Effective 3 August 2026
Privacy Policy
ERS is designed to collect only what is needed to create references and operate Pro licenses. The free modes do not upload the page you are viewing.
At a glance
- Strict and Enhanced: reference extraction and RIS generation happen locally in your browser.
- Pro: the generated RIS metadata is sent to the ERS service over HTTPS for validation and enrichment. The complete page HTML is not uploaded.
- No advertising: ERS does not sell personal data or use behavioral advertising trackers.
- No browsing history: ERS acts only when you click it and does not maintain a browsing-history profile.
Data controller and contact
ERS Reference Saver is operated by Sandra Marents. Privacy and support requests can be sent to sandramarents@gmail.com.
Data processed by the extension
Strict and Enhanced modes
When you request a reference, ERS reads citation-related metadata from the active tab, such as title, authors, date, publication, DOI, abstract, keywords and canonical URL. It uses this information locally to create the downloaded RIS file. This data is not sent to the ERS server in these modes.
Pro mode
When you explicitly use Pro, ERS sends the generated RIS record to the ERS backend. Depending on the available fields, this can include title, authors, DOI, abstract, publication details and source URL. Processing may use ERS-operated infrastructure in Norway with a Cloudflare edge fallback. ERS may use Crossref, Unpaywall and xAI to check or normalize these fields. The full source-page HTML is not transmitted.
License and purchase data
Stripe processes payment information. ERS receives purchase identifiers and the purchaser email needed to create and deliver a license; ERS does not receive or store full card details. Resend processes outgoing transactional license emails.
For activation, the extension sends the license key and a random installation identifier. The backend stores a keyed hash of that identifier to enforce the installation limit; it does not need to store the raw identifier. New license tokens and installation identifiers are stored locally in the browser. A legacy synchronized token may remain temporarily for users upgrading from ERS 1.6 so existing installations continue to work.
Operational data
The service may process standard security and diagnostic data, including request time, endpoint, error information, IP-derived anti-abuse keys and Pro usage token counts. Anti-abuse keys are hashed. These data are used to operate, secure and troubleshoot the service, not to build advertising profiles.
Storage and retention
Customer email, license status and activation records are retained while needed to provide the purchased license and handle support. Short-lived rate-limit records expire automatically. Provider logs may be retained according to the applicable provider settings and policies. Data no longer required for legal, security or service purposes is deleted or anonymized.
Legal basis and processors
License and purchase processing is necessary to perform the user agreement. Security and reliability processing is based on legitimate interests in preventing abuse and maintaining the service. Optional Pro enrichment occurs only when the user selects Pro. Processing uses ERS-operated infrastructure and may involve Cloudflare (edge services and database), Stripe (payments), Resend (transactional email), Crossref and Unpaywall (metadata lookups), and xAI (metadata normalization where needed).
Permissions used by the extension
- activeTab and scripting: read citation metadata from the page only after the user invokes ERS.
- downloads: save the generated RIS file.
- storage: remember mode selection, installation identifier and Pro activation locally.
- ERS backend access: activate licenses and process Pro requests.
Your choices and rights
You can use Strict or Enhanced without sending reference metadata to ERS. You can remove locally stored extension data by uninstalling the extension or clearing its storage. Depending on applicable law, you may request access, correction or deletion of personal data, or object to certain processing, by emailing the address above. Identity verification may be required before fulfilling a request.
Security and changes
ERS uses HTTPS, scoped browser permissions, signed license tokens and access controls intended to protect the service. No system can guarantee absolute security. Material policy changes will be posted on this page with an updated effective date.