Privacy Policy
Daybreak - New Tab · Last updated: September 7, 2026 · reviewed for version 2.3.0
Daybreak ("the extension") is a browser extension that replaces the Chrome new tab page with a customizable start page. This policy explains what data the extension accesses and how it is handled. In short: the extension does not collect, store, or transmit your personal information to the developer. It has no analytics, no advertising, no user accounts, and no tracking.
Data stored on your device
Your preferences — which widgets are on your board and how they are arranged, your theme and colours, your links, your to-do items, your cities, and each widget's settings — are saved with the browser's extension storage and synced across the devices where you are signed in to Chrome.
Content that individual widgets create is stored locally on your device, and two of these also sync if they are small enough: your scratchpad text (up to about 6KB) and your habit history (trimmed to roughly the last year), each in their own limited slot so a long note cannot crowd out your other settings. Anything over that size simply stays on the device where you wrote it. The most recent weather reading, kept so the tile still shows something offline, always stays local. All of this stays in your browser, is never sent to the developer, and is removed if you uninstall the extension. You can export a copy of everything, or erase it, from Settings.
Optional features that read browser data
These features need access to something in your browser, and each one asks for its own permission at the moment you turn it on. Chrome shows the request; nothing is read before you accept, and you can revoke any of them at any time from Chrome's extension settings. Everything below is read on your device, shown only on your new tab page, and never sent anywhere.
-
Recent Tabs widget —
sessions. Lists tabs and windows you recently closed so you can reopen them. -
Search suggestions from open tabs —
tabs. Offers the tabs you already have open as you type, and switches to one instead of opening a duplicate. -
Search suggestions from history —
history. Matches what you type against pages you have visited before. Only the titles and addresses of matches are read, only while you are typing. -
Bookmarks —
bookmarks. Two features use this permission. Search suggestions match what you type against your saved bookmarks, reading only the titles and addresses of matches and only while you are typing. The Bookmarks widget shows your bookmark folders on the new tab page, and lets you add, rename, move and delete bookmarks and folders from the widget’s own settings. Those edits are made in Chrome’s bookmarks — that is the point of the widget: it shows and edits the one list your browser already keeps rather than a private copy of it, so nothing can drift out of step. Deleting anything asks for a second confirming tap, and deleting a folder tells you how many bookmarks go with it. Your bookmarks are read and written on this device only. None of them is uploaded, sent anywhere, or seen by anyone but you. -
Top Sites widget —
topSites. Shows the sites you visit most often as shortcuts. Chrome supplies the list it has already compiled for its own new tab page; the extension reads the titles and addresses in it to draw the tiles, and nothing else. It is read at most once per new tab, it never leaves your browser, and hiding a site from the widget is remembered locally rather than changing anything in Chrome. -
Pasting a copied link —
clipboardRead. When you add a Quick Link, the address you have just copied is offered in the address field so you do not have to paste it by hand. The clipboard is read only while that add form is open, and only to fill in that one field. Nothing from your clipboard is stored, kept after the form closes, or sent anywhere. This is requested the first time you press “Paste what I copied” inside the widget, never at install, and you can withdraw it at any time from Chrome’s own permission list — the field simply goes back to being typed in by hand. -
Site icons —
favicon. Lets search suggestions show a page's real icon. This reads Chrome's own, already-cached favicon store — it does not make a request to the site itself. Requested the first time you turn on one of the search suggestion sources above.
If you do not turn a feature on, its permission is never requested and the extension never reads that data. Each source can also be switched off individually under Search suggestions in Settings.
Optional access to a single address you provide
Some widgets work with a private address you paste in yourself — for example a calendar's iCal link, or a feed URL. When you do this, the extension asks Chrome for permission to fetch that one address, and only that one; nothing is granted for any other site. Chrome shows the request at the moment you add the address, and you can revoke it at any time from Chrome's extension settings. The address itself is stored only in your own synced settings — it is never logged, displayed elsewhere, or sent to the developer.
Information sent to third parties
To provide certain features, the extension communicates directly with the following third-party services. The developer does not operate any server and does not receive any of this data.
-
Weather and Air quality — Open-Meteo. When either
feature is enabled, the name(s) of the city/cities you configure are
sent to Open-Meteo (
open-meteo.comand itsair-quality-api.andgeocoding-api.subdomains) to look up coordinates and retrieve current conditions. No account or API key is involved. See the Open-Meteo terms & privacy. -
Currency — Frankfurter. The base currency and the
currencies you choose to track are sent to Frankfurter
(
api.frankfurter.dev), which serves European Central Bank exchange rate data. No account or API key is involved. If you turn on the Iranian Rial, its rate is fetched from tgju.org (call1.tgju.org), which needs a one-time permission for that single address, or from exchangerate-api.com's open endpoint (open.er-api.com) when that isn't available — either way, only the request itself is sent, with no query and no personal data. -
Crypto — CoinGecko. The coins and fiat currency you
choose are sent to CoinGecko's public API
(
api.coingecko.com) to look up prices. No account or API key is involved. -
On this day — Wikipedia. Only today's date (month
and day, never the year) is sent to Wikipedia's public feed
(
en.wikipedia.org) to retrieve historical events. No account or API key is involved. -
News — Hacker News, or a feed you choose. By
default this widget reads Hacker News' public API
(
hacker-news.firebaseio.com); no query or personal data is sent, only a request for the current top stories. If you switch to your own RSS or Atom feed instead, only that address you pasted in is fetched, using the one-time permission described above. - Calendar — the address you paste in. Fetches only the private calendar address you provide, from whichever provider issued it (Google, Outlook, iCloud, or another). That address is never sent anywhere else, logged, or shown again once saved — see the permission section above.
- Search — your chosen engine. If you type a query into the search box and submit it, that query is sent to the search engine you selected (Google, Bing, or DuckDuckGo) to display results, exactly as it would be on that engine's own website.
Quick links and the Google apps widget simply open the website you click, the same as any ordinary bookmark or link. Their icons are drawn from artwork bundled with the extension (or, for quick links, from Chrome's own favicon cache described above), so no request is made to those sites just to display a tile. Backgrounds are generated by the extension rather than downloaded. Every other widget — the clock, world clocks, tasks, scratchpad, focus timer, habits, and quote of the day — runs entirely offline and makes no network requests at all. All widgets are bundled with the extension; none is downloaded or updated separately.
Permissions
The extension requests one Chrome permission up front: storage, to save and sync your settings.
Further permissions are optional and requested only when you turn on the feature that needs one: sessions, tabs, history, bookmarks, topSites, clipboardRead and favicon, each described above.
The extension declares no host permissions up front, so it starts with no standing access to the content of any website. A widget that needs to fetch an address you paste in yourself — a calendar link or a feed URL — asks Chrome for access to that one address only, at the moment you add it, as described above.
Data sale and sharing
The developer does not collect, sell, rent, or share any user data with anyone. The extension is not used for any purpose unrelated to its single purpose of providing a customizable new tab page.
Children's privacy
The extension is a general-purpose new tab page and does not knowingly collect any personal information from anyone, including children.
Changes to this policy
This policy may be updated from time to time. Any changes will be posted on this page with an updated revision date.
Contact
Questions about this policy can be raised via the project's GitHub repository: github.com/mehrshaad/daybreak-newtab (open an issue).