AdShy Privacy Policy
Service operator: Vyacheslav Rodkin, individual developer. Contact: zzulyss@gmail.com.
1. What the extension does
AdShy detects and hides advertising blocks on web pages. A content script analyses the page inside your browser. Blocks with an explicit ad label ("Advertisement", "Sponsored", "Promoted", etc.; multilingual labels and known advertising slots are recognised locally) are hidden locally without contacting the server. Only if you have accepted the first-run consent screen, blocks with ad signals that have no stored answer in the browser are sent to the server. If you decline (or have not decided yet), nothing is sent to the server and only local detection runs.
2. Consent
When the extension is first installed it opens a consent screen and does not register or send anything until you press "Accept". The screen states what is sent (site origin, cleaned excerpts of up to 600 characters of suspected ad blocks, link domain and element type, an anonymous installation ID), that it goes to the AdShy server and on to OpenRouter and an AI model provider, and links to this policy. "Decline" keeps the extension in local-only mode. You can withdraw or give consent at any time in the toolbar popup; withdrawing deletes the server token and the queue of unsent marks from the browser. Your account record on the server can be deleted on request (section 10).
3. Data sent to the server (only after consent)
3.1. Installation registration
After you accept the consent screen the extension sends a random installation ID (UUID, created locally) with the extension version number. The server creates an account record and returns a signed token, which is stored in the extension and sent with requests.
3.2. Block check (up to 20 blocks per request)
- the installation ID and the token;
- the page origin only — scheme, domain and port (e.g.
https://example.com), without path, query or page title. This is web browsing information: the server learns the domain of every site on which a suspected ad block was found (it does not receive a list of all pages you visit); - for each block: up to 600 characters of its text after cleaning — the visible text and, for images, the
alt/titleattributes; links are replaced with domain names, e-mail addresses with[email], and long numbers (including phone numbers with spaces, parentheses or separators) with[number]. Names, postal addresses and other free text are not masked. - the domain the block links to;
- the element type (article, div, aside, iframe, …) and technical ad signals (e.g.
sponsored,banner,promo,iframe).
3.3. Your marks
When you click "Yes", "Not an ad" or use the context menu item "AdShy: hide as ad", the server receives the key (hash) of the checked block and your decision (ad / not an ad). Context-menu marking first checks the block as in 3.2 to obtain that key. Votes count towards a shared verdict only when they come from different accounts and different networks.
4. What is not sent
- full page HTML, full page URLs (path and query), page titles, cookies;
- form and input contents, passwords; blocks inside forms, input fields, chats and messages are not analysed;
- pages that look private are not analysed at all, and the same list is enforced again by the server (if a request for such a site ever reaches it, it is rejected without being classified, charged or forwarded): banks and other financial sites (for example Chase, Citi/Citibank, Bank of America, Wells Fargo, Capital One, Barclays, HSBC, Santander, American Express, Schwab, Fidelity, Vanguard, Commonwealth Bank, Westpac, ANZ, NAB, RBC, Scotiabank, BMO, DBS, OCBC, UOB, Maybank, ICBC, Itaú, Bradesco, Mercado Pago, and any host with a
bank/bankinglabel); PayPal and Stripe checkout/billing hosts andcheckout./pay./payments.subdomains; health portals (MyChart andpatient/patientportal/healthhosts); webmail and messengers (Gmail, Proton Mail, Outlook, Yahoo/AOL/iCloud/Fastmail/Zoho mail, Yandex and Mail.ru mailboxes, Telegram Web, WhatsApp Web, Discord); sign-in hosts (login.,auth.,accounts.,signin.,passport.,id.,oauth.,webmail.,inbox.); pages with a password or payment-card field or embedded Stripe/PayPal frames; paths containingcheckout,payment,billing,login,account,settings,messages,inbox,chat,patient,password,webmail; sites on your exclusion list (client side).
These rules are a best-effort list, not a guarantee: they do not cover every bank, medical or other private site in the world. Add such sites to the exclusion list in the extension settings.
5. IP address
The server receives your IP address as part of any network connection. The service does not store IP addresses in plain form:
- for rate limiting it computes an HMAC-SHA256 keyed hash of the IP address (for IPv6, of the /64 network prefix), truncated to 32 hex characters, used as a counter key that is deleted after 2 minutes (per-minute limit), 2 hours and 2 days (registration limits); registration is also limited per network with a similar hash of the IPv4 /24 (IPv6 /48) network, kept for the same 2 hours / 2 days;
- to count votes from distinct networks it stores an HMAC-SHA256 keyed hash of "block key + IP address" for 7 days after the last vote on that block.
These hashes use a server-held secret key and separate purposes for request limits, registration, subnets and voting. We do not link the hashes to other data. No web-server access logs are kept for adshy.asistbot.ru; web-server error logs may briefly contain IP addresses of failed connections.
6. Server-side retention
| Data | Retention |
|---|---|
| AI answer cache: key = SHA-256 of (origin, normalised text, link domain, element type, signals, model); value = a numeric score only. The block text itself is not stored. | 7 days |
| Check "receipt" (user ID + block key), needed to accept your mark | 7 days |
| Votes per block (user ID → decision; IP hash → decision) and totals | 7 days after the last vote |
| Account record: random user ID, installation ID, plan, daily quota, subscription status and expiry, creation and last-seen times, extension version; installation ID → user ID mapping | until deleted on your request |
| Daily usage counter | 2 days |
| Aggregate AI usage statistics per day (number of calls and checks, token counts and cost reported by the AI provider; no text, no user ID, no IP address) | 35 days |
| Technical service logs (events without block text and without IP addresses; per-call token counts and cost; for skipped private sites only a coarse category such as "financial", never the site address) | container log rotation |
Checks that fail on our side (for example provider errors or timeouts) are not counted against your daily limit.
The debug mode that logs block text is disabled in production.
7. Sub-processors and third parties
To provide the service the data in section 3 passes through the following parties, each of which processes it only to classify advertising blocks:
- The AdShy server — a virtual server rented by the operator from a hosting provider; it receives all data in section 3 and stores what is listed in section 6.
- OpenRouter, Inc. — an API gateway (openrouter.ai/privacy). It receives the block data for classification and passes it to the model provider.
- The AI model provider — the company that runs the AI language model reached via OpenRouter and returns the classification verdict. The model and its provider may change; the current provider is listed on request at zzulyss@gmail.com.
What is forwarded to OpenRouter and the model provider: the block data from 3.2 (origin, cleaned text, link domain, element type, signals) — without the token, the installation ID and your IP address. OpenRouter and the model provider process requests under their own terms and privacy policies and may retain them as those policies state. AdShy is not affiliated with Google, OpenRouter or any AI model vendor. We do not sell data, do not use it for advertising, credit scoring or any purpose unrelated to ad filtering, and do not share it with anyone else except where required by law. The operator does not read the text of requests: it is not written to the database or to logs.
8. Data in your browser
chrome.storage.local holds: settings and the exclusion list, the installation ID, the token, the daily-limit state, your personal rules (block hashes, structural position signals and the cleaned block description as in 3.2), AI answers (up to 1 hour), your consent choice and its time, and a queue of unsent marks (up to 500). Personal rules are kept for 365 days; at most 3000 entries are stored. This data does not leave the browser except as described in section 3 and is removed when you uninstall the extension or press "Reset my rules".
9. Analytics and advertising
The extension and the website use no analytics, ad networks, trackers or third-party scripts.
10. Deleting your data
- Uninstall the extension — this removes all data in the browser.
- To delete your account record on the server, e-mail zzulyss@gmail.com with your account ID (shown in the extension settings window). Without the ID we cannot tell which data is yours. We delete the record within 30 days. Other server-side data expires automatically as listed in section 6.
Depending on where you live (for example under the EU/UK GDPR, the California CCPA/CPRA or the Australian Privacy Act), you may have the right to access, correct or delete your data, to object to or restrict processing, and to complain to your local data protection authority. Write to zzulyss@gmail.com; we answer within 30 days. We do not sell personal information and do not share it for cross-context behavioural advertising.
11. Chrome Web Store
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
12. Local backups
Protected backups of the repository, configuration and database are made daily on the same server. Backups are not sent to third parties. Automatic deletion is disabled until retention is approved; account deletion requests include backup handling.
13. Changes
A new version is published on this page with a new effective date. Material changes will be announced in the extension description.
Русская версия
Политика конфиденциальности AdShy
Оператор сервиса: Вячеслав Родкин, частный разработчик. Контакт: zzulyss@gmail.com.
1. Что делает расширение
AdShy находит и скрывает рекламные блоки на веб-страницах. Для этого content script анализирует страницу в вашем браузере. Блоки с явной пометкой рекламы («Реклама», «Sponsored» и т. п.) скрываются локально, без обращения к серверу. Только если вы приняли экран согласия при первом запуске, на сервер отправляются блоки с рекламными признаками, для которых в браузере ещё нет сохранённого ответа. Если вы отказались (или ещё не решили), на сервер ничего не отправляется, работает только локальный поиск.
2. Согласие
При первой установке расширение открывает экран согласия и ничего не регистрирует и не отправляет, пока вы не нажмёте «Принять». На экране указано, что отправляется (origin сайта, очищенные фрагменты до 600 символов подозрительных рекламных блоков, домен ссылки и тип элемента, анонимный идентификатор установки), что данные попадают на сервер AdShy, а далее в OpenRouter и поставщику ИИ-модели, и есть ссылка на эту политику. «Отклонить» оставляет расширение в локальном режиме. Согласие можно отозвать или дать в любой момент в окне расширения; при отзыве из браузера удаляются токен сервера и очередь неотправленных отметок. Запись аккаунта на сервере можно удалить по запросу (раздел 10).
3. Какие данные отправляются на сервер (только после согласия)
3.1. Регистрация установки
После принятия экрана согласия расширение отправляет случайный идентификатор установки (UUID, создаётся локально) вместе с номером версии расширения. Сервер создаёт запись аккаунта и возвращает подписанный токен, который хранится в расширении и передаётся в заголовке запросов.
3.2. Проверка блока (до 20 блоков за запрос)
- идентификатор установки и токен;
- origin страницы — только схема, домен и порт (например,
https://example.com), без пути, параметров и заголовка страницы. Это информация о посещении сайтов: сервер узнаёт домен каждого сайта, на котором найден подозрительный блок (список всех посещённых вами страниц он не получает); - для каждого блока: до 600 символов его текста после очистки — видимый текст и, для изображений, атрибуты
alt/title; ссылки заменены на доменные имена, e-mail — на[email], длинные числа (включая телефоны с пробелами, скобками и разделителями) — на[number]. Имена, почтовые адреса и другой произвольный текст не маскируются.; - домен, на который ведёт ссылка блока;
- тип элемента (article, div, aside, iframe и т. п.) и технические рекламные признаки (например,
sponsored,banner,promo,iframe).
3.3. Ваши отметки
Когда вы нажимаете «Да», «Не реклама» или выбираете в контекстном меню «AdShy: это реклама», на сервер отправляется ключ проверенного блока (хэш) и ваше решение («реклама» / «не реклама»). При отметке через контекстное меню блок сначала проверяется так же, как в п. 3.2, чтобы получить этот ключ. Отметки разных пользователей учитываются, только если они пришли от разных аккаунтов и из разных сетей.
4. Что не отправляется
- полный HTML страницы, полные адреса страниц (путь и параметры), заголовки страниц, cookies;
- содержимое форм и полей ввода, пароли; блоки внутри форм, полей ввода, чатов и переписки не анализируются;
- страницы, которые выглядят приватными, не анализируются вообще, а тот же список дополнительно применяется сервером (если запрос по такому сайту всё же дойдёт до сервера, он отклоняется без классификации, списания лимита и передачи ИИ): банки и другие финансовые сайты (например, Chase, Citi/Citibank, Bank of America, Wells Fargo, Capital One, Barclays, HSBC, Santander, American Express, Schwab, Fidelity, Vanguard, Commonwealth Bank, Westpac, ANZ, NAB, RBC, Scotiabank, BMO, DBS, OCBC, UOB, Maybank, ICBC, Itaú, Bradesco, Mercado Pago и любые адреса с меткой
bank/banking); хосты оплаты и биллинга PayPal и Stripe и поддоменыcheckout./pay./payments.; медицинские порталы (MyChart и адресаpatient/patientportal/health); веб-почта и мессенджеры (Gmail, Proton Mail, Outlook, почта Yahoo/AOL/iCloud/Fastmail/Zoho, ящики Яндекса и Mail.ru, Telegram Web, WhatsApp Web, Discord); адреса входа (поддоменыlogin.,auth.,accounts.,signin.,passport.,id.,oauth.,webmail.,inbox.); страницы с полем пароля или платёжной карты, со встроенными формами Stripe/PayPal; пути сcheckout,payment,billing,login,account,settings,messages,inbox,chat,patient,password,webmail; сайты из вашего списка исключений (на стороне клиента).
Список составлен по возможности полно, но это не гарантия: он не охватывает все банки, медицинские и другие приватные сайты в мире. Добавьте такие сайты в «Не проверять сайты» в настройках расширения.
5. IP-адрес
Сервер получает ваш IP-адрес при любом сетевом соединении. Сервис не сохраняет IP-адрес в открытом виде:
- для ограничения частоты запросов вычисляется HMAC-SHA256 с серверным секретом от IP-адреса (для IPv6 — от префикса сети /64), усечённый до 32 шестнадцатеричных символов; он используется как ключ счётчика, который удаляется через 2 минуты (поминутный лимит), 2 часа и 2 суток (лимиты регистрации); регистрация также ограничивается по сети с помощью аналогичного хэша сети IPv4 /24 (IPv6 /48), который хранится те же 2 часа / 2 суток;
- для подсчёта голосов из разных сетей хранится HMAC-SHA256 с серверным секретом от пары «ключ блока + IP-адрес» — 7 дней после последнего голоса по этому блоку.
Хэши защищены серверным секретом; для лимитов запросов, регистрации, подсетей и голосов используются разные назначения. Мы не связываем их с другими данными. Журналы доступа веб-сервера для adshy.asistbot.ru не ведутся; системные журналы ошибок веб-сервера могут кратковременно содержать IP-адреса неудачных соединений.
6. Хранение на сервере
| Данные | Срок хранения |
|---|---|
| Кэш ответов ИИ: ключ — SHA-256 от (origin, нормализованный текст, домен ссылки, тип элемента, признаки, модель); значение — только числовая оценка. Сам текст блока не хранится. | 7 дней |
| «Квитанция» проверки (ID пользователя + ключ блока) — нужна, чтобы принять вашу отметку | 7 дней |
| Голоса по блоку (ID пользователя → решение; хэш IP → решение) и итоговые счётчики | 7 дней с последнего голоса |
| Запись аккаунта: случайный ID пользователя, ID установки, тариф, дневной лимит, статус и срок подписки, даты создания и последней активности, версия расширения; связь «ID установки → ID пользователя» | до удаления по вашему запросу |
| Счётчик использованных проверок за сутки | 2 дня |
| Суточная агрегированная статистика использования ИИ (число вызовов и проверок, токены и стоимость, сообщённые ИИ-провайдером; без текста, ID пользователя и IP) | 35 дней |
| Технические журналы сервиса (события без текста блоков и без IP; число токенов и стоимость каждого вызова; для пропущенных приватных сайтов — только грубая категория, например «financial», но не адрес сайта) | ротация журналов контейнера |
Проверки, не выполненные по нашей вине (например, ошибки или тайм-ауты провайдера), не засчитываются в ваш дневной лимит.
Режим отладки, при котором в журнал пишется текст блоков, в рабочей версии выключен.
7. Субобработчики и третьи лица
Для работы сервиса данные из раздела 3 проходят через следующих лиц; каждое обрабатывает их только для классификации рекламных блоков:
- Сервер AdShy — виртуальный сервер, арендуемый оператором у хостинг-провайдера; получает все данные из раздела 3 и хранит то, что указано в разделе 6.
- OpenRouter, Inc. — API-шлюз (openrouter.ai/privacy). Получает данные блока для классификации и передаёт их поставщику модели.
- Поставщик ИИ-модели — компания, которая запускает ИИ-языковую модель, доступную через OpenRouter, и возвращает вердикт. Модель и поставщик могут меняться; текущего поставщика назовём по запросу на zzulyss@gmail.com.
Что передаётся OpenRouter и поставщику модели: данные блока из п. 3.2 (origin, очищенный текст, домен ссылки, тип элемента, признаки) — без токена, ID установки и вашего IP-адреса. OpenRouter и поставщик модели обрабатывают запросы по своим условиям и политикам конфиденциальности и могут хранить их, как там указано. AdShy не связан с Google, OpenRouter и разработчиками ИИ-моделей. Мы не продаём данные, не используем их для рекламы, кредитного скоринга или любых целей, не связанных с фильтрацией рекламы, и не передаём их другим лицам, кроме случаев, предусмотренных законом. Оператор не читает тексты запросов: они не записываются ни в базу данных, ни в журналы.
8. Данные в вашем браузере
В chrome.storage.local хранятся: настройки и список исключений, ID установки, токен, состояние дневного лимита, ваши личные правила (хэши блока, структурные признаки положения на странице и очищенное описание блока в объёме п. 3.2), ответы ИИ (до 1 часа), ваш выбор по согласию и его время и очередь неотправленных отметок (до 500). Личные правила хранятся 365 дней; всего хранится не более 3000 записей. Эти данные не покидают браузер, кроме отправки, описанной в п. 3, и удаляются при удалении расширения или кнопкой «Сбросить мои правила».
9. Аналитика и реклама
Расширение и сайт не используют аналитику, рекламные сети, трекеры и сторонние скрипты.
10. Удаление данных
- Удалите расширение — это удалит все данные в браузере.
- Чтобы удалить запись аккаунта на сервере, напишите на zzulyss@gmail.com и укажите ID аккаунта (показан в окне настроек расширения). Без ID мы не можем определить, какие данные ваши. Мы удалим запись в течение 30 дней. Остальные серверные данные удаляются автоматически в сроки из п. 6.
В зависимости от страны проживания (например, по GDPR в ЕС и Великобритании, CCPA/CPRA в Калифорнии или Privacy Act в Австралии) у вас может быть право на доступ к данным, их исправление и удаление, на возражение против обработки или её ограничение, а также на жалобу в местный надзорный орган. Пишите на zzulyss@gmail.com; мы отвечаем в течение 30 дней. Мы не продаём персональные данные и не передаём их для поведенческой рекламы.
11. Chrome Web Store
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Использование информации, полученной от расширения, соответствует Политике пользовательских данных Chrome Web Store, включая требования об ограниченном использовании (Limited Use).
12. Локальные резервные копии
Защищённые копии репозитория, конфигурации и базы делаются ежедневно на том же сервере, без отправки третьим лицам. Автоматическое удаление отключено до решения о сроке хранения; запросы удаления аккаунта учитывают резервные копии.
13. Изменения
Новая редакция публикуется на этой странице с новой датой вступления в силу. О существенных изменениях мы сообщим в описании расширения.