Privacy, in plain language.
Effective September 29, 2026 · Drift 1.0.0 · Maintained by Kyle Reddoch
What Drift reads
When you click Drift, use its keyboard shortcut, or choose its right-click menu, it uses the selected page’s title and URL, and any passage you selected, to prepare a post. It does not monitor your browsing in the background. Some protected pages and embedded content do not allow access to selected text.
What stays in your browser
Saved Mastodon server addresses and preferences are stored locally in Chrome’s extension storage. They are not synced by Drift. Draft text and its source information are stored in temporary extension session storage so a closed popup can recover your edits. This session storage clears when Chrome restarts, or the extension is disabled, reloaded, or updated. Drift also removes a tab’s saved draft when that tab closes.
These storage areas are not a password vault. Drift does not store passwords, authentication tokens, or Mastodon cookies.
What leaves your browser
Only when you choose Continue to Mastodon does Drift open your selected server’s HTTPS /share page with the draft text in the URL. That request sends the draft to the server before you publish it. The URL can appear in browser history, history sync if enabled in Chrome, and the server’s logs. Your server’s privacy rules apply. Check the draft before continuing, particularly when sharing text or links from private pages.
Copy writes your draft to the system clipboard when you ask. Your operating system’s clipboard history or sync settings may apply. Links to GitHub, donation services, and the author’s site open only when clicked; those sites have their own privacy policies.
Website visit attribution
Links to Kyle’s website, kylereddoch.me, include the fixed tags utm_source=drift and utm_medium=extension. When you click one, the website’s existing Tinylytics analytics can attribute that visit to Drift. The same tags are used for everyone; they contain no user identifier, selected text, draft, Mastodon server, or address of the article you are sharing.
These links open only when clicked. Drift does not send background analytics requests or load a Tinylytics script or tracking pixel inside the extension. Visiting the website is subject to its privacy policy. Traffic attribution may be limited by browser privacy settings or content blockers.
No extension usage analytics or advertising
Drift contains no usage analytics, advertising, remote scripts, or telemetry, and sends no page content to its developer. It does not sell or use your data for advertising. Its use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements.
Permissions and their purpose
- activeTab: temporary access to the page you explicitly choose to share.
- scripting: reads the selected passage from that page after you invoke Drift.
- storage: saves server preferences and temporary drafts.
- contextMenus: adds right-click actions for pages, links, and selected passages.
Drift requests no persistent access to websites, browser history permission, cookies permission, or account API access.
Remove your data
Use Clear temporary drafts or Reset Drift on the welcome page. Already-open editor text remains visible and can be saved again if you edit it. Uninstalling Drift removes its local extension data. Removing a draft does not erase clipboard contents, browser history, or information already received by a Mastodon server.
About this website
This website is hosted on GitHub Pages. GitHub records visitor IP addresses for security purposes. This website uses Tinylytics to understand visits and referral sources. Its script sends the visited page’s URL (including any query string) and the external referring page, when available, to Tinylytics. As with other web requests, Tinylytics receives connection and browser request information when your browser contacts its service. See the Tinylytics privacy policy for its data-handling practices. Tinylytics does not use tracking cookies; its optional ignore setting can save a preference in your browser’s local storage. This website has no advertising. These website analytics do not run inside the Drift extension and do not receive its selected passages or drafts.
Links from this website to Kyle’s personal website use the fixed tags utm_source=drift and utm_medium=website. After a click, the personal website’s Tinylytics installation can attribute that visit. This is separate from the extension’s utm_medium=extension links described above.
Questions
Contact the maintainer through Drift’s GitHub issues. For private security reports, use the repository’s Security tab to report a vulnerability privately. Do not post private article text, credentials, or confidential URLs in a public issue.