who is the controller of the personal data described in this policy. Contact: support@xeviora.com
The short version
The extension does its work inside your browser. We do not collect the addresses of pages you visit, and we do not build a profile of your browsing. If you never create an account, nothing about your use of the extension reaches our servers at all.
What stays on your device
- Your refresh rules and monitors, including the URLs or patterns you chose to watch.
- Runtime state such as how many times a rule has run and when it fires next.
- A local history of monitor hits, and any values extracted from pages you configured.
- Your settings, including the trial start date.
This lives in the browser's extension storage. Uninstalling the extension removes it. We cannot read it.
What reaches our servers, and only if you ask
- Account. If you create one: your email address, a hashed password or the identifier from the sign-in provider you chose, and session records.
- Cloud sync. If you turn it on: the rules and monitors you wrote, plus a device name and identifier so you can see which machines are syncing.
- Change history. If you are on a paid plan: the hits your monitors produced, the URL of the page each hit came from, and a truncated text snapshot used to show what changed. Retained for the period stated on the pricing page, then deleted.
- AI features. When you use one: the text you typed, the page URL, and a bounded excerpt of the page are sent to our model provider (OpenRouter, routing to the model in use) to produce the result. We do not use this content to train models.
- Alerts. The channel details you configure (email address, webhook URL, chat identifier) and the alert contents at the moment we deliver them.
- Payments. Handled by Paddle, our merchant of record. We receive a customer and subscription identifier and your plan status. We never see your card details.
What we never collect
A list of sites you have visited, your browsing history, page contents from sites you have not configured a monitor for, or analytics that identify individual pages you open. The extension has no site access at all until you grant it, one site at a time.
Payments and Paddle
Payments are processed by our reseller and Merchant of Record, Paddle.com ("Paddle"). Paddle collects and processes your payment and billing information (such as name, email, billing address, country and payment details) as an independent data controller in order to process your order, calculate taxes, prevent fraud and meet its legal obligations. We never receive or store your full card details. We receive limited order information from Paddle (such as your email, country, plan and transaction status) to provide the service. See Paddle's Privacy Notice: https://www.paddle.com/legal/privacy.
Service providers
Besides Paddle, we use the following processors to run the service:
- Vercel — hosting of the website and API (United States / global edge).
- Neon — the PostgreSQL database that stores accounts, sync data, history and alert channels.
- Amazon Web Services (SES) — delivery of account email and of the alert emails you configure.
- OpenRouter, and the model providers it routes a request to — AI features only, see below.
- Google and GitHub — only if you choose to sign in with one of them; we receive the identifier and email address of the account you signed in with.
We do not use advertising networks, and the marketing site sets no analytics or tracking cookies.
AI processing
To provide the AI features (rule generation, page summaries, change classification and selector healing), the text you typed, the page URL and a bounded excerpt of the page are sent to our AI service providers (OpenRouter and the model providers it routes to) for processing. We do not use your content to train models, and our providers process it only to return results to you.
Site access
Timed reloads work without access to any website. Access to a specific site is requested only when you use the on-page countdown or keyword monitoring there. You can review and revoke every granted site from the extension's options page, or from your browser's extension settings.
Retention and deletion
Account data is kept while the account exists. Change history and extracted values are deleted after the retention period of your plan. Deleting your account removes your account record, sync data, history and alert channels. Local data is removed by uninstalling the extension.
Your rights
You can request access to, correction of, deletion of, or a copy of your data, and you can object to processing, by writing to support@xeviora.com. Because the great majority of what the product handles never leaves your device, most such requests concern only the account and sync records described above.
If you are in the EU, EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
Children
The service is not directed at children under 13 and we do not knowingly collect their data.
Changes
Material changes will be announced in the extension's release notes before they take effect. The date at the top of this page always reflects the current version.
Contact
Xeviora — support@xeviora.com