Skrim — Privacy Policy

Effective 7 August 2026. This policy is about the Skrim Chrome extension. The website it is served from, skrim.app, is a different and much shorter story, and has its own section at the end.

Skrim hides your bookmarks bar while you share your screen. It does that entirely inside your own browser. It has no servers, no accounts, no analytics and no network code at all — there is nothing for it to send your data to, and no request in it that could send anything.

The short version

What Skrim does to your bookmarks

Chrome offers no way to hide the bookmarks bar programmatically, so Skrim hides it by moving what is on it out of sight and putting it back afterwards. In your own bookmark tree, on your own machine:

  1. When a screen share starts, every bookmark on your bar is moved into a new folder inside Other bookmarks named “Skrim — hidden while screen sharing”.
  2. A few placeholder links to well-known sites (Google, Gmail, Calendar, Drive, Maps, News) are added to the bar so it does not look conspicuously empty. They are ours, not yours, and they are removed on restore.
  3. One receipt bookmark is written inside that folder. Its title spells out how to put everything back by hand, and its URL carries the positions needed to do it automatically.
  4. When the share ends, every bookmark goes back to its original position, and the folder, the placeholders and the receipt are deleted.

If you turn on Tuck into a folder in the popup, step 1 changes: instead of the Other-bookmarks vault, your bar is parked inside a single folder you name that stays on the bar, so your other synced computers keep their bookmarks. It is still a move inside your own tree, with nothing copied out.

During a hide, nothing is ever deleted permanently and nothing is copied out of your browser. If a share, the browser or the machine dies mid-way, the next startup finishes the restore.

Backing up your bookmarks

Because Skrim moves your real bookmarks, the popup offers an optional backup, so trying it never risks them. When you ask for one, Skrim reads your bookmark tree and saves it as an ordinary HTML bookmarks file to your downloads — the same format Chrome itself exports. That file is created inside your browser and is never uploaded or sent anywhere; where it goes next is up to you. Import reads a file you pick and adds its bookmarks back. Both are started by hand — Skrim never exports or imports on its own, and neither touches the network.

What is stored, where, and when it goes away

WhatWhereRemoved
Crash-safety journal — bookmark ids and positions only, never titles or URLs chrome.storage.local Cleared as soon as a restore is verified complete
Ids of folders and placeholder links Skrim created, so it never touches one of yours by mistake chrome.storage.local Cleared once they have been cleaned up
Last-failure record — bookmark ids, counts and a timestamp, shown on the recovery screen when a restore could not finish chrome.storage.local Cleared on the next successful restore
Your settings — placeholder links on or off, and the tuck folder's name. Preferences only, never bookmark content; stored locally, so they do not sync chrome.storage.local Deleted when you uninstall
Live share bookkeeping — which tab and frame is currently sharing, and when it last checked in. No URLs, no page data. chrome.storage.session Deleted by Chrome when you close the browser
The receipt bookmark Your bookmark tree, inside the folder above Deleted when your bookmarks are restored

Uninstalling the extension makes Chrome delete everything in the first five rows. Your bookmarks are yours and stay where they are.

Permissions, and what each one is actually for

PermissionWhy Skrim needs it
bookmarks The whole feature. Read what is on the bar, move it into the folder, add the placeholders and the receipt, then move everything back. The same permission reads your tree when you ask for a backup. Bookmarks are rearranged in place and never uploaded or transmitted — a backup is a local file, and only ever one you asked for.
storage Keep the records in the table above — the crash-safety bookkeeping and your settings — so an interrupted hide can always be repaired and your preferences persist. Local to your profile.
alarms A once-a-minute watchdog that re-checks a hide or restore really completed. Chrome shuts the extension's background worker down when idle; the alarm is what wakes it to finish the job.
tabs Some screen recorders (Loom, for example) capture from a page belonging to their own extension, which Skrim is not allowed to look inside. Skrim matches tab URLs against a short built-in list of those capture pages so it knows a recording has started. The URL is compared in memory and immediately discarded — it is never stored and never sent anywhere. No browsing history is read.
Scripts on all sites (<all_urls>) Screen sharing can start on any site, so Skrim wraps navigator.mediaDevices.getDisplayMedia on every page to learn that a share started and stopped. That is all it does: it does not read, alter or transmit page content, and it adds nothing visible to any page.

What Skrim never touches

Chrome Web Store data disclosures

These are the categories Chrome asks every extension to declare. Skrim collects none of them, because it makes no network requests:

Personally identifiable informationNot collected
Health informationNot collected
Financial and payment informationNot collected
Authentication informationNot collected
Personal communicationsNot collected
LocationNot collected
Web historyNot collected
User activityNot collected
Website contentNot collected

Accordingly: Skrim's handling of data is limited to providing the single feature described in its listing; no data is sold or transferred to third parties; none is used for creditworthiness, lending, advertising or profiling; and none is used for any purpose unrelated to hiding and restoring your bookmarks bar.

The one thing that does leave your device — and it is Chrome, not Skrim

If you have Chrome Sync turned on for bookmarks

Hiding the bar is a bookmark change, and Chrome syncs bookmark changes to your other signed-in devices. So while your bar is hidden here, it is also empty on those devices, and the folder, the receipt and the placeholder links appear in your synced tree. Restoring reverses all of it, and the reversal syncs too.

That transfer is performed by Chrome under Google's privacy policy, using the sync you already enabled. Skrim never sends your bookmarks anywhere itself. Sharing a single tab avoids the situation entirely — a captured tab cannot show the bookmarks bar, so Skrim brings the bar straight back.

The recovery page

The receipt bookmark links to a page that explains how to get your bookmarks back. In the current version that page (recovery.html) is inside the extension, so opening it makes no network request at all.

The recovery details ride in the part of the URL after the #, which browsers never send to a server. That is deliberate: if a copy of the page is ever hosted on the web, the host still cannot learn anything about your bookmarks from a visit, and the receipt contains no bookmark titles or URLs in the first place — only positions. A hosted copy would see what any website sees from any visit (an IP address and a browser user-agent, in ordinary server logs) and nothing else. Should a hosted page become the default destination, this policy will be updated to say so before it does.

Children

Skrim is a general-purpose utility, is not directed at children, and collects no personal information from anyone regardless of age.

Your rights

Rights such as access, correction, export and erasure exist to be exercised against data a company holds about you. The extension gives us nothing to hold — no database, no log, no account. To remove everything it has ever stored, uninstall it: Chrome deletes its storage with it. If your bookmarks were hidden at that moment, the folder and the receipt stay in your bookmark tree so you can put things back; the recovery instructions cover that case.

The single exception is an email address you chose to type into the waitlist form on this website. That we do hold, and This website below says exactly what it is and how to have it deleted.

This website

Everything above describes the extension, which runs on your own machine and talks to nothing. skrim.app is an ordinary website and is not the same thing. It is kept deliberately small, and there are exactly two things about it worth telling you.

The waitlist form

If you type your email address into the form on the front page, we store three things: the address, the date, and which page you sent it from. That is the entire record — no name, no location, no profile. We use it once, to tell you Skrim is out. It is never sold, never shared, and never connected to anything the extension does, because the extension has no way to reach it. Reply to that email or write to the address at the bottom of this page and the row is deleted.

The site is hosted on Cloudflare, which keeps the ordinary server logs any web host keeps — an IP address, a browser user-agent and a timestamp per request. We do not add anything on top of that: we set no cookies of our own, and there is no analytics, no tracking script and no advertising pixel on any page here, this one included. Every page on this site is a single self-contained file, which is why there is nothing for a third party to be loaded from in the first place.

Changes

If a future version of Skrim ever collects or transmits anything, this policy will be updated to describe it, with a new effective date, before that version ships. The current version transmits nothing.