Privacy Policy

Effective date: July 15, 2026

This Privacy Policy explains how ZIP Extractor (“we”, “us”, “our”) handles your information when you use the ZIP Extractor browser extension (“Extension”) or the companion web app at zipextractor.vip.

If you do not agree with this policy, please do not install or use the Extension.


What ZIP Extractor Does

ZIP Extractor is a browser extension that lets you open and extract archive files (.zip.rar.7z.tar.gz) directly in your browser. Archive contents are processed entirely on your device using WebAssembly (WASM). File contents are never uploaded to our servers or any third party — with the specific exceptions described below.


What Leaves Your Device

Most processing happens locally. The following are the only scenarios in which data leaves your device:

Data / actionDestinationCondition
SHA-256 hashes, URLs, and if needed file contentsVirusTotal (virustotal.com)Only when you trigger a VirusTotal check with your own API key — file hash/upload or URL scan you initiate
Billing / authaccount.zipextractor.vip (Monetize)Only if you sign in for a Pro trial or subscribe
Your email addressMonetize / payment processorWhen you sign in with Google/email or complete checkout
Auth session tokenaccount.zipextractor.vip (Monetize)Stored locally after you sign in; used to restore Pro entitlement
Files you saveGoogle Drive (Google)Only when you explicitly use the optional Drive save feature
Anonymous usage eventsAmplitude analytics serversWhen analytics is enabled (default on; can be disabled in Settings)
Error stack traces and masked Session Replay recordingsSentryWhen analytics is enabled (default on; can be disabled in Settings)

Archive file contents leave your device only in the VirusTotal and Google Drive cases listed above. Filenames and other on-screen text in Session Replay are masked before upload (see Sentry below).


Information We Do Not Collect

We do not collect, store, or transmit:

  • The contents of any archive files you open or extract.
  • File or folder names inside your archives.
  • Your browsing history or the content of pages you visit.
  • Cookies or tracking pixels inside the Extension.

Information Stored Locally on Your Device

The Extension stores the following data in Chrome’s local extension storage (chrome.storage.local). Unless noted above, none of it leaves your device.

KeyPurposeCleared
displayModeWhether the Extension opens as a tab or side panelPersists until you change it
activeZipExtractorTabChrome tab ID of the active Extension windowCleared when the tab is closed
pendingArchiveURL and filename of an archive opened from a page linkCleared after the archive loads
analytics_device_idRandom UUID used for anonymous analyticsPersists until you reset it in Settings
analytics_opt_outWhether you opted out of analytics and error reportingPersists until you change it
pro_paid_snapshotEncrypted paid subscription snapshot for 72-hour offline grace periodCleared on signout or subscription expiry
Archive workspace sessionTemporary state of the currently open archiveCleared on browser startup or after extraction completes

All locally stored data is accessible only to the Extension.


ZIP Extractor Pro (Subscription)

ZIP Extractor offers an optional paid Pro tier that unlocks additional features (Bulk Extract, PDF Preview, Security Scan). Pro is processed through Monetize (account.zipextractor.vip).

Sign-in and free trial

Pro trial and subscription require signing in through Monetize (account.zipextractor.vip), typically with Google (or another provider configured for the paywall). Anonymous “continue without account” sign-in is not used — that Monetize option applies only to tokenized paywalls, and ZIP Extractor Pro uses a regular opens-based trial.

After you sign in, the auth session is stored locally in chrome.storage.local so entitlement can be restored on this device. Your account email is processed by Monetize as part of authentication.

Subscription and checkout

If you choose to subscribe, checkout uses your signed-in account. Email and payment details are shared with Monetize and the payment processor (Stripe, Paddle, or the acquirer in use). We do not store payment card numbers.

Billing

  • Subscriptions are billed through the payment processor connected to your Pro account.
  • You may cancel anytime from the Extension (Settings → Features → Pro → Manage) or by contacting support at delopappz@gmail.com.
  • Refund policy (draft): Refund requests within 14 days of a charge may be submitted via your payment processor’s support portal or by emailing delopappz@gmail.com with your order details. We review requests in accordance with the processor’s policy. Refunds are not guaranteed after 14 days.

Offline grace period

After your last successful entitlement check, the Extension allows Pro access for up to 72 hours without a network connection. After that grace period, Pro features become unavailable until connectivity is restored and entitlement is confirmed.

Monetize’s privacy practices

When you use Pro features, Monetize’s own privacy policy applies to data handled by Monetize. See monetize.software/privacy.


VirusTotal BYOK (Bring Your Own Key)

ZIP Extractor includes an optional free integration with VirusTotal. To use it, you must supply your own VirusTotal API key in Settings → Features → VirusTotal.

  • On each file check we first send the file’s SHA-256 hash. If VirusTotal already has a report, no file contents are uploaded.
  • If the hash is unknown, the selected file is uploaded from your browser to VirusTotal for analysis (up to 650 MB; files over 32 MB use VirusTotal’s large-file upload URL). Do not check files you are not willing to share with VirusTotal.
  • On a URL check (Open file from URL), the archive URL you entered is submitted to VirusTotal for analysis — no file bytes are downloaded for that check.
  • Requests go directly from your browser to virustotal.com — no server proxy.
  • Your VirusTotal API key is stored locally in chrome.storage.local and is never sent to our servers.
  • VirusTotal’s own terms of service and privacy policy apply. See virustotal.com/gui/terms-of-service.

Google Drive Integration

The Extension offers an optional feature to save extracted files directly to your Google Drive.

When you choose to connect Google Drive, the Extension requests an OAuth2 token from Google using the identity Chrome API. The requested OAuth2 scope is:

https://www.googleapis.com/auth/drive.file

This scope grants access only to files that the Extension itself creates or opens — not to your entire Google Drive. The OAuth2 token is used solely to upload files you explicitly select for saving. You can revoke access at any time from your Google Account permissions page.

When you use Google Drive integration, Google’s own privacy policy applies. See Google Privacy Policy.


Host Permissions and Content Script

The Extension requests access to all websites (https://*/* and http://*/*) in order to run a content script that scans page links for archive file extensions and adds an “Extract” button next to them.

The content script only reads href attributes of <a> elements to detect archive links. It does not read, capture, or transmit page text, form data, passwords, or any other page content.


Downloads Permission

The Extension uses the downloads Chrome API to save extracted files to your local Downloads folder. No download history or metadata is collected or transmitted.


External Websites

On first install, the Extension opens https://zipextractor.vip/welcome/ in a new browser tab. On significant version updates, it opens a changelog page. The Extension’s UI may load content from zipextractor.vip in an embedded frame. These pages are subject to the website’s own privacy practices. The Extension does not pass personal data or file contents to these pages.


Analytics and Error Reporting

The Extension collects optional, anonymous usage analytics, error reports, and masked Session Replay recordings to help us understand how the Extension is used and fix bugs. Analytics is enabled by default; you can turn it off at any time in Settings.

Usage Analytics (Amplitude)

The Extension sends anonymous usage events to Amplitude.

What we collect:

  • A randomly generated device identifier (UUID) stored locally. This ID is not linked to your Google account or any personally identifiable information.
  • Session identifiers (timestamps) to measure session duration.
  • Anonymous usage events such as: opening an archive (format and file size — no filename), extracting files, toggling display mode, switching themes, Pro feature usage (feature key only), and paywall interactions (no email, no archive contents).
  • Extension version and approximate country (derived automatically from your IP address by Amplitude’s servers; the IP itself is not stored by us).

What we do NOT collect:

  • Filenames, archive URLs, or file contents.
  • Your Google account identity or OAuth tokens.
  • Email addresses in analytics events.
  • Any personally identifiable information.

Amplitude’s privacy policy: amplitude.com/privacy.

Error Reporting and Session Replay (Sentry)

We use Sentry to collect anonymous crash reports, error stack traces, and Session Replay recordings that help us reproduce bugs.

Error reports include:

  • JavaScript stack traces and error messages.
  • Extension version.
  • Approximate country (derived from IP by Sentry; IP is not stored by us).

Session Replay records a sample of user sessions in the Extension UI (and all sessions where an error occurs). Before a recording is sent:

  • All on-screen text is masked (including filenames and labels).
  • Media (images, video, canvas) is blocked from the recording.
  • Input fields (such as passwords) are masked.

Archive file contents are not included in error reports or Session Replay. Sentry’s privacy policy: sentry.io/privacy/.

Opting Out

You can disable anonymous usage analytics (Amplitude), error reporting, and Session Replay (Sentry) at any time from the Extension Settings dialog using the Share anonymous usage data toggle.

Resetting Your Analytics Identifier

In Settings → Privacy, you can Reset analytics identifier to generate a new random device ID. Future events are then not linked to your previous anonymous profile.

Requesting Data Deletion

To request deletion of data stored on our analytics and error-reporting providers, use Request data deletion in Settings → Privacy. This opens an email to delopappz@gmail.com with your current device ID pre-filled.

You may also contact us directly at delopappz@gmail.com with your analytics device ID to exercise your right to erasure or other data subject rights under applicable privacy laws including GDPR.


Children

The Extension is not directed at children under 13. We do not knowingly collect any personal information from children.


Changes to This Policy

We may update this policy as the Extension evolves. The “Effective date” at the top of this document will be updated accordingly. Material changes will be noted in the Extension’s changelog.


Contact

Questions, cancellation requests, or data deletion requests:

Email: delopappz@gmail.com

keyboard_arrow_up