Privacy Policy — RoPA Pilot
Last updated: 2026-07-10
RoPA Pilot is a GDPR compliance tool. It is built so that your data never leaves
your browser — that is the product's core design, not a marketing line.
What the extension processes locally
- Detected tools — when a tab finishes loading, the extension compares the
tab's domain name (hostname) in memory against its built-in catalog of known SaaS tools. If
the domain matches a known tool, only the tool's identifier and dated counters are stored
locally. Full URLs are never stored. Page content is never read (the extension
contains no content script). Domains that are not known SaaS tools leave no trace.
- Your register — organizations, processing records, DPA tracking and
settings are stored locally using the browser's
chrome.storage API.
- Exports (CSV, JSON, printable register, privacy notices) are generated
locally in your browser and saved to your device. Imports (JSON restore)
read a file you pick from your device, entirely in the browser.
- DPA review reminders (Pro) — a local system notification when a DPA
review date is overdue, computed from your local register. It is never triggered by the
network and contains nothing beyond the record's name.
None of the above is transmitted anywhere.
The only network call: license check (Pro)
- License key — an opaque, randomly generated identifier (UUID) created on
your device. It is sent to our licensing backend (
https://ropapilot.leandro-sierra.com)
only to check whether a Pro subscription is active, or to start the 14-day trial. It is not
linked to your identity by the extension and contains no personal data.
We do not collect: your name, email, address, browsing history, page
content, or any personally identifiable information.
The website (ropapilot.leandro-sierra.com)
The extension and the website are separate surfaces. The website — and only the website —
can process an email address, and only when you type one yourself:
- Compliance watch signup (
/api/subscribe) — the email address
you submit, the page it came from and your locale, stored to send the monthly watch. One click
to unsubscribe. Never sold, never shared.
- Contact / quote form (
/api/contact) — email, optional name and
your message, stored solely to answer you.
- Free online register generator — everything you type stays in your browser
(local storage); CSV and PDF exports are built client-side. No field of that form is
ever transmitted.
- Audience measurement — cookieless, without any persistent identifier
(GoatCounter, self-hosted in the EU). No profiling, no advertising, no third-party beacon.
Legal basis: consent (watch signup) or legitimate interest in answering you (contact form).
Retention: until unsubscription for the watch, 24 months for contact messages. Requests for
access, rectification or erasure: contact@leandro-sierra.com.
What we do NOT do
- We do not sell or rent any data — there is nothing to sell.
- We do not use advertising or analytics trackers inside the extension.
- We do not read or inject anything into web pages (no content scripts,
no
host_permissions).
Payments
Pro subscriptions are processed by Stripe. Payment details are entered on
Stripe's hosted checkout and handled entirely by Stripe — the extension never sees or stores
them. See Stripe's privacy policy for how they process payment data.
Data location & retention
- Local data (
chrome.storage) lives on your device. You can clear detection
history from the settings page at any time; uninstalling the extension removes everything.
- The licensing backend stores only the license key and its subscription status (Stripe
customer/subscription identifiers), hosted in the EU (Germany).
Your choices
- Clear detection history: Settings → Local data → "Clear detection history".
- Delete everything: uninstall the extension.
- Cancel a Pro subscription: use the Stripe-hosted portal from your checkout confirmation
email, or contact us.
Contact
Questions about privacy: contact@leandro-sierra.com