PrankSync — Privacy Policy

Last updated: 26 July 2026

PrankSync is a two-player prank extension. Two people who both installed it pair with a single-use code; one can then trigger visual, audio and text effects in the other's browser. This policy covers what that involves.

What is transmitted

While a session is active and a Prankster is connected, the Victim's browser sends two things through the relay:

Nothing is sent when no Prankster is connected, and nothing is sent when no session is active. The Prankster sends only effect identifiers and trap configuration.

What is never collected

No accounts, no analytics, no advertising, no tracking, no fingerprinting. Full URLs, browsing history, page content, form input, keystrokes, credentials and payment details are never read and never leave the device. Nothing is sold or shared with third parties, and nothing is used for any purpose other than running the prank session you started.

Retention

Session data lives only in memory on a Cloudflare Durable Object for the life of the session. The active hostname is held only long enough to forward it to the connected Prankster and is never written to disk. Unclaimed pairing codes expire after 15 minutes. Ending the session, dropping the Prankster, or disconnecting destroys the session state. There is no database and no backup.

Local storage

The extension stores your role, current session tokens, relay URL, and trap configuration locally via chrome.storage. This stays on your machine and is cleared when the session ends.

Control

The Victim can drop the Prankster or end the session at any time from the extension popup, which immediately revokes access. Uninstalling the extension removes all locally stored data.

Contact

Questions, privacy requests, or bug reports: nir.ashkenazi88@gmail.com. This is the same address listed as the publisher contact on the Chrome Web Store.