JevBlock Privacy Policy
Service operator: Vyacheslav Rodkin, individual developer. Contact: zzulyss@gmail.com.
1. What the extension does
JevBlock detects and hides advertising blocks on web pages. A content script analyses the page inside your browser. Blocks with an explicit ad label ("Advertisement", "Sponsored", "Promoted", etc.; English and Russian labels are recognised today) are hidden locally without contacting the server. Only blocks with ad signals that have no stored answer in the browser are sent to the server.
2. Data sent to the server
2.1. Installation registration
On installation the extension creates a random installation ID (UUID) and sends it with the extension version number. The server creates an account record and returns a signed token, which is stored in the extension and sent with requests.
2.2. Block check (up to 20 blocks per request)
- the installation ID and the token;
- the page origin only — scheme, domain and port (e.g.
https://example.com), without path, query or page title; - for each block: up to 600 characters of visible text after cleaning — links replaced with domain names, e-mail addresses replaced with
[email], sequences of 8–19 digits (card or phone numbers) replaced with[number]; - the domain the block links to;
- the element type (article, div, aside, iframe, …) and technical ad signals (e.g.
sponsored,banner,promo,iframe).
2.3. Your marks
When you click "Yes", "Not an ad" or use the context menu item "JevBlock: hide as ad", the server receives the key (hash) of the checked block and your decision (ad / not an ad). Context-menu marking first checks the block as in 2.2 to obtain that key. Votes count towards a shared verdict only when they come from different accounts and different networks.
3. What is not sent
- full page HTML, full page URLs (path and query), page titles, cookies;
- form and input contents, passwords; blocks inside forms, input fields, chats and messages are not analysed;
- pages that look private are not analysed at all: pages with a password or payment-card field or embedded Stripe/PayPal frames; sign-in hosts (
login.,auth.,accounts.,signin.,passport.,id.,oauth.); paths containingcheckout,payment,billing,login,account,settings,messages,inbox,chat,patient,password,webmail; webmail and messengers (Gmail, Proton Mail, Outlook, Telegram Web, WhatsApp Web, Discord, mailbox pages);bank./banking.andhealth./patient.subdomains; sites on your exclusion list.
These rules are heuristics and do not cover every bank, medical or other private site. Add such sites to the exclusion list in the extension settings.
4. IP address
The server receives your IP address as part of any network connection. The service does not store IP addresses in plain form:
- for rate limiting it computes a SHA-256 hash of the IP address (for IPv6, of the /64 network prefix), truncated to 32 hex characters, used as a counter key that is deleted after 2 minutes (per-minute limit), 2 hours and 2 days (registration limits);
- to count votes from distinct networks it stores a SHA-256 hash of "block key + IP address" for 7 days after the last vote on that block.
These hashes are not keyed with a secret, so an IPv4 address could theoretically be recovered by brute force; we do not do this and do not link the hashes to other data. No web-server access logs are kept for jevblock.asistbot.ru; web-server error logs may briefly contain IP addresses of failed connections.
5. Server-side retention
| Data | Retention |
|---|---|
| AI answer cache: key = SHA-256 of (origin, normalised text, link domain, element type, signals, model); value = a numeric score only. The block text itself is not stored. | 7 days |
| Check "receipt" (user ID + block key), needed to accept your mark | 7 days |
| Votes per block (user ID → decision; IP hash → decision) and totals | 7 days after the last vote |
| Account record: random user ID, installation ID, plan, daily quota, subscription status and expiry, creation and last-seen times, extension version; installation ID → user ID mapping | until deleted on your request |
| Daily usage counter | 2 days |
| Technical service logs (events without block text and without IP addresses) | container log rotation |
The debug mode that logs block text is disabled in production.
6. Third parties
For classification, the block data from 2.2 (origin, cleaned text, link domain, element type, signals — without the token, installation ID or your IP address) is sent via the OpenRouter API (OpenRouter, Inc.) to the Jev model by TypeSafe AI. They process requests under their own policies: openrouter.ai/privacy, typesafe.ai. We do not sell data, do not use it for advertising, credit scoring or any purpose unrelated to ad filtering, and do not share it with anyone else except where required by law.
7. Data in your browser
chrome.storage.local holds: settings and the exclusion list, the installation ID, the token, the daily-limit state, your personal rules (block hashes, structural position signals and the cleaned block description as in 2.2), AI answers (up to 1 hour) and a queue of unsent marks (up to 500). Personal rules are kept for 365 days; at most 3000 entries are stored. This data does not leave the browser except as described in section 2 and is removed when you uninstall the extension or press "Reset my rules".
8. Analytics and advertising
The extension and the website use no analytics, ad networks, trackers or third-party scripts.
9. Deleting your data
- Uninstall the extension — this removes all data in the browser.
- To delete your account record on the server, e-mail zzulyss@gmail.com with your account ID (shown in the extension settings window). Without the ID we cannot tell which data is yours. We delete the record within 30 days. Other server-side data expires automatically as listed in section 5.
Depending on where you live (for example under the EU/UK GDPR, the California CCPA/CPRA or the Australian Privacy Act), you may have the right to access, correct or delete your data, to object to or restrict processing, and to complain to your local data protection authority. Write to zzulyss@gmail.com; we answer within 30 days. We do not sell personal information and do not share it for cross-context behavioural advertising.
10. Chrome Web Store
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Changes
A new version is published on this page with a new effective date. Material changes will be announced in the extension description.
Русская версия
Политика конфиденциальности JevBlock
Оператор сервиса: Вячеслав Родкин, частный разработчик. Контакт: zzulyss@gmail.com.
1. Что делает расширение
JevBlock находит и скрывает рекламные блоки на веб-страницах. Для этого content script анализирует страницу в вашем браузере. Блоки с явной пометкой рекламы («Реклама», «Sponsored» и т. п.) скрываются локально, без обращения к серверу. На сервер отправляются только блоки с рекламными признаками, для которых в браузере ещё нет сохранённого ответа.
2. Какие данные отправляются на сервер
2.1. Регистрация установки
При установке расширение создаёт случайный идентификатор установки (UUID) и отправляет его вместе с номером версии расширения. Сервер создаёт запись аккаунта и возвращает подписанный токен, который хранится в расширении и передаётся в заголовке запросов.
2.2. Проверка блока (до 20 блоков за запрос)
- идентификатор установки и токен;
- origin страницы — только схема, домен и порт (например,
https://example.com), без пути, параметров и заголовка страницы; - для каждого блока: до 600 символов видимого текста после очистки — ссылки заменены на доменные имена, адреса e-mail заменены на
[email], последовательности из 8–19 цифр (номера карт, телефонов) заменены на[number]; - домен, на который ведёт ссылка блока;
- тип элемента (article, div, aside, iframe и т. п.) и технические рекламные признаки (например,
sponsored,banner,promo,iframe).
2.3. Ваши отметки
Когда вы нажимаете «Да», «Не реклама» или выбираете в контекстном меню «JevBlock: это реклама», на сервер отправляется ключ проверенного блока (хэш) и ваше решение («реклама» / «не реклама»). При отметке через контекстное меню блок сначала проверяется так же, как в п. 2.2, чтобы получить этот ключ. Отметки разных пользователей учитываются, только если они пришли от разных аккаунтов и из разных сетей.
3. Что не отправляется
- полный HTML страницы, полные адреса страниц (путь и параметры), заголовки страниц, cookies;
- содержимое форм и полей ввода, пароли; блоки внутри форм, полей ввода, чатов и переписки не анализируются;
- страницы, которые выглядят приватными, не анализируются вообще: страницы с полем пароля или платёжной карты, со встроенными формами Stripe/PayPal; адреса входа (поддомены
login.,auth.,accounts.,signin.,passport.,id.,oauth.); пути сcheckout,payment,billing,login,account,settings,messages,inbox,chat,patient,password,webmail; веб-почта и мессенджеры (Gmail, Proton Mail, Outlook, Telegram Web, WhatsApp Web, Discord, страницы почтовых ящиков); поддоменыbank./banking.иhealth./patient.; сайты из вашего списка исключений.
Эти правила эвристические и не охватывают все банки, медицинские и другие приватные сайты. Добавьте такие сайты в «Не проверять сайты» в настройках расширения.
4. IP-адрес
Сервер получает ваш IP-адрес при любом сетевом соединении. Сервис не сохраняет IP-адрес в открытом виде:
- для ограничения частоты запросов вычисляется SHA-256 от IP-адреса (для IPv6 — от префикса сети /64), усечённый до 32 шестнадцатеричных символов; он используется как ключ счётчика, который удаляется через 2 минуты (поминутный лимит), 2 часа и 2 суток (лимиты регистрации);
- для подсчёта голосов из разных сетей хранится SHA-256 от пары «ключ блока + IP-адрес» — 7 дней после последнего голоса по этому блоку.
Хэши не защищены секретным ключом, поэтому теоретически IPv4-адрес можно восстановить перебором; мы этого не делаем и не связываем хэши с другими данными. Журналы доступа веб-сервера для jevblock.asistbot.ru не ведутся; системные журналы ошибок веб-сервера могут кратковременно содержать IP-адреса неудачных соединений.
5. Хранение на сервере
| Данные | Срок хранения |
|---|---|
| Кэш ответов ИИ: ключ — SHA-256 от (origin, нормализованный текст, домен ссылки, тип элемента, признаки, модель); значение — только числовая оценка. Сам текст блока не хранится. | 7 дней |
| «Квитанция» проверки (ID пользователя + ключ блока) — нужна, чтобы принять вашу отметку | 7 дней |
| Голоса по блоку (ID пользователя → решение; хэш IP → решение) и итоговые счётчики | 7 дней с последнего голоса |
| Запись аккаунта: случайный ID пользователя, ID установки, тариф, дневной лимит, статус и срок подписки, даты создания и последней активности, версия расширения; связь «ID установки → ID пользователя» | до удаления по вашему запросу |
| Счётчик использованных проверок за сутки | 2 дня |
| Технические журналы сервиса (события без текста блоков и без IP) | ротация журналов контейнера |
Режим отладки, при котором в журнал пишется текст блоков, в рабочей версии выключен.
6. Передача третьим лицам
Для классификации данные блока из п. 2.2 (origin, очищенный текст, домен ссылки, тип элемента, признаки — без токена, ID установки и вашего IP-адреса) передаются через API OpenRouter (OpenRouter, Inc.) модели Jev компании TypeSafe AI. Они обрабатывают запрос по своим правилам: openrouter.ai/privacy, typesafe.ai. Мы не продаём данные, не используем их для рекламы, кредитного скоринга или любых целей, не связанных с фильтрацией рекламы, и не передаём их другим лицам, кроме случаев, предусмотренных законом.
7. Данные в вашем браузере
В chrome.storage.local хранятся: настройки и список исключений, ID установки, токен, состояние дневного лимита, ваши личные правила (хэши блока, структурные признаки положения на странице и очищенное описание блока в объёме п. 2.2), ответы ИИ (до 1 часа) и очередь неотправленных отметок (до 500). Личные правила хранятся 365 дней; всего хранится не более 3000 записей. Эти данные не покидают браузер, кроме отправки, описанной в п. 2, и удаляются при удалении расширения или кнопкой «Сбросить мои правила».
8. Аналитика и реклама
Расширение и сайт не используют аналитику, рекламные сети, трекеры и сторонние скрипты.
9. Удаление данных
- Удалите расширение — это удалит все данные в браузере.
- Чтобы удалить запись аккаунта на сервере, напишите на zzulyss@gmail.com и укажите ID аккаунта (показан в окне настроек расширения). Без ID мы не можем определить, какие данные ваши. Мы удалим запись в течение 30 дней. Остальные серверные данные удаляются автоматически в сроки из п. 5.
В зависимости от страны проживания (например, по GDPR в ЕС и Великобритании, CCPA/CPRA в Калифорнии или Privacy Act в Австралии) у вас может быть право на доступ к данным, их исправление и удаление, на возражение против обработки или её ограничение, а также на жалобу в местный надзорный орган. Пишите на zzulyss@gmail.com; мы отвечаем в течение 30 дней. Мы не продаём персональные данные и не передаём их для поведенческой рекламы.
10. Chrome Web Store
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Использование информации, полученной от расширения, соответствует Политике пользовательских данных Chrome Web Store, включая требования об ограниченном использовании (Limited Use).
11. Изменения
Новая редакция публикуется на этой странице с новой датой вступления в силу. О существенных изменениях мы сообщим в описании расширения.