MasterFinder Privacy Policy
Version: 2.7 Effective date: August 25, 2026 Translation: the Brazilian Portuguese policy is the reference version
1. Controller and contact
MasterFinder is provided by Caetano Hillesheim Sadosiuk, an individual located in Porto Alegre, Rio Grande do Sul, Brazil. For privacy or support matters, contact hillcaetano@gmail.com.
2. Scope
This policy explains how the MasterFinder Chrome extension processes data when a user analyzes product pages, searches MasterShop candidates and suppliers, or organizes ads from the Meta Ads Library.
3. Data processed
The extension may process:
- URLs, titles, descriptions, prices, images, variants, and other visible content from product pages chosen by the user;
- ads, text, creatives, destination URLs, identifiers, and responses shown or received by the Meta Ads Library;
- products, candidates, suppliers, profiles, and statistics returned by MasterShop;
- email, authentication tokens, and business context found in known fields of the active MasterShop session, only while necessary calls are made;
- MasterFinder account email, user identifier, and authentication session managed by Supabase;
- sanitized title, description, category, and brand; normalized candidates; and normalized ad snapshots sent to the protected backend, including only an allowlisted CTA and a destination-derived category. An HTTP URL may be read transiently only to derive that category and is never stored, opened, or transmitted; MasterShop/Meta cookies, tokens, email, and business context remain excluded;
- at most two public HTTPS URLs (the product page and, when available, the Meta ad) sent by the backend to Google Gemini to generate terms and select MasterShop categories; if the product page cannot be read, an extracted and sanitized context of up to 6,000 characters may be sent in one final attempt;
- normalized HTTPS URLs for mined products and aggregate completed-search counts, without an account identifier or individual mining event;
- terms, categories, and filters actually used; unique or removed candidate counts; and, only when an enabled user chooses to submit feedback, the partial ratings selected by that user;
- extension preferences, consent, tab context, terms, results, audits, and workflow state;
- local transport and recovery checkpoints, including up to 15,000 ad IDs, hashes, or projections per explorer, temporary staged pages, and pending supplier tasks, without cookies, tokens, or headers;
- a sanitized technical diagnostic generated locally only when requested by the user;
- messages voluntarily sent to support.
4. Purposes
Data is used to perform user-requested actions: extract a product, generate semantic terms and select categories with AI, search and rank candidates, retrieve supplier information, group ads, hand a product between Meta and MasterShop workflows, restore tab state, and retain preferences. The backend validates accounts, access decisions, limits, minimum extension version, and the model's structured response, and performs deduplication, ranking, and audit. Optional feedback is stored passively to guide future improvements; it never blocks terms, changes searches, trains agents, or modifies prompts automatically. MasterShop/Meta authentication data is used only for direct browser calls and is never sent to the MasterFinder backend or Google. The MasterFinder session authenticates only the protected API.
5. Consent and user control
On first use, the extension displays a disclosure and blocks extraction, search, enrichment, and collection until the current policy is accepted. The record contains the policy version and acceptance date. A later version may require renewed consent. Choosing “Not now” keeps those features blocked.
6. Storage and retention
Operational data may be held temporarily in memory, chrome.storage.session, and IndexedDB. If chrome.storage.session is unavailable, session contexts may fall back to chrome.storage.local. IndexedDB stores the tab's completed result, minimum recovery checkpoints, temporary staged pages, and supplier tasks that are still pending. Each Meta explorer keeps at most 15,000 confirmed IDs, hashes, or projections. Local contexts and payloads are deleted when the tab closes, leaves a supported URL, signs out, loses access, or its single active session is replaced. The extension does not create a history library. Preferences and consent remain in chrome.storage.local; the Supabase session remains until logout, replacement, reset, manual deletion, or uninstall.
MasterShop jobs collect for 5 minutes, drain for another 30 seconds, and allow finalization to begin until 10 minutes after creation; accepted computation may continue for up to 5 minutes, and all temporary result pages remain for up to 10 minutes after finalization. Meta segments last 5, 10, 15, 20, or 30 minutes as configured, drain for another 2 minutes, and allow finalization to begin until 10 minutes after collection; final snapshot pages remain for up to another 10 minutes. Sanitized products, candidates, occurrences, ads, and temporary backend projections are deleted after confirmed local persistence through DELETE, cancellation, or expiry. Technical failure tombstones may remain for 15 minutes without product or ad content. Term and category responses may remain in a pseudonymized cache for up to 7 days. AI generation audits remain for up to 30 days, and daily usage counters for up to 35 days. The normalized product URL, aggregate completed-search count, and optional feedback are retained indefinitely to produce statistics and guide improvements. Mining statistics never carry an account link. Upon hard account deletion, feedback loses the user, client IDs, and correlatable hashes, receives a new ID, and has its timestamp reduced to the UTC day; its URL, terms, categories, filters, and ratings remain anonymously. Identity, account, access decision, permissions, structured administrative events, and the minimal deletion ledger persist as needed to provide, protect, and control MasterFinder. Technical logs and metrics without payloads or content may retain request ID, pseudonymous identifier, endpoint, status, counts, bytes, and latency for up to 30 days.
Support diagnostic version 1.2 is generated only by user action, remains local until copied or downloaded, and is never transmitted automatically. It contains only version/environment, generic technical state, aggregate counts/bytes, up to 20 technical events, and up to ten sanitized flow incidents; it excludes identity, URLs, terms, products, ads, cookies, tokens, headers, and payloads. Support receives it only if the user chooses to share it. Voluntary support email and diagnostics may be retained for up to 90 days after resolution and then deleted unless retention is legally required.
7. Sharing and transfers
The browser calls MasterShop, Meta/Facebook, and the user-authorized page directly. For protected access, we use Supabase for authentication and database services, Render to host the API, and the Google Gemini API as the processor that generates search terms and selects categories. Google receives only the public URLs and, when needed, the sanitized context described above, under the configured service and applicable terms. These providers may operate infrastructure in other countries under their terms and safeguards. We do not transmit data for analytics, advertising, sale, or unrelated purposes.
8. Practices we do not perform
MasterFinder does not sell personal data, use data for personalized advertising, run automated analytics or telemetry, contain ads, or load remote code. The API returns JSON data only, never JavaScript, DSLs, or executable commands. The hosted policy uses no cookies, trackers, scripts, fonts, or external resources.
9. Chrome permissions
Permissions are used only to copy requested content, inject packaged local scripts where needed, display the side panel, keep preferences and state, identify the correct tab, and access supported hosts or an HTTPS origin granted by the user. Optional access is requested only after a user action.
If Meta responds with rate limit 1675004, the extension uses the required cookies permission to automatically and locally remove only the first-party datr, dpr, ps_l, and ps_n cookies for the Facebook origin and cookie store associated with the affected tab. The extension does not query, copy, log, persist, or transmit those cookie values; it does not remove known authentication cookies, run “Clear site data,” or reload tabs. Removal starts together with a mandatory 15-minute cooldown, may affect other Facebook tabs in the same profile, and never runs preventively: only after response 1675004.
10. Security
We use message and data validation, tab/session/generation/job isolation, HTTPS-only stored, opened, or transmitted URLs, short-lived renewable Bearer tokens, access-decision checks on each operation, payload limits, automatic expiry, limited hosts and resources, and packaging without remote code. Supabase handles passwords, which we do not log. No system is completely infallible; report suspected incidents to the contact address.
11. Data subject rights
Users may request information, correction, or deletion, including their identity, account, and access, as provided by applicable law. Local data can be removed by signing out, resetting or uninstalling the extension, or clearing its data in Chrome. Requests may be sent to hillcaetano@gmail.com; minimal information may be requested to confirm and locate the request.
12. Changes
This policy may change to reflect product, legal, or security developments. The version and effective date will be updated. Material changes may require renewed acknowledgement inside the extension.