OddWorks

Privacy Policy

Last updated: 3 October 2026

This Privacy Policy applies to OddWorks software and services that link to it. It explains what information each covered product accesses, why it is used, where it is stored, and the choices available to users.

Products covered

This is the common privacy policy for OddWorks products that link to this page. Product-specific details form part of this policy and describe the actual data practices of each product.

The current product-specific provisions apply to Re:Stack and Re:Form. Re:Stack manages browser-workspace information. Re:Form captures user-selected browser form entries for encrypted recovery and optional autofill. If another OddWorks product has materially different data practices or legal requirements, OddWorks may publish a product-specific supplement and link to it prominently from that product.

1. Privacy approach

Re:Stack and Re:Form are designed to operate locally by default.

OddWorks does not sell personal information, browsing information, form content, or user data. OddWorks products do not use this information for advertising, profiling, creditworthiness, lending decisions, or unrelated analytics.

Each extension accesses browser information only where required to provide its stated user-facing purpose. Optional cloud synchronisation is initiated and controlled by the user.

Chrome Web Store Limited Use

OddWorks products' use and transfer of information obtained through Chrome permissions complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide or improve the extension's disclosed single purpose and user-facing features. OddWorks does not permit humans to read this content except with the user's affirmative consent for a specific support case, where required for security, where required by law, or where data has been aggregated and anonymised for permitted internal operations.

2. Information Re:Stack accesses

Browser tabs and windows

Re:Stack may access information about open browser tabs and windows, including:

  • page URLs;
  • page titles;
  • tab order;
  • active-tab state;
  • pinned state;
  • window structure and position; and
  • information required to restore a browser workspace.

This information is required to capture and restore the user's browser workspace following a browser restart, shutdown, crash, or user-requested restore.

Tab groups

Re:Stack may access:

  • tab-group membership;
  • group names;
  • group colours;
  • collapsed state; and
  • the relationship between groups, tabs and windows.

This information is used to preserve and restore the organisation of the user's browser workspace.

Bookmarks

Re:Stack may access the user's browser bookmarks and bookmark folders.

This allows Re:Stack to provide bookmark management, backup, import, export and restoration functionality.

Re:Stack does not implicitly replace the user's existing bookmark hierarchy when importing a backup.

Re:Stack settings and recovery information

Re:Stack stores information required for its operation, including:

  • extension settings;
  • local recovery checkpoints;
  • named backups and backup metadata;
  • recovery state;
  • device identifiers generated by Re:Stack;
  • synchronisation configuration;
  • continuity and event-history information; and
  • other application state necessary to provide Re:Stack functionality.

A Re:Stack device identifier identifies an installation for recovery and synchronisation purposes. It is not intended to identify the person using the browser.

3. Local storage

Re:Stack stores browser-workspace and recovery information locally within browser extension storage by default.

This may include sensitive information such as URLs and page titles because those details are necessary to accurately restore a browser workspace.

Re:Stack does not require a Re:Stack or OddWorks online account for its core local functionality.

Removing the extension may cause locally stored extension data to be removed by the browser.

4. Chrome profile synchronisation

Re:Stack may allow a user to deliberately publish a portable recovery snapshot using Chrome's profile synchronisation storage.

This is an optional feature.

A portable snapshot may contain browser-workspace information, including URLs and other recovery information. Chrome controls the synchronisation of this information between Chrome profiles and devices.

A snapshot received from another device is not intended to automatically alter the local browser workspace. The user remains in control of restoration.

5. Optional cloud storage

Re:Stack may provide optional synchronisation with supported third-party cloud-storage providers.

Cloud synchronisation is disabled by default and is not required for Re:Stack's local functionality.

When cloud synchronisation is enabled, Re:Stack encrypts continuity data before transmitting it to the selected provider.

Continuity data may include:

  • tab URLs and titles;
  • window and tab organisation;
  • tab-group information;
  • bookmarks;
  • backups and recovery history; and
  • Re:Stack configuration required for continuity between devices.

The cloud-storage provider receives the encrypted backup data and associated file metadata. Re:Stack is designed so that the provider does not need plaintext access to the contents of the encrypted continuity data.

Google Drive

When Google Drive synchronisation is enabled, Re:Stack uses Google's OAuth authentication system and requests the Google Drive drive.file permission.

Re:Stack creates or manages an app-specific _ReStack folder and encrypted Re:Stack backup file.

The drive.file permission is used so Re:Stack can work with files it creates or that are made available to it rather than requesting unrestricted access to all files in the user's Google Drive.

Microsoft OneDrive

When Microsoft OneDrive synchronisation is enabled, Re:Stack uses Microsoft's OAuth authentication system and Microsoft Graph to access the user's OneDrive.

Re:Stack requests the permissions necessary to create and maintain its _ReStack storage location and encrypted backup data.

Microsoft's OneDrive permission model may provide Re:Stack with broader file-storage authorisation than the Google Drive integration requires. Re:Stack uses that access for Re:Stack synchronisation functionality and does not use it to inspect unrelated user files.

Apple iCloud

Apple iCloud/CloudKit integration is not currently an active Re:Stack synchronisation capability.

If Apple cloud synchronisation is introduced, this Privacy Policy will be updated to describe the integration and the information involved before the capability is made generally available.

6. Encryption

Portable and cloud-hosted Re:Stack continuity information is designed to be encrypted before it leaves the extension.

Re:Stack currently uses AES-256-GCM encryption with a key derived from the user's encryption passphrase.

The encryption passphrase is used locally to protect the continuity data.

Users are responsible for retaining their encryption passphrase. Re:Stack and OddWorks cannot recover an encrypted backup if the required passphrase or recovery information is lost.

7. Authentication

Re:Stack may use OAuth to connect to supported cloud-storage providers.

OAuth allows the user to authorise Re:Stack without providing their cloud account password to Re:Stack.

Re:Stack does not ask for or store the user's Google, Microsoft or Apple account password.

Authentication tokens may be temporarily stored within browser session storage where necessary to communicate with the authorised provider.

Re:Stack does not use cloud authentication to create an advertising profile or track users across unrelated services.

Google API Limited Use

Re:Stack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing synchronisation functionality the user enables.

8. Information Re:Stack does not collect

Re:Stack does not intentionally collect:

  • health information;
  • financial or payment information;
  • personal communications;
  • precise location information;
  • keystrokes;
  • mouse movements;
  • page-body content; or
  • information for advertising or behavioural profiling.

Re:Stack does not currently include third-party behavioural analytics or advertising trackers.

Re:Stack does not use content scripts to inspect the contents of webpages.

9. Network access

Re:Stack's network access is limited to services required for optional cloud-storage functionality and authentication.

Depending on enabled integrations, this may include services operated by:

  • Google;
  • Microsoft; and
  • Apple, if Apple integration is introduced.

Re:Stack does not transmit browsing history to OddWorks for advertising, analytics or profiling.

10. Data sharing and sale

OddWorks does not sell Re:Stack user data.

Re:Stack does not share browsing information with third parties for:

  • advertising;
  • marketing;
  • behavioural profiling;
  • creditworthiness or lending decisions; or
  • unrelated data analytics.

When a user explicitly enables a third-party cloud-storage integration, encrypted Re:Stack data is transmitted to that provider as necessary to provide the requested synchronisation or backup functionality.

The provider's handling of the user's account and stored data is also governed by that provider's own terms and privacy policies.

11. Data retention and deletion

Re:Stack's recovery history is designed to use a default retention period of 30 days, subject to the user's configured settings and the type of stored information.

Current browser-workspace state and user-created backups may remain available independently of historical-event retention.

Users can delete Re:Stack information through applicable Re:Stack controls.

Users may also remove Re:Stack data stored with a cloud provider through Re:Stack where supported or directly through the relevant cloud-storage service.

Uninstalling Re:Stack may cause data stored locally by the extension to be deleted by the browser. Data previously exported by the user or stored with an external cloud provider may remain until separately deleted.

12. Security

Re:Stack is designed to minimise access to information and services that are not required for its functionality.

Security measures include:

  • local processing by default;
  • encrypted portable and cloud continuity data;
  • OAuth-based cloud authorisation;
  • PKCE protection during supported OAuth authorisation flows;
  • restricted cloud-provider API endpoints;
  • no requirement for a Re:Stack-hosted account for local functionality; and
  • separation between local recovery and optional external synchronisation.

No software or storage mechanism can guarantee absolute security. Users should protect their browser profile, devices, cloud accounts and Re:Stack encryption credentials appropriately.

13. Re:Form-specific information

Re:Form's single purpose is to securely capture and encrypt browser form entries so the user can review, recover and optionally reuse unfinished form data after refreshes, closed tabs, expired sessions, browser errors or device changes.

Information Re:Form handles

Depending on the websites, forms, capture rules and autofill values selected by the user, Re:Form may handle:

  • user-entered text and rich-text website content;
  • field labels, form identifiers and compatible form structure;
  • website origins, paths and capture times;
  • names, email addresses, telephone numbers, addresses and other identifiers used for recovery or optional autofill;
  • financial or authentication field values only if the user explicitly enables the corresponding higher-risk capture category;
  • encrypted reusable autofill values and website-specific autofill rules;
  • Re:Form settings, recovery metadata and local lifetime value counters; and
  • OAuth access information needed for an optional cloud provider connection.

Re:Form does not request or provide purpose-specific collection of medical history, diagnoses, symptoms or procedures. If a user writes about any subject inside a general text field, Re:Form treats it as user-controlled website content rather than analysing or classifying its subject matter.

Password, one-time-code and payment-field capture are disabled by default. A user must explicitly enable those higher-risk categories. File-input contents and hidden page values are not captured. Re:Form does not silently submit forms.

Website access and activity

Re:Form uses a packaged content script on ordinary HTTP and HTTPS websites covered by the user's chosen all-sites, ask-first or maintained-site-list mode. It reacts to compatible field changes and form navigation only to create recovery checkpoints, offer enabled autofill values and restore data requested by the user. Re:Form stores the resulting allowed field value rather than a log of individual keystrokes, clicks, mouse position or scrolling. It does not use this activity for advertising, employee monitoring or behavioural profiling.

Encryption, retention and deletion

Persistent form records and autofill details are encrypted locally before storage. The master password is not stored. The encryption key is held only for the active browser session after the user unlocks Re:Form.

Encrypted recovery records are removed according to the user's configured retention period. Users can delete individual records, clear applicable local extension data, remove the extension, and delete cloud copies through the connected provider. Removing the extension may cause locally stored data to be removed by the browser.

Optional cloud continuity

Cloud sync is disabled by default. When enabled and connected, Re:Form uploads an encrypted reform-vault.json file to an app-specific folder such as _ReForm in the user's selected provider. The provider receives encrypted content and ordinary file metadata. Plaintext form contents are not sent to OddWorks.

Google Drive connectivity uses OAuth and the limited drive.file permission so Re:Form can create and manage the files it uses without requesting unrestricted access to all Drive files. Microsoft OneDrive support uses the permissions disclosed during its OAuth flow. iCloud is not an active Re:Form integration unless and until the product and this policy say otherwise.

14. Children's privacy

Re:Stack and Re:Form are general-purpose browser productivity and recovery utilities and are not specifically directed at children.

OddWorks does not knowingly use either extension to collect personal information from children for advertising or profiling.

15. Changes to this Privacy Policy

This Privacy Policy may be updated when an OddWorks product's functionality, integrations, data handling practices, or legal obligations change.

The current version will be published at this location with an updated revision date.

Material changes affecting how an OddWorks product handles user information will be reflected in the policy before or when the relevant functionality is released.

16. Contact

Questions about this Privacy Policy or an OddWorks product's handling of information can be sent to:

OddWorks
Email: oddworksdev@gmail.com