Skip to content

Privacy Policy for AEM Editorial Toolbar

Last Updated: September 2026

Overview

The AEM Editorial Toolbar is a Chrome extension for Adobe Experience Manager users. I don't want your data, I don't collect your data, and I don't care about your data. The extension talks to your own AEM instances and, if you set one up, your own configuration URL. It talks to nothing else, and it sends nothing to me.

Simple Truth: I Collect NOTHING

Zero data collection. Zero tracking. Zero transmission to me or to any third party.

  • No personal information - I don't know who you are
  • No browsing history - I don't track where you go
  • No analytics - I don't measure what you do
  • No servers of mine - I run none, and nothing is sent to me or to any third party
  • No user accounts - I don't store profiles or login data
  • No cookies - I don't set tracking cookies
  • No fingerprinting - I don't identify your device

What Actually Happens

The Extension Reads

  • Current page URL: To detect if you're on an AEM site. The check itself is local. On a page that matches your configuration, the page's content path is used to build the requests to your own AEM instance described under Network Activity below
  • Page elements: To identify AEM editing contexts and to find images whose DAM asset can be looked up. Read in the page, and sent nowhere except as part of a request to your own AEM instance
  • Your configuration: YAML files you create to tell the extension about your AEM setup

The Extension Stores (In Your Browser Only)

  • Your preferences: Toolbar position, colors, enabled/disabled state
  • Your configuration files: The YAML files you create for your AEM environments
  • The last AEM author page you opened: One content path and the AEM origin it came from, so the options page can list that page's properties when you build a link from them. It is overwritten each time, so it is one page and not a history, and the options page has a "Forget this page" button
  • Nothing else: Seriously, that's it

Network Activity

Your AEM instances

Some toolbar features ask the AEM instance you are already working on about the page you are already looking at. Those requests are made by the extension's background script on the page's behalf:

  • Am I logged in? A check against the instance, so the toolbar knows whether to offer the features that need an author session
  • Which DAM asset is this image? A lookup for an image on the page, so the toolbar can offer a link into the asset's own screen
  • What are this page's properties? A read of the page's own node, when your configuration uses {page.<name>} tokens or you open the property picker in the options page
  • Which content fragments does this page use? A query against the instance's QueryBuilder endpoint, so the toolbar can list them

In every case:

  • Only your own instances: the request goes to a host in your own configuration and nowhere else
  • Your existing session: it carries the AEM login the browser tab already has, and asks for nothing you cannot already see
  • Answers stay in your browser: they are used to draw the toolbar, cached for the tab, and forwarded nowhere

These features need the instance to answer, so they do not work without a connection to it. The rest of the toolbar, which is built from the page URL and your configuration, does.

Remote configuration (optional)

IF you choose to load configuration files from external URLs (completely optional):

  • Simple file download: The extension downloads your YAML config files via HTTPS
  • No data sent: These are simple GET requests - no personal data is transmitted
  • You control the URLs: You specify exactly which URLs to fetch from
  • Cached locally: Downloaded files are stored in your browser to minimize requests
  • You can disable this: Use local files only if you prefer

Permissions Explanation

Why We Need Broad Website Access

The extension requires access to all websites (*://*/*) because:

  • Dynamic AEM Detection: AEM instances can be hosted on any domain, and the extension uses your configuration files to determine which sites are AEM environments
  • Multi-Environment Support: Organisations typically have AEM instances across multiple domains (production, staging, development, local)
  • User-Controlled Activation: The extension only activates functionality on domains you specify in your configuration files, with one exception: on any URL containing ".aem-toolbar.json" it reads the page's own text and offers a configuration import that you have to accept before anything is stored

Specific Permissions Used

The extension requests the permissions listed here and host access, and nothing else.

  • Storage: To save your preferences and configuration locally
  • Alarms: To schedule periodic fetching of remote configuration packages (if you configure one)
  • Host Permissions: To detect AEM contexts, inject the toolbar on configured domains, and ask your own AEM instances about the page you are on - those requests carry the AEM login the browser tab already has

Why I Don't Want Your Data

  • I'm not a data company: I build tools, not data profiles
  • Privacy by design: The extension talks to your own AEM instances and, if you set one up, your own config URL - nothing else
  • No business model around data: I don't sell data, analyze data, or monetize data
  • Simpler is better: No servers to maintain, no databases to secure, no privacy laws to navigate

Your Control

You have complete control over:

  • Configuration: What domains and settings the extension uses
  • Activation: The extension only works on sites you configure, apart from the configuration import described above
  • Data: All stored data can be cleared through Chrome's extension settings
  • Permissions: You can disable the extension or revoke permissions at any time

Changes to This Policy

I may update this privacy policy occasionally. Any changes will be reflected in the "Last Updated" date above. Continued use of the extension after changes constitutes acceptance of the updated policy.

Contact

If you have questions about this privacy policy or the extension's data practices, please contact me through the Chrome Web Store support channels.

Data Handling Summary

For Chrome Web Store compliance:

  • Personal Data Collected: None
  • Personal Data Shared: None
  • Personal Data Sold: None
  • Data Used for Advertising: None
  • Data Used for Analytics: None

Compliance

This extension is designed to comply with:

  • Chrome Web Store Developer Program Policies
  • General Data Protection Regulation (GDPR) principles
  • California Consumer Privacy Act (CCPA) requirements

Bottom Line

This extension is a tool for working with your own AEM instances. I built it to solve a workflow problem, not to collect data. Your privacy is protected because I literally don't have access to anything about you.

Questions? If you're still concerned about privacy, you can:

  • Review the source code (it's a standard Chrome extension)
  • Watch the network tab while you work, and check every request against the list above: you will see your own AEM instances and the config URL you set, and nothing else