Privacy policy
In short: your bookmarks and device names are encrypted on your device before they reach us, and we don’t have the keys. We don’t ask for your name, email address or password. We don’t use analytics, ads or trackers, and we don’t sell or share data.
Who we are
FerryKey is a browser extension and sync service run by ILB Computing, an Australian business (“we”, “us”). This policy covers the FerryKey extension for Chrome and Firefox, the sync service at api.ferrykey.com and mqtt.ferrykey.com, and this website. We handle personal information in line with the Australian Privacy Principles.
How FerryKey works
When you set up FerryKey, your browser creates a random secret and shows it to you as 24 recovery words. All of FerryKey’s keys come from that secret or are created on your devices. Your bookmarks are encrypted on your device with those keys, and only the encrypted result is uploaded. Each browser forgets the 24 words once it is set up and keeps its own device key instead.
We never receive your 24 words or any key that can decrypt your data. We will never ask you for your 24 words. Anyone who does is not us.
What the extension accesses on your device
- Your bookmarks (titles, addresses and folders), so it can sync them. They are read and changed only inside your browser, and leave it only in encrypted form.
- Extension storage, to keep this browser’s device keys, sync state and settings. This stays on your device.
The extension does not read your browsing history, the pages you visit, your tabs, or anything else in your browser.
Future features are opt-in only
Today FerryKey syncs bookmarks and nothing else. We plan to add other kinds of data later, such as passwords from password managers. Any new kind of data will be:
- Strictly opt-in. Off by default. Nothing beyond bookmarks is read or synced until you explicitly turn that feature on, for that kind of data, on a device you choose.
- End-to-end encrypted in the same way as bookmarks, with keys we never have.
- Kept out of the browser extension where it is sensitive. Passwords and password-manager access keys will be handled by a separate desktop app that keeps them in your operating system’s secure keychain, not by the extension.
- Announced first. We will update this policy and say exactly what is accessed before any such feature is released, and you can turn it off again at any time.
What we store on our servers
| Data | Can we read it? | Why |
|---|---|---|
| Encrypted bookmarks (each change and periodic full copies), padded to fixed-size blocks | No | To sync your bookmarks between your browsers |
| Encrypted device names | No | So your browsers can show your device list |
| Account ID (a fingerprint of a public key), device public keys, and a signed log of devices added or locked out | Yes, but they are random numbers, not personal details | To check that requests come from your devices |
| Technical details: when each device last synced, how many changes and roughly how much encrypted data each account stores, sequence numbers and timestamps | Yes | To run the service, apply storage limits and fix problems |
| Signup counter per network (see below) | Only as an unreadable code | To limit abuse |
We cannot see the titles, addresses or folders of your bookmarks, or the names of your devices. Because padding hides exact sizes, we only see approximately how much you store.
IP addresses
Your IP address is visible to our servers and to Amazon Web Services while your device is connected, as with any internet service. We don’t store it in our database. To stop people creating huge numbers of accounts, we count new accounts per network per day (the limit is 5). For this we keep only a code computed from your network address, the date and a secret key (the first three parts of an IPv4 address, or the first half of an IPv6 address). The code can’t be turned back into an address, and it is deleted automatically after about two days.
Our application logs record errors and service events. They are designed not to contain IP addresses or your data, and are kept for 30 days.
Live updates
To sync quickly, each browser keeps a connection to mqtt.ferrykey.com. When one of your browsers uploads a change, the others get a short notice that something new is available, and then fetch it. These notices contain no bookmark content. They are addressed to a random code that does not reveal your account ID, and are kept in memory only.
The website
This website sets no cookies, runs no scripts, and loads nothing from other sites. Our servers see the usual technical details of each request (such as your IP address and browser) while serving the page, and we don’t keep them.
What we don’t do
- No analytics, telemetry, advertising or tracking of any kind.
- We don’t sell, rent or trade data, and we don’t use it for advertising or profiling.
- We don’t share data with anyone except our hosting provider (below), or where Australian law requires it. Even then, all we could hand over is what is listed above: we have no way to decrypt your bookmarks.
Where your data is kept
FerryKey runs on Amazon Web Services (AWS) in the Sydney region (ap-southeast-2), Australia. AWS stores and processes data for us as our hosting provider and has no access to your keys. We don’t use any other service providers to handle your data.
How long we keep it
- Your encrypted data, public keys and device log are kept while your account exists.
- Signup network codes: about two days. Application logs: 30 days.
- Policy: accounts with no activity from any device for 18 months may be treated as abandoned and their data deleted.
Locking out devices and deleting your data
You can lock out any browser from the device list in FerryKey. It loses access immediately, and data synced afterwards uses new keys it doesn’t have.
Uninstalling the extension deletes its keys and sync state from that browser. Your bookmarks stay in the browser.
There is no self-serve way to delete your account from our servers yet. To have an account’s data deleted, contact us. Because accounts have no email or name, we’ll work with you to confirm the account is yours, for example from a browser that is still set up. Never send us your 24 words.
Your rights
You can ask what personal information we hold about you, ask us to correct or delete it, or complain about how we handle it. Because we hold so little and can’t link accounts to people, we may only be able to help if you can show that an account is yours. If you’re not satisfied with our answer, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
Children
FerryKey is not directed at children under 13, and we don’t knowingly collect information about them. We don’t collect names, ages or contact details from anyone.
Changes to this policy
If we change this policy, we’ll update the date at the top. If a change means we would collect or use data in a new way, we’ll explain it in the extension before it takes effect.
Contact
Email support@ferrykey.com with any privacy question or request.