Vast Extensions Hub

Privacy Notice

Vast collects no browsing telemetry. The Browser, Relay, Extensions Hub, and independently published extensions are separate data contexts.

The Hub processes GitHub account and profile details used for publisher identity, session and CSRF records, keyed hashes of IP addresses for rate limiting, listings, packages and media stored in D1 and R2, automated and human review records, audit events, terms acceptances, and abuse reports.

Publisher sessions expire after 7 days, OAuth state after 10 minutes, rate-limit hashes after their bounded cleanup window, and unpublished staged packages after 14 days. Reporter contact fields are removed after 1 year and closed reports after 3 years unless a legal hold applies. Published artifacts, terms acceptances, review/audit records, and evidence needed for distribution, security, disputes, or legal compliance may remain longer. The Hub does not receive a user's browsing history from Vast Browser.

Each publisher must separately disclose an extension's data practices and remote services. Vast review does not replace the publisher's privacy obligations.