Only the ticker leaves.
Privacy Policy · Effective July 19, 2026
The short version: TickerPop collects no personal data, no browsing
history, and no page content. What leaves your browser is the ticker symbol you explicitly
highlight — or one you starred yourself — sent directly to public data sources, a company's own
domain when we fetch its logo, and anonymous, opt-out feature-usage counts that never include
pages. There are no accounts and no servers that store anything about you.
Single purpose
TickerPop's single purpose is to display financial information for a ticker symbol the user
explicitly highlights on a web page (or types into the extension's own watchlist).
What data is processed, and where it goes
- Highlighted ticker symbols (e.g. "NVDA", "ASML.AS") and the matched company
name are sent from your browser directly to Yahoo Finance (quotes, charts,
fundamentals) and Google News RSS (headlines). These requests are subject to those
services' own privacy policies. Because they are made by your browser itself, they carry
the same cookies as visiting yahoo.com or news.google.com would — we never see them.
No other part of the page is ever transmitted.
- Spotting your watchlist on the page. If "Spot my watchlist on the page" is on
(Settings → Reading), TickerPop looks through the text of the page you are reading for the
ticker symbols you have starred, and underlines them. This matching happens
entirely inside your browser: the page's text is never sent anywhere, never stored,
and never seen by us or anyone else. The only request the feature can cause is a price
quote for symbols already on your watchlist — the same request your watchlist makes anyway.
Switch it off and no page text is examined at all.
- The price badge on a company's own website. If "Peek at the price on a company's own
site" is on (Settings → Reading), TickerPop can tell that, say,
apple.com is
Apple's own website and — only if AAPL is on your watchlist — rests a small sliver at
the edge of the screen that slides out when you move to that corner. Which site you are on is
never sent anywhere to work this out. The check is a lookup in a fixed list that ships
inside the extension, plus the website addresses already saved for companies
you starred — both of which live on your machine, so the address bar's contents
never leave your browser. Only the ticker the lookup finds is then quoted, which is
exactly the request starring that ticker already makes. It reads nothing from the page.
Press × and that site's hostname is stored with the time, so it stays quiet there for a
week; or switch the whole feature off in Settings.
- Watchlist, alert thresholds, and settings are stored in Chrome's built-in
storage.sync, controlled by your own Google account's Chrome sync. We never
see them.
- Snoozed and disabled sites. If you snooze or disable TickerPop on a site, that
site's hostname is stored with your settings so we can stay out of the way there. Like
everything else, it never leaves your browser.
- Company logos. The hover card shows a company's logo, fetched from
Google's public favicon service using that company's own website domain (for example
figma.com) — never your ticker, never the page you are on. The request is sent
with no-referrer, so Google is not told where you are browsing; what it can see
is that someone looked up a well-known company domain. If the logo can't be fetched — some
sites' security policy blocks it — the card falls back to a plain monogram and nothing is
requested at all.
- A static status file is fetched from this website (a service-health banner and the
welcome page on install). The request carries no personal data and nothing about what you
looked up.
- Nothing else leaves the browser. No page content, no URLs you visit, no browsing
history, no keystrokes, no personal identifiers.
Anonymous usage statistics
To understand which features help (and to notice quickly when a data source breaks),
TickerPop sends anonymous feature-usage events to PostHog and Mixpanel (US cloud, the same events to both): things like
"a card was opened for NVDA", "the Analysts tab was viewed", or "an error was shown", tied
to a random install identifier and the extension version. Since v2.3 this includes the
looked-up ticker symbol (a public market identifier) and anonymous diagnostics —
load-time buckets and crash reports that reference only the extension's own code.
- Never sent: the pages you visit, page content, your watchlist as a list, alert
thresholds, or anything you type. Event names and properties are allow-listed in code.
- Opt out any time: Settings → Privacy → untick "Share anonymous usage stats".
Nothing is sent after that.
What we do NOT do
- No accounts, sign-ups, or authentication of any kind.
- No ad networks, tracking pixels, or fingerprinting — the anonymous usage counts above
are the only telemetry, and they have an off switch.
- No servers that store your data — there is no database with anything about you in it.
- No selling, sharing, or monetization of data, ever.
- No AI processing of page content.
Permissions explained
- Access to websites — needed to detect when you highlight a ticker on the page
you're reading. The detection runs locally; only a highlighted symbol matching a strict
ticker pattern (≤16 characters) is ever used.
- storage — your watchlist and settings.
- alarms — periodic price checks (every 5–30 minutes, configurable) for alerts you set.
- notifications — showing those price alerts and earnings-day reminders.
- contextMenus — the right-click "Look up ‹selected text›" action. Only the text you
selected is used.
Changes
If this policy ever changes, the new version will be posted at this URL with an updated
effective date. Material changes will be noted in the extension's changelog.
Contact
Questions or concerns? Reach us through the
support tab on the Chrome Web Store listing.