개인정보처리방침
시행일: 2026-08-15 · 연락: hello@urlpopdoc.com
urlpopdoc.com 웹앱과 Chrome 확장「urlpopdoc QR」이 사용자 데이터를 어떻게 다루는지 밝힙니다. 선택·입력한 글은 브라우저에서 QR과 URL로 바뀌지만, 그 본문을 개발자 서버로 수집·전송하지 않습니다.
웹앱 (토큰 1: · 2:)
문서 본문은 주소의 # 프래그먼트에만 있습니다. 프래그먼트는 브라우저에만 있고 HTTP 요청 본문·서버 로그에 실리지 않습니다. 서버에 본문을 저장하지 않습니다.
Chrome 확장
선택 글, 링크, 페이지 주소, 붙여넣기한 텍스트는 브라우저 안에서만 urlpopdoc URL과 QR로 인코딩합니다. 권한은 contextMenus와 storage뿐입니다.
chrome.storage.session은 우클릭한 글을 QR 창으로 넘기는 임시 용도이며, 창이 읽은 뒤 지웁니다. 브라우저를 끄면 사라집니다.
- 페이지를 몰래 읽거나 서버로 보내는
fetch, 호스트 권한, 원격 코드는 없습니다.
- 제3자와 공유하지 않으며 판매·광고·중개에 쓰지 않습니다.
Chrome 및 Google API로 받은 정보의 이용은 Chrome Web Store User Data Policy(Limited Use 요건 포함)를 지킵니다.
열람 암호 (토큰 4:)
암호가 켜진 문서의 본문과 암호문도 URL 프래그먼트에만 있고 서버에 없습니다. 키 서버(keys.urlpopdoc.com)의 D1에는 키 메타만 둡니다: serverShare, auth_hash, 만료 시각(exp), 실패 횟수.
- 암호 원문, 브라우저 쪽 키 조각(
pwdShare), 성공 열람 로그는 저장하지 않습니다.
- 요청 IP는 속도 제한 카운터로만 쓰고, 열람자 IP를 로그로 남기지 않습니다.
- 만료되면 해당 키를 삭제합니다.
호스팅
정적 사이트는 Cloudflare Pages, 키 서버는 Cloudflare Workers입니다. 호스팅 사업자에게 본문을 넘기지 않도록, 본문은 프래그먼트에만 둡니다.
문의
이 방침에 관한 문의는 hello@urlpopdoc.com으로 보내 주세요.
Privacy policy
Effective: 2026-08-15 · Contact: hello@urlpopdoc.com
This page describes how the urlpopdoc.com web app and the Chrome extension “urlpopdoc QR” handle user data. Selected or typed text is encoded into a QR and URL in the browser. We do not collect or send that body to our servers.
Web app (tokens 1: and 2:)
The document body lives only in the URL # fragment. The fragment stays in the browser and is not sent in HTTP request bodies or server logs. We do not store the body on a server.
Chrome extension
Selected text, link URLs, page URLs, and pasted text are encoded into a urlpopdoc URL and QR only inside the browser. Permissions are contextMenus and storage only.
chrome.storage.session is a temporary hand-off from a right-click into the QR window; the window deletes it after reading. It disappears when the browser quits.
- There is no
fetch, host permission, or remote code that would read a page in the background or send it to a server.
- We do not share data with third parties, and we do not sell, advertise with, or broker it.
The use of information received from Chrome and Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Read password (token 4:)
For password-protected documents, the body and ciphertext also stay in the URL fragment and are not on the server. The key server (keys.urlpopdoc.com) stores only key metadata in D1: serverShare, auth_hash, expiry (exp), and failure counts.
- We do not store the password itself, the browser-side key share (
pwdShare), or successful-read logs.
- Request IPs are used only as rate-limit counters; we do not keep viewer IP logs.
- When a key expires, we delete it.
Hosting
The static site runs on Cloudflare Pages; the key server runs on Cloudflare Workers. We keep the body in the fragment so it is not delivered to us as page content.
Contact
Questions about this policy: hello@urlpopdoc.com.