Team Reply Library privacy
Your Friendly Developer · Version 0.10.0 · Updated September 13, 2026
Team Reply Library helps you create, organize and deliberately reuse personal reply templates. It has no developer-operated account, cloud synchronization, analytics, advertising, AI service or automatic sending.
What stays on your device
The extension stores the replies you create or import: titles, text, tags, folders, usage notes, favorite/archive settings, saved fill-in defaults and choices, identifiers, revisions and timestamps. It also stores recent-reply identifiers, backup-reminder metadata, limited edit history and temporary deletion recovery. These records support the visible library and recovery features.
Encrypted local storage
Version 0.10.0 encrypts local extension records using AES-256-GCM. A key is derived from your library password using PBKDF2-HMAC-SHA-256 with 600,000 iterations and a random salt. A new random nonce is used for each encrypted write. Your password is not saved by the extension or sent to the developer. The derived unlock key is kept in Chrome's in-memory extension session storage, restricted to trusted extension contexts; it is not written into the persistent encrypted-library record.
The library remains unlocked until you lock it, Chrome fully restarts, or the extension is reloaded, updated or disabled. Anyone using the unlocked Chrome profile can access the library. Encryption does not protect against a compromised device or access to an unlocked session. We do not claim forensic erasure, protection of operating-system memory copies or confidential-record certification.
On upgrade, you choose a password before using the library. Existing records are encrypted and checked before their plaintext storage keys are removed. Failed writes leave original data intact; interrupted cleanup can be retried by unlocking. This cannot remove earlier disk copies or old backups. There is no password-reset service. Keep your password safely and retain an exported backup if you need recovery in a fresh installation.
Temporary information when using a reply
When you invoke the extension, it checks the current tab URL/origin and selected field to decide whether direct insertion is supported. The selected field's text, selection and identity are temporarily held in an isolated page context for change checks and Undo. The worker receives bounded target metadata, not the existing draft. This is not a browsing-history log and does not read surrounding inbox messages. No persistent permission to all websites is requested.
Values typed while preparing a reply are used for its preview and are not saved as template defaults unless you separately edit and save the defaults. Clicking Insert reviewed reply sends that reviewed text to the selected supported field. Clicking Copy reply writes the reviewed text to your system clipboard. The extension does not read the clipboard. The destination website can see the text you insert or paste and its own privacy practices apply.
Insertion authority expires after 60 seconds or earlier when the popup closes or its target changes. Undo is available for up to 60 seconds after insertion and refuses to remove newer text. These are functional time limits, not promises that a device has securely erased all memory.
Backups, sharing and deletion
JSON exports are ordinary unencrypted files requested by you. Keep them private. Sharing a backup or pasting a reply shares that content with the recipient you choose. The extension does not send your library, passwords or draft text to the developer or a tracking service.
Edit history keeps up to 10 older versions per reply within a shared 1 MB limit. Oldest versions drop off first. Deleting a reply clears its history. Deleting or replacing the library clears all history and recent-reply metadata. Recent activity stores up to 20 reply identifiers. One deleted-reply recovery copy can remain available for up to 24 hours; a later deletion replaces it, and expired recovery is removed when activity metadata is next checked. History is excluded from JSON exports.
Removing the extension removes its local extension records through Chrome's normal uninstall process. It does not remove downloaded backups or text already pasted elsewhere. Delete those separately if you wish. We do not operate a remote copy of your library that can be recovered on request.
Limited use and permissions
Information accessed through Chrome APIs is used only for the user-facing template, preview, insertion, copy and recovery features described here. It is not sold, used for advertising or credit decisions, or made available to developers for remote inspection. The activeTab and scripting permissions enable a deliberate interaction with a selected supported field; storage saves and protects the local library. Executable code is packaged with the extension; no remote code is loaded.
This website and support email
This information page contains no analytics scripts, forms or automatic extension-data uploads. Its hosting provider may handle ordinary request metadata to deliver and secure the page. Chrome Web Store installation, updates and store interactions are governed separately by Google's policies.
If you email guides@yourfriendlydeveloper.com, your address and message are handled to respond to your request. Do not send library passwords, real customer messages, confidential backups or other private information. Support email is separate from local extension storage.
Changes and contact
Future changes to data handling will be reflected in this page and the relevant store disclosures. Publisher: Your Friendly Developer. Contact: guides@yourfriendlydeveloper.com.