Last updated: 30 July 2026
The Cardit Web Clipper is a Chrome extension that lets a signed-in Cardit user save a web page as a card in their Cardit account. This policy explains exactly what the extension accesses, what it stores, and what it never does.
launchWebAuthFlow against Cardit’s existing web login. The extension
receives only a short-lived Cardit access token, kept in
in-memory session storage and wiped when the browser closes. No password, no
long-lived refresh token, and no API key are ever stored in the extension.chrome.storage.local) so drafts can sync automatically when you’re back
online. Drafts contain only the card fields you were saving — never credentials.The metadata you choose to save is sent over HTTPS to Cardit’s API
(www.cardition.com) and stored as a card in your Cardit account,
exactly as if you had created it in the Cardit app. It is handled under the same terms
as the rest of your Cardit data.
activeTab + scripting — read the current page’s metadata
only when you click Save.storage — keep your short-lived session, last-used folder, and offline
drafts.contextMenus — the right-click “Save … in Cardit” actions.sidePanel — the Save-in-Cardit interface.identity — the secure sign-in flow.alarms — periodically retry syncing offline drafts.https://www.cardition.com/* (the Cardit API
and sign-in bridge). The extension does not request access to all
websites.The session token is discarded when the browser closes or you sign out. You can clear local preferences and drafts at any time by removing the extension. To delete cards or your account, use the Cardit app or web app (Account & Data settings).
Questions about this policy or your data: info@cardition.com.