Skip to content

Privacy Policy

Use Emoji is built so that what you type stays on your computer. This page says exactly what the extension and this website store, where, and why.

Last updated: September 25, 2026

The short version

  • The emoji picker sends nothing anywhere. Searching, copying and your settings all happen in your browser.
  • What you type is never collected. :emoji: codes are matched on your computer, against a list that ships with the extension. Your text, the codes you type and what your custom codes contain never reach us.
  • It runs only where you let it. Use Emoji runs only on the websites you allow and asks just once for each. Other sites stay untouched.
  • Our server keeps only what Pro needs: a random device identifier with a count of free tries used, your account and subscription if you have one, and a small set of usage events.
  • Payments go through Stripe. Your card details go to Stripe, never to us.
  • No ads, no selling, no third-party trackers in the extension.

Who we are

Use Emoji ("the extension", "we", "us") is a browser extension made by Artyom Shimanski, an independent developer. This policy covers the extension and this website, useemoji.com. Questions about it go to [email protected].

What stays on your device

The extension keeps these in your browser's own extension storage (chrome.storage.local). They never leave your device, and removing the extension removes them:

  • Your appearance settings: theme, emoji style and skin tone, and the interface language you chose.
  • Your custom codes and what each one types.
  • Your :emoji: typing settings: whether the suggestion list shows, and any fields you told it to ignore.
  • Your sign-in session, if you sign in.
  • A random device identifier (see below) and a few flags, such as whether you have seen the welcome page.

The emoji picker (emoji-mart) remembers your most-used emoji in the popup's local storage, so they stay at the top. The list of websites you allowed is kept by your browser as extension permissions; you can see and remove them in the Use Emoji settings or your browser's extension settings.

What reaches our server

Our server (emoji-api.shimanski.dev) exists for the paid features: free-try limits, accounts and payments. It receives only the following. Like any server, it also sees the IP address of each request; it uses it only to limit abuse and does not store it with your data.

A device identifier and your free tries

On install the extension creates a random identifier. It is sent with a count of how many free :emoji: replacements and custom codes you have used, so the free limits work without an account. It does not identify you by itself, and it comes with no text, codes or page addresses.

Your account, only if you sign in

An account is only needed for Pro. With Google sign-in we receive your email address, name and profile picture from Google (never your Google password). With email sign-in we keep your email address, the name you enter and a hashed password. One-time sign-in codes are stored hashed and expire.

Your subscription, only if you buy Pro

We keep your plan, its status and dates, and Stripe's references to your customer record, subscription or payment. Payment happens on Stripe's own checkout page, and changing your card, seeing invoices or cancelling happens in Stripe's billing portal: we never see or store your card details. Stripe tells us when a payment succeeds or fails, so Pro can turn on, renew or stop.

Your country, to show prices

When the extension shows the Pro plans, it sends your device's time zone (such as Europe/Berlin), and our network provider tells our server which country your connection comes from. Both are used only to choose the currency the prices are shown in, and neither is stored.

A small set of usage events

To learn which parts of the extension help people, it sends a fixed list of events: the welcome page was opened, the Pro page was opened (and why), a plan or a currency was chosen, a checkout started, a reminder of how many free tries remain was shown, you signed in or created an account, a site was turned on for :emoji: typing (with that site's host name, such as mail.google.com), a custom code was created (where it was created, never what it contains), and the first time a replacement worked (with the host name). Nothing outside this list is accepted by our server. Events carry your device identifier, and your account if you are signed in. They are deleted automatically after 180 days.

What is never collected

What you type. The codes you type. What your custom codes contain. The addresses of the pages you visit, your browsing history and your clipboard. The extension has no permission to read any of these on sites you have not allowed, and on the sites you have allowed it matches codes locally and sends nothing about them.

Emails

If you have an account, we send the emails the service needs: verification and password reset codes, a notice when your password changes, a welcome message, confirmations when a subscription starts, renews or is cancelled, notices about failed payments, and a confirmation when you delete your account. If you start a Pro checkout and do not finish it, we may send one reminder with a link back to it, at most once a week. Stripe emails you a receipt for each payment. We do not send newsletters or marketing.

How we use it

  • To apply the free limits and turn on the Pro features you paid for.
  • To create and keep your account and sign you in.
  • To process payments through Stripe and send the emails above.
  • To see, in aggregate, which features and sites matter, and to fix what breaks.
  • To prevent abuse of the free tries and of the service.

We do not sell or rent your data, we do not use it for advertising, and we do not build profiles of you.

What the extension asks your browser for

  • Storage: to keep your settings and custom codes on your device.
  • Identity: for the optional Google sign-in.
  • Active tab: when you open the popup, to read that tab's address so the popup can offer to turn typing on there.
  • Scripting: to run :emoji: typing on the sites you have allowed, and nowhere else.
  • Website access (optional): none at install. Your browser asks you once for each site you turn on (or for all sites, if you choose that), and you can take any site back at any time.

Password fields and code editors are always skipped, on every site, whatever your settings.

Services we rely on

  • Stripe, for payments. Stripe runs the checkout and billing pages and receives your email address, card and billing details there, under its own privacy policy.
  • Google, for the optional sign-in (Google's privacy policy).
  • Cloudflare, which carries the traffic to this website and to our server (Cloudflare's privacy policy).
  • Our email provider, which delivers the emails above.
  • The Chrome Web Store, which installs and updates the extension under Google's terms.

When you uninstall the extension, your browser opens a short, optional feedback form on Google Forms. Answering it is up to you.

This website

useemoji.com is a static website, hosted on Cloudflare Pages. It does not require an account and sets no cookies of its own. Cloudflare keeps standard technical logs (such as IP address, browser type and the pages requested) for security and reliability.

The picker and the typing box on our pages run in your browser. The picker remembers your recently used emoji and skin tone in your browser's local storage; nothing you click or type in them is sent to us.

We do not run analytics on this website.

How long we keep it, and deleting it

Data on your device stays until you remove the extension or clear it. Usage events are deleted after 180 days. Account and subscription records are kept while your account exists.

You can delete your account in the extension, under Settings, Account, Delete account. That cancels any active subscription straight away and closes the account; your codes and settings stay in your browser. We, and Stripe, keep what the law requires for tax and payment records. If you want everything else about you removed as well, email [email protected] and we will do it.

Your rights

Depending on where you live (for example under the GDPR in the EU and the UK, or the CCPA in California), you can ask to access, correct, export or delete your personal data, and object to or restrict how it is used. Write to [email protected] and we will answer within 30 days. You can also complain to your local data protection authority.

Security

Traffic to our server is encrypted, passwords and sign-in codes are stored hashed, and sessions end when you sign out or change your password. No system is perfectly secure, but we keep what we hold small on purpose.

Children

Use Emoji is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If this policy changes, we will update this page and the date at the top. If a change is significant, we will say so in the extension or by email to account holders.