Privacy Policy for Alphafox Auth Sync Extension

Last updated: July 30, 2026

Alphafox Auth Sync helps an Alphafox user detect an existing web login session for a supported cryptocurrency exchange and create or update the corresponding exchange-authentication record in the user's own Alphafox account.

This policy describes data handled by the extension itself. The Alphafox website and the rest of the Alphafox service are also subject to the general Alphafox privacy policy.

Supported Exchanges and Authentication Data

The extension handles authentication cookies, session tokens, and selected request headers from Binance, OKX, Bitget, Bybit, and Gate.io. The required values are Binance p20t plus a CSRF header, the OKX token Cookie or Authorization fallback, the Bitget bt_newsessionid and bt_rtoken Cookies, the Bybit secure-token Cookie, and the Gate.io token Cookie.

Chrome's Cookies API returns cookies available for a supported exchange domain. The extension examines those cookies to locate the required authentication values and, where available, derive an exchange account username or account ID used to identify the account being synchronized. It does not include the raw Binance x_token value in the constructed credential sent to Alphafox, but available Binance Cookie values can be examined by the local account-identifier detector.

Other Data Handled

The extension handles Alphafox session information that may include user ID, email address, name, profile image, email-verification state, account timestamps, and roles. It can also handle exchange usernames or account IDs derived from supported cookies or an Authorization header.

Operational metadata includes the supported exchange domain, credential type and capture source, capture time, required Cookie names, a randomly generated browser-profile ID and label, linked Alphafox record IDs, and Bitget automatic-synchronization status.

The extension receives an active or completed tab URL long enough to determine whether it belongs to a supported exchange. Unsupported URLs are not stored or transmitted. The extension does not read page text, images, form contents, balances, orders, positions, payment-card data, or the user's Alphafox password.

How Data Is Collected

The background service checks supported exchange sessions when it starts, when the user requests a refresh, when a supported exchange page finishes loading, and when matching requests contain a Cookie, CSRF, or Authorization header that can contribute to credential detection. These checks can occur before the user chooses to transmit a credential to Alphafox.

The first Alphafox credential record is transmitted only after the user chooses Create or Sync. After the user manually binds a Bitget record, changes to either required Bitget Cookie can automatically update that same bound record. The extension does not create a new Bitget record in the background.

How Data Is Used

Data is used only to detect Alphafox and supported-exchange sessions, show masked status, help prevent synchronization to the wrong exchange account, manage the user's Alphafox exchange-authentication records, associate a browser profile with the intended record, and update an already bound Bitget record when its required Cookies change.

Local Storage and Retention

The extension uses Chrome storage.local. Stored data can include the latest constructed exchange credential and capture metadata, the last successfully synchronized Bitget credential, cached Alphafox session and masked record data, browser-profile information, linked record IDs, and automatic-synchronization status. Credential values are not masked before being written to storage.local.

Signing out of Alphafox prevents authenticated synchronization but does not by itself delete every locally stored value. Uninstalling the extension removes its local extension storage through Chrome. A synchronized server record remains in the user's Alphafox account until the user deletes it or it is removed under Alphafox account and data-retention policies.

Transmission and Sharing

The extension transmits data over HTTPS only to Alphafox API endpoints under alphafox.app. A synchronization request can include the exchange, credential type, full credential value, capture and browser-profile metadata, and a derived exchange account username or account ID.

The extension does not send exchange credentials to advertising networks, data brokers, third-party analytics services, or any non-Alphafox service. It does not sell user data or use it for personalized advertising, creditworthiness, or lending decisions.

Security

Data sent from the extension to Alphafox is transmitted over HTTPS. Chrome isolates extension storage from ordinary website scripts. No method of transmission or electronic storage is completely secure, and users should protect access to their operating-system account and Chrome profile.

Permissions

The cookies permission examines supported-domain cookies; storage keeps credential and synchronization state; activeTab and tabs identify supported exchange pages; webRequest observes Cookie, CSRF, or Authorization request headers that can contribute to credential detection without blocking or modifying requests; and host permissions limit access to Alphafox and the declared supported-exchange domains.

User Choices and Controls

Users can choose whether to create or manually synchronize a record, select or switch the record associated with a browser profile, delete an Alphafox exchange-authentication record, sign out to prevent authenticated synchronization, and uninstall the extension to remove Chrome local extension storage.

Removing an Alphafox server record does not necessarily remove every locally cached value. Uninstall the extension to remove its Chrome local extension storage.

Chrome Web Store Limited Use

The extension uses user data only to provide or improve its single purpose of synchronizing supported exchange web authentication information with the user's Alphafox account. Its use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Third-Party Services

The extension interacts with Alphafox and supported exchange websites. Alphafox Auth Sync is not affiliated with or endorsed by Binance, OKX, Bitget, Bybit, Gate.io, or any cryptocurrency exchange.

Children's Privacy

The extension is not intended for children under 18. Alphafox does not knowingly collect personal data from children through the extension.

Changes to This Policy

Alphafox may update this policy when the extension's behavior, permissions, or legal obligations change. Material changes will be reflected in the published policy before or when the corresponding extension change is released.