Privacy Policy for Jap!
Privacy Policy for Jap!
Effective date: 30 August 2026
Jap! is a Chrome extension developed by Cikgu Slumber to help users manage, search, synchronize, and autofill credentials in shared-device environments such as schools, classrooms, computer labs, offices, and similar settings.
This Privacy Policy explains what information Jap! handles, why it is used, how it is protected, and which third-party services are involved.
By using Jap!, you acknowledge the practices described in this Privacy Policy.
1. Jap! operating modes
Jap! provides Local and Sync functionality.
Local Mode
Local Mode stores workspace information and credentials on the Admin device.
Local Mode does not require:
a Jap! account;
user registration;
Google sign-in;
an email address; or
a Jap! Sync license.
Data stored in Local Mode remains on the device unless the user later chooses to use Jap! Sync.
An Admin may also place a Local Workspace into Local Reader Mode. In Local Reader Mode, authorized users can use permitted Reader functions such as searching and autofilling credentials while administrative controls remain protected by the Admin's Master Password.
Local Reader Mode does not synchronize the Workspace with Jap!'s backend.
Jap! Sync
Jap! Sync is an optional paid feature that allows an Admin to synchronize selected Workspace information with Reader devices using a Sync Code.
Jap! Sync may provide:
Reader synchronization;
Broadcast announcements;
Reader Inbox;
domain-only Activity monitoring;
Workspace updates;
synchronization across supported devices;
Class Session management;
realtime Reader presence;
Reader-to-student assignment;
Remote Fill;
Personal Alert; and
End Class session cleanup.
Jap! Sync does not require Reader users to create a Jap! account.
2. Information Jap! may handle
Depending on the features used, Jap! may handle the categories of information described below.
Authentication information
Jap! may store and process credentials added by an Admin, including:
account display names;
usernames;
email addresses;
passwords;
associated website domains; and
tags or labels.
This information is used only to provide credential management, search, synchronization, Reader access, assignment, and autofill functionality.
Personally identifiable information
Account information entered by an Admin may contain personally identifiable information such as names, usernames, or email addresses.
Jap! Sync licensing may also process the email address used by a purchaser during checkout.
Purchase and payment-related information
Jap! Sync purchases are processed through Buy Me a Coffee and its payment providers.
Jap!'s licensing backend may receive limited purchase metadata necessary to issue and manage a license, such as:
purchase identifier;
transaction identifier;
purchaser email address;
purchased item identifier;
purchase status; and
refund status.
Jap! does not receive, store, or process credit card numbers, bank account numbers, card security codes, or other payment credentials.
Payment credentials are processed by Buy Me a Coffee and its payment providers under their own privacy policies.
Personal communications
Jap! Sync includes communication features such as:
Broadcast;
Reader Inbox; and
Personal Alert.
Messages sent by an Admin may therefore be processed and delivered to connected Reader devices.
Browser activity information
When Activity or Class Session functionality is used, Jap! may process limited Reader status information such as:
Reader device identifier;
Reader device name;
Admin-assigned Reader name;
current website domain;
online/offline status;
session status; and
last-seen timestamp.
For example, Jap! may report:
classroom.google.com
Jap! is designed to process domain-level information only for Activity and Class Session status.
Jap! does not intentionally collect or store:
full webpage URLs;
URL paths;
URL query parameters;
page titles;
page text or webpage content;
screenshots;
mouse movements;
keystrokes;
form contents; or
complete browsing-history logs.
The Activity system is designed to record limited current-domain and last-seen information rather than maintaining a detailed timeline of browsing history.
3. How credentials are used
Credentials stored in Jap! are used to provide the extension's core functionality.
This includes:
searching accounts;
selecting accounts;
filtering accounts using tags;
assigning accounts to Reader devices;
copying permitted information;
identifying appropriate login fields;
filling usernames or email addresses;
filling passwords;
Remote Fill; and
synchronizing credentials with authorized Reader devices when Jap! Sync is used.
Jap! does not use stored credentials for:
advertising;
behavioral profiling;
marketing;
creditworthiness decisions;
lending decisions; or
unrelated purposes.
4. Autofill and website access
Jap! requires access to supported HTTP and HTTPS websites so that it can detect login fields and perform credential autofill when requested.
Jap! may inspect the structure of a webpage locally to identify suitable username, email, and password fields.
This inspection is performed to provide autofill functionality.
Jap! does not upload webpage text, images, page content, or form contents to its backend for advertising, analytics, behavioral profiling, or unrelated purposes.
Some Chrome-protected pages, including certain chrome:// pages and other browser-restricted pages, cannot be accessed or modified by Chrome extensions.
5. Local data and Local Reader Mode
Local Workspaces are stored on the Admin device.
An Admin may enable Local Reader Mode so that a shared computer can provide Reader-style search and autofill without synchronizing its database to Jap!'s backend.
Administrative controls remain protected by the Admin Master Password.
Closing or reopening Chrome does not intentionally convert the device into an unrestricted Admin session.
Users with sufficient technical or operating-system access to a device may potentially access locally stored extension data. Administrators should therefore deploy Jap! only on devices they are authorized to manage.
6. Paste from Spreadsheet and CSV import
Jap! may allow an Admin to import credential information using CSV files or by manually pasting tabular data copied from spreadsheet software.
Supported spreadsheet sources may include applications such as:
Google Sheets;
Microsoft Excel;
LibreOffice Calc; and
similar spreadsheet applications.
When using Paste from Spreadsheet, the user manually copies selected cells and pastes them into Jap!.
Jap! does not require Google OAuth or direct access to the user's Google Drive or private Google Sheets for this feature.
Jap! does not continuously read or monitor clipboard contents.
7. Jap! Sync encryption
For Jap! Sync, credential Workspace data is encrypted on the client before being sent to the synchronization backend.
The Cloudflare backend stores an encrypted synchronization envelope rather than the plaintext credential database.
Reader devices obtain the encrypted data and decrypt it locally using information derived from the applicable Sync Code.
Because a Reader device must decrypt credentials locally in order to perform autofill, a person with sufficient technical access to that Reader device may potentially recover locally available credentials.
Jap! should therefore only be deployed on devices and to users that the Admin is authorized to manage.
8. Sync Codes
Each Sync Workspace may use a Sync Code that allows Reader devices to connect to that Workspace.
A Sync Code should be treated as sensitive Workspace access information.
Users should only share Sync Codes with authorized Reader devices or authorized users.
9. Broadcast and Reader Inbox
Jap! Sync allows an Admin to send Broadcast messages to connected Readers.
Broadcast data may be synchronized through the Jap! backend so that connected Reader devices can receive and display the messages.
Broadcast content is used only to provide the Broadcast and Reader Inbox functionality.
Jap! does not use Broadcast content for advertising or behavioral profiling.
10. Activity monitoring
The Activity feature is intended to help an authorized Admin manage shared Reader devices.
Jap! Activity may process:
Reader device identifier;
Reader device name;
Admin-assigned Reader name;
current domain; and
last-seen time.
Jap! does not provide Activity monitoring involving:
screenshots;
keylogging;
page-content monitoring;
full-URL logging;
mouse tracking; or
detailed browsing-history recording.
Administrators are responsible for using Activity monitoring only where they are authorized to do so and in accordance with applicable school, workplace, organizational, privacy, and local requirements.
11. Class Session and realtime Reader presence
Jap! Sync may provide a Class Session feature for an authorized Workspace Admin.
Class Session allows an Admin to identify Reader devices that are currently available within the same Sync Workspace.
During Class Session functionality, Jap! may process limited realtime information such as:
Reader device identifier;
Reader device name;
Admin-assigned custom Reader name;
current domain;
online/offline status;
account assignment status; and
command delivery status.
This information is used to provide:
Reader discovery;
Reader search;
Reader assignment;
automatic assignment;
Remote Fill;
Personal Alert;
End Class; and
related Class Session controls.
Jap! does not use Class Session presence information for advertising, behavioral profiling, or unrelated monitoring.
12. Custom Reader names
An Admin may assign a custom name to a Reader device within a Workspace, for example:
PC 1
PC 2
Computer Lab 3
Custom Reader names are intended to help an Admin identify shared computers during Class Sessions and Activity monitoring.
The custom name is associated with the Reader device within the applicable Workspace and may remain stored after credentials are autofilled or a Class Session ends.
Logging a website account in or out does not intentionally change the custom Reader name.
13. Reader assignment
During a Class Session, an Admin may assign a credential account from the Workspace database to a connected Reader device.
For example, an Admin may assign one student account to PC 1 and another account to PC 2.
Assignments are used to facilitate Remote Fill and Class Session management.
Admins are responsible for verifying that the correct account is assigned to the correct Reader device.
14. Remote Fill
During a Class Session, an authorized Admin may request Jap! to autofill an assigned credential on a connected Reader device.
The realtime Remote Fill command does not transmit the plaintext password through the realtime command channel.
Instead, the command identifies the relevant account that is already available within the Reader's synchronized Jap! data.
The Reader device then performs the credential autofill locally.
Remote Fill may report operational status such as:
delivered;
filled;
failed; or
Reader offline.
Remote Fill is intended only for credentials and Reader devices that the Admin is authorized to manage.
Jap! does not use Remote Fill to provide general remote-desktop access.
15. Personal Alert
Jap! allows an authorized Admin to send a Personal Alert to:
one Reader;
selected Readers; or
all online Readers in the applicable Class Session.
A Personal Alert may temporarily place a blocking overlay over the Reader's active supported webpage.
The webpage may be visually blurred and interaction with the webpage may be blocked until the Reader acknowledges the alert by pressing OK.
Jap! may process:
the alert message;
target Reader identifiers;
delivery status; and
acknowledgement status.
A Personal Alert may also play a locally packaged notification sound on the Reader device.
Jap! does not capture:
screenshots;
webpage content;
keystrokes;
microphone recordings; or
camera recordings
in order to provide Personal Alert functionality.
Personal Alerts cannot be displayed on Chrome-protected pages where extensions are not permitted to inject content.
16. End Class and session cleanup
Jap! provides an End Class feature intended for shared-computer environments.
When an authorized Admin explicitly ends a Class Session, Jap! may instruct connected Reader devices to remove website session data associated with relevant session origins.
Depending on the applicable site, the cleanup may include:
cookies;
local site storage;
IndexedDB;
cache storage; and
service-worker data.
The purpose of this feature is to reduce the risk of a student's website account remaining signed in on a shared computer after class.
Jap! does not use the Chrome browsing-data permission to collect browsing-history information.
End Class cleanup is intended to target the relevant assigned or active session origins rather than indiscriminately clearing all browser information.
Jap!'s credential database is not intentionally deleted when End Class cleanup is performed.
The following are also intended to remain available unless separately deleted or reset:
Workspace configuration;
Sync configuration;
Reader device identity; and
Admin-assigned custom Reader name.
An End Class command cannot sign a user out of a Chrome browser profile or Chrome Sync account where such access is controlled by Chrome itself rather than a normal website session.
17. Realtime communication
Class Session functionality may use a realtime connection between the Jap! extension and Jap!'s Cloudflare infrastructure.
Realtime communication may be used to provide:
Reader presence;
Remote Fill commands;
Personal Alert commands;
acknowledgement status; and
End Class commands.
Jap! is designed so that realtime commands transmit only the information required to provide the requested functionality.
Credential passwords are not intentionally transmitted as plaintext Remote Fill command data.
18. Jap! Sync licensing
Jap! Sync uses an activation-code licensing system.
When a qualifying Jap! Sync purchase is completed, the backend may generate an activation code and associate it with the purchase.
The licensing system may store:
activation code;
purchase identifier;
purchaser email;
license status;
permitted Admin device count;
permitted Sync Workspace count;
activated device identifiers; and
related timestamps.
The applicable device and Workspace limits are described on the Jap! purchase page or within the product.
Reader devices do not require a paid Jap! Sync license.
19. Activation emails
Jap! may use Resend to deliver Jap! Sync activation emails.
For this purpose, the purchaser's email address and activation-message content may be transmitted to Resend.
Resend is used only for operational or transactional communications related to Jap!, such as delivering an activation code.
Jap! does not use activation-email information for targeted advertising.
20. Buy Me a Coffee
Jap! Sync purchases are handled through Buy Me a Coffee.
Buy Me a Coffee may send purchase events to Jap!'s backend through a secured webhook.
These events may be used to:
verify qualifying Jap! Sync purchases;
generate licenses;
issue activation codes;
enforce applicable license limits; and
update license status when a purchase is refunded.
Buy Me a Coffee processes payment transactions under its own terms and privacy policy.
21. Cloudflare
Jap! uses Cloudflare infrastructure for backend functionality.
Depending on the Jap! feature being used, Cloudflare services may process or store:
encrypted Sync Workspace data;
encrypted Broadcast data;
Reader Activity status;
Reader device identifiers;
Workspace identifiers;
Class Session connection information;
limited Reader presence information;
Remote Fill command metadata;
Personal Alert delivery and acknowledgement information;
authorization-token hashes;
licensing records; and
activated device identifiers.
Cloudflare is used as an infrastructure and service provider and not for advertising purposes.
22. Data stored on the user's device
Jap! uses Chrome extension storage to retain information required for the extension to function.
This may include:
Jap! settings;
interface language;
Admin configuration;
Workspace information;
locally managed credentials;
Local Reader Mode state;
Reader settings;
Reader device identity;
Admin-assigned Reader names;
Class Session assignments;
encrypted synchronization state;
Reader connection state; and
device license state.
The unlimitedStorage permission is used because Jap! may support large imported credential databases and multiple Workspaces.
23. Clipboard access
Jap! may write information to the clipboard when a user explicitly initiates an action that requires copying information.
Examples may include:
an authorized email or username; or
a Workspace Sync Code.
Jap! does not continuously monitor clipboard contents.
Paste from Spreadsheet relies on the user manually pasting information into Jap!.
24. Background tasks
Jap! may use Chrome alarms or other extension background processes to perform lightweight operational tasks such as:
checking for Reader synchronization updates;
checking for Broadcast updates;
refreshing relevant synchronization state; and
maintaining domain-only Activity status.
These background tasks support Jap!'s user-facing functionality.
Class Session realtime communication may use a separate realtime connection when required rather than relying exclusively on scheduled background checks.
25. Chrome permissions
Jap! may request Chrome permissions necessary to provide its functionality.
These may include permissions for:
extension storage;
script injection;
Chrome Side Panel;
clipboard writing;
scheduled background tasks;
expanded local storage capacity;
supported HTTP and HTTPS website access; and
browsing-data cleanup for End Class.
Permissions are used only to provide Jap!'s disclosed functionality.
Jap! does not intentionally request browser permissions for advertising or unrelated surveillance.
26. Remote code
Jap! does not execute remotely hosted JavaScript or other remotely hosted executable code.
Executable JavaScript and CSS used by the Chrome extension are packaged with the extension.
Jap! may communicate with backend APIs and realtime services, but responses and commands received from those services are treated as data and are not evaluated or imported as remotely hosted program code.
27. Data sharing
Jap! does not sell user data.
Jap! does not transfer user data to third parties for:
targeted advertising;
behavioral advertising;
data brokerage;
unrelated marketing;
creditworthiness assessment; or
lending purposes.
Information may be transmitted to service providers only where necessary to provide Jap!'s disclosed functionality.
Relevant service providers may include:
Cloudflare — backend infrastructure, synchronization, realtime Class Session functionality, Activity, and licensing;
Resend — transactional activation emails;
Buy Me a Coffee — Jap! Sync purchasing and purchase notifications; and
payment processors used by Buy Me a Coffee for payment processing.
Each provider may process information under its own privacy policy.
28. No advertising or sale of personal data
Jap! does not:
display targeted advertising;
sell personal information;
sell browsing activity;
sell credential information;
sell Personal Alert content;
build advertising profiles;
use browsing information for personalized advertising; or
use user data for purposes unrelated to Jap!'s stated functionality.
29. Data retention and deletion
Local Jap! data can be removed from a device using available reset or deletion controls.
Admins may also delete information such as:
accounts;
Workspaces;
Sync Workspaces; and
applicable Workspace configuration.
Deleting a Sync Workspace may also remove associated synchronization data and Activity information from the Jap! backend.
Transient realtime Class Session information may be discarded when connections or sessions end unless limited information is required for normal operational functionality.
Purchase and licensing records may be retained where reasonably necessary to:
validate lifetime licenses;
prevent duplicate or fraudulent activations;
manage refunds;
enforce device or Workspace limits;
maintain transactional records; or
comply with legal or operational requirements.
30. Security
Jap! uses reasonable technical measures intended to protect user information.
These measures may include:
client-side encryption of Sync credential data;
hashed authorization tokens;
signed webhook verification;
backend secrets that are not stored inside the Chrome extension;
HTTPS communication;
separation between Admin and Reader authorization;
Workspace-specific synchronization identifiers; and
controlled realtime commands.
No software system can guarantee absolute security.
Users should appropriately protect:
Master Passwords;
Sync Codes;
activation codes;
administrator devices;
Reader devices; and
access to shared computers.
31. Shared devices and administrator responsibility
Jap! is designed for environments where credentials may be managed by an authorized administrator.
Admins should only add, synchronize, monitor, assign, autofill, remotely fill, message, or log out accounts they are authorized to manage.
Organizations using Jap! are responsible for complying with applicable:
laws;
school policies;
workplace policies;
organizational requirements;
contractual obligations; and
privacy requirements.
The Admin is responsible for confirming that each Reader device and account assignment is appropriate before using Remote Fill or other Class Session controls.
32. Children and educational environments
Jap! may be used in educational environments.
Jap! itself does not require Reader users to create a personal Jap! account.
Schools, administrators, teachers, and other organizations are responsible for determining whether and how Jap! may be used with students or minors.
They are also responsible for obtaining any permissions, approvals, notices, or consent required by applicable law or organizational policy.
33. Changes to this Privacy Policy
This Privacy Policy may be updated when Jap!'s:
features;
infrastructure;
Chrome permissions;
legal requirements; or
data practices change.
Material changes will be reflected by updating the effective date and publishing the revised Privacy Policy on the official Jap! privacy-policy page.
34. Contact
For privacy questions, support requests, or requests concerning Jap! data, contact:
Cikgu Slumber
Email: cikguslumber@gmail.com