TinkerfontSupport the Project

Last updated July 9, 2026

Privacy policy

Tinkerfont is available as a Chrome extension and a Firefox add-on for typography prototyping on the live web. This policy explains what data the extension uses, why browser permissions are needed, and how we handle your information.

The short version

Tinkerfont does not require an account and does not sell your data. Your font rules, area scopes, theme preference, uploaded custom fonts, and cached font catalog are stored locally on your device by default. The replacement panel runs when you click the extension icon; a lightweight inspect script loads on pages you visit for the right-click font inspector.

If you use Share, settings for the current site are sent to tinkerfont.com and stored temporarily so you can paste them on the same hostname or download a JSON file. We do not receive your page content, browsing history, or analytics from the extension.

Chrome extension

Local storage (chrome.storage.local)

Tinkerfont uses chrome.storage.local to save user settings on your device:

  • Per-site font replacement rules
  • Optional area selectors (which parts of a page to scope)
  • Panel theme preference (light or dark)
  • Uploaded custom font files
  • A cached Bunny Fonts catalog for faster search

This data persists across browser sessions. Storage is only for local settings and user-uploaded fonts. No data from storage is sent to external servers operated by Tinkerfont. You can remove individual rules in the panel, clear extension data from Chrome settings, or export and delete your setup manually.

When the extension runs (activeTab)

Tinkerfont's font replacement panel only runs on the tab you are viewing when you click the extension icon. The activeTab permission grants temporary access to that tab so the extension can open its panel, scan fonts on the page, and apply font replacements you choose. The extension does not access tabs in the background without user action for panel features.

Right-click font inspector (contextMenus)

Tinkerfont adds a Tinkerfont entry to the right-click context menu on normal web pages. The contextMenuspermission is used only to create and update this inspect submenu. Inspector data is computed locally from the page's DOM and styles — not sent to Tinkerfont or any other server.

font-inspect.jsloads on pages you visit. It may fetch linked stylesheets from the page's own origins to read font sources. Font file detection is experimental; system fonts have no file URL, and a URL may not appear in some cases.

Copy to clipboard (clipboardWrite, offscreen)

Tinkerfont can copy values to your clipboard from the right-click font inspector, from Copy CSS on active rules, and when you create a share link. The extension uses clipboardWrite and a short-lived offscreen document so copies work from the floating panel on strict sites (Chrome service workers cannot access the clipboard directly). The offscreen document is closed immediately after copying.

Copied values stay on your device. Tinkerfont does not receive or store what you copy.

Share and paste (tinkerfont.com)

When you click Share, the extension sends a JSON payload for the current site only — replacement rules and optional area selectors — to tinkerfont.com/api/go. Custom font files are not uploaded; only rule metadata is sent.

We store that payload on our server (Cloudflare D1) under a short link such as tinkerfont.com/go/abc123xyz0. Links expire after 14 days. Anyone with the link can view summary metadata on the share page or download an import-compatible JSON file. Paste only applies settings when you are on the same hostname as the share; pasting on a different site is blocked.

Share and paste are optional. If you never use them, no settings leave your device for this feature.

Script injection (scripting)

When you click the Tinkerfont icon, the extension may inject bundled content scripts into the active tab if they are not already loaded. font-inspect.js is registered as a content script for the right-click inspector. Only packaged extension files are injected — no remote code.

Host access (http and https)

Host access lets Tinkerfont run on pages you open, detect fonts in use, inject font overrides, and display its panel. When you apply a Bunny Font, font files may be fetched from fonts.bunny.net directly from your browser — not through Tinkerfont servers.

Firefox add-on

Local storage (browser.storage.local)

The Firefox add-on uses the WebExtensions storage API (browser.storage.local) for the same local data as the Chrome version:

  • Per-site font replacement rules
  • Optional area selectors
  • Panel theme preference
  • Uploaded custom font files
  • A cached Bunny Fonts catalog

Data stays on your device. You can clear add-on storage from Firefox's extension settings or remove rules individually in the panel.

Data collection declaration

The Firefox manifest declares data_collection_permissions with none— Tinkerfont does not collect, transmit, or sell personal data. This matches Mozilla's add-on data disclosure requirements.

When the add-on runs (activeTab)

The font replacement panel runs on the tab you are viewing when you click the add-on icon. activeTab grants temporary access to that tab for scanning fonts and applying replacements. The add-on does not monitor tabs in the background for panel features.

Right-click font inspector (contextMenus)

The Firefox add-on provides the same right-click Tinkerfont inspect submenu. Typography is computed locally. font-inspect.js may read linked stylesheets and performance data to resolve font file URLs when possible.

Copy to clipboard (clipboardWrite)

The Firefox add-on can copy inspector values, CSS snippets from active rules, and share links to your clipboard. It requests clipboardWrite where needed. Unlike Chrome, the Firefox add-on does not use an offscreen document — copies use the clipboard APIs available in the add-on or page context.

Copied values stay on your device. Tinkerfont does not receive or store what you copy.

Share and paste (tinkerfont.com)

The Firefox add-on provides the same optional Share and Paste flow as the Chrome extension. Sharing sends per-site rules and area selectors to tinkerfont.com/api/go; custom font binaries are not uploaded. Stored links expire after 14 days. Paste only works on the hostname the share was created for.

Script injection (scripting)

When you click the add-on icon, bundled scripts may be injected into the active tab. The background runs as a persistent script (not a service worker). Only packaged add-on files are used — no remote code.

Host access (http and https)

Host permission for <all_urls> lets the add-on work on pages you open for font detection, replacement, and the floating panel. Bunny Font requests go directly from your browser to fonts.bunny.net.

Bunny Fonts (bunny.net)

Both versions integrate with Bunny Fonts. When you search or apply a Bunny Font, your browser requests font metadata, CSS, and font files from Bunny's servers. Tinkerfont does not send your rules, page content, or browsing history to Bunny.

Import, export, and share downloads

Export and Import write or read a JSON file you choose on your device. Custom font binary data is not included in exports — only font names and metadata.

Share pages at tinkerfont.com/go/… also offer a Download JSON file in the same import format, so you can save a shared setup without using Paste in the extension.

Data stored for a share link includes the site hostname, replacement rules, area selectors, and timestamps. We do not store page HTML, page text, or custom font file contents in shares.

  • Links expire automatically after 14 days
  • Anyone with the link can open the share page or download the JSON export
  • Paste in the extension is limited to the hostname the share was created for
  • We do not use share data for advertising or sell it to third parties

How we use data

User data is used only to provide Tinkerfont's single purpose: typography prototyping and inspection on live websites.

  • We do not sell or transfer user data to third parties, except fetching font files from Bunny Fonts when you choose to apply them, and temporarily storing share payloads when you explicitly click Share.
  • We do notuse or transfer user data for purposes unrelated to the extension's single purpose.
  • We do not use or transfer user data to determine creditworthiness or for lending purposes.

What we do not collect

  • No accounts or sign-in for the extension
  • No analytics or advertising trackers inside the extension
  • No remote code execution in the extension
  • No automatic cloud sync of your rules — only if you export, import, or share yourself
  • No transmission of page content to Tinkerfont when you inspect or replace fonts

This website (tinkerfont.com)

The marketing site at tinkerfont.com hosts install links, documentation, the support form, share pages, and this policy. We do not use advertising cookies.

Analytics. We use privacy-focused analytics via um.tinkerfont.com (self-hosted Umami) to understand aggregate traffic on the website — not inside the browser extension. No personal profiles are built for advertising.

Support form. If you contact us, we receive the name, email, subject, and message you submit, plus a Cloudflare Turnstile verification token to reduce spam. Messages are sent by email to our support inbox.

Share API. When you or another user creates a share from the extension, settings are stored on our infrastructure as described in Share links on tinkerfont.com.

If you click “Add to Chrome” or install from Firefox Add-ons, you leave this site for the respective store, which has its own policies.

Children

Tinkerfont is not directed at children under 13, and we do not knowingly collect information from them.

Changes

We may update this policy as the product changes. When we do, we will revise the date at the top of this page.

Contact

Questions about privacy? Email tinkerfont@m64.in.

← Back to home