Effective August 5, 2026
Privacy Policy.
RecommendLess checks whether your Trial or License is active. It does not send us your browsing history or the content you view on supported websites.
Who is responsible
GrumpyOats FZ-LLC is responsible for the personal data described here. We are a Free Zone Limited Liability Company registered with Ras Al Khaimah Economic Zone under services licence 47008339.
Registered business address: SFFO0121, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.
Data we collect
- License and Trial data: a random installation identifier, Trial claim and last-validation times, plan, subscription status and expiry, and internal License and checkout identifiers.
- License-key data: an encrypted copy of the key, a keyed cryptographic hash used to validate it, and a short hint used for support.
- Billing data: Paddle may make available your name, billing address or country, email address, purchase history, prices and taxes, transaction analytics, partial payment-method details, and customer, subscription, transaction, and event identifiers. We do not receive your full card or bank-account details.
- Optional website analytics: if you allow them, a random browser identifier, page views, clicks on named purchase buttons, the product page involved, and timestamps.
- Operational events: checkout, Trial, License, validation, and subscription events, with related internal identifiers and timestamps.
- Service diagnostics: structured request and application logs, service traces and metrics, error type names, request timing, route templates, database operation names, outbound service hosts, deployment environment, region, release revision, instance identifiers, and random request identifiers. We do not include request bodies, query strings, raw headers, email addresses, License keys, checkout-recovery secrets, exception messages, or stack traces.
- Security data: an IP address is converted to a keyed hash for minute-level rate limiting.
- Communications: information you include when you contact us for support or make a privacy request.
What the extension does not send
The extension needs permission to run on supported websites so it can remove or redirect distracting parts in your browser. That work happens locally. It does not send us the pages or URLs you visit, searches, messages, posts, videos, watch history, time spent browsing, or the parts it removes.
How we use data
We use this data to:
- create, validate, and recover Trials and Licenses;
- fulfil subscriptions and provide billing and product support;
- secure the service, limit abuse, and diagnose failures;
- measure the limited path from a product page to License activation; and
- meet legal, tax, accounting, and dispute-resolution obligations.
We process License, billing, and security data as necessary to provide the service, comply with law, establish or defend legal claims, and protect the service. Optional website analytics are based on your consent. We do not use personal data for advertising profiles or automated decisions with legal or similarly significant effects.
RecommendLess’s use and transfer of information received from browser APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use browser permissions and the resulting data only to provide, maintain, secure, and support RecommendLess’s stated feed-blocking purpose.
Browser storage and analytics choice
The website uses local browser storage for your analytics choice, random browser and installation identifiers, and any License key you save. The extension uses its own local storage for its random installation identifier, License key, entitlement status, and last validation time. A short-lived checkout-recovery secret is kept in the URL fragment rather than local storage and is sent to us only in a dedicated request header. None of this storage follows you across unrelated websites.
Optional page-view and purchase-button analytics run only after you allow them and never run when your browser sends a Do Not Track signal. Operational events needed to create a checkout, start a Trial, issue a License, and validate access continue regardless of this choice.
Checking this browser’s choice…
You can also remove local data through your browser or by uninstalling the extension. Clearing local data does not cancel a Paddle subscription or erase records we must retain on the service.
Who receives data
Paddle is our authorised reseller and merchant of record. When you choose to start checkout, your browser loads Paddle.js, so Paddle receives the IP address and ordinary request metadata needed to deliver that script. Paddle then collects checkout and payment information and shares order details with us. Paddle acts under its Privacy Notice.
Honeycomb receives service traces, metrics, and structured logs, including limited lifecycle context, so we can measure activation and diagnose reliability problems. Honeycomb does not receive browser history, viewed content, request bodies, query strings, raw headers, email addresses, License keys, or checkout-recovery secrets from this integration.
Hosting, traffic-security, backup, and email providers may process limited data needed to operate and protect the service. We may also provide data to professional advisers or public authorities where necessary and lawfully required. We do not sell personal data or share it for behavioural advertising.
International processing
We are based in the United Arab Emirates. Paddle and infrastructure providers may process data in other countries. We make cross-border transfers only where permitted by applicable law, using recognised safeguards as applicable. You may contact us for information about the safeguard used for a particular transfer.
How long we keep data
- Optional website analytics, operational lifecycle events, and billing webhook receipts are deleted after 13 months.
- Rate-limit hashes are deleted after one day.
- Service logs, traces, and error diagnostics are normally deleted after 30 days, unless a security incident or legal obligation requires longer.
- Checkout recovery secrets expire after 24 hours and their hashed records are deleted after expiry or within one day after use.
- Abandoned checkout records are deleted after 30 days.
- License, completed-checkout, and installation records are kept while access is active and for up to 24 months afterwards for recovery, fraud prevention, chargebacks, and disputes. Information that law requires us to keep may be retained longer.
- Support and privacy correspondence is normally deleted within 24 months after the matter is resolved, unless it is needed longer for a legal obligation or claim.
- Data in your browser remains until you clear it or uninstall the extension.
Paddle keeps transaction data under its own retention rules.
Your rights
Depending on the law where you live, you may ask for information about our processing and request access, correction, deletion, restriction, objection, or a portable copy of your personal data. You may withdraw consent where processing is based on consent and complain to the relevant data-protection authority.
We may need to verify your identity and may retain information where the law permits or requires it. To make a request, email [email protected].
Security
We use measures appropriate to the data we process, including encryption of recoverable License keys, keyed hashes for credentials and rate limiting, signed billing webhooks, request-size limits, an HTTPS-only production configuration, and browser security headers. No online service can guarantee absolute security.
Changes and contact
We may update this Privacy Policy when the service or legal requirements change. We will post the revised version here, update the effective date, and provide additional notice where required.
For privacy questions or requests, contact [email protected] or write to the registered business address above.