Last updated: September 17, 2026
Privacy Policy
At WaaFaa, we value your privacy and are committed to protecting your personal information. This policy explains how we collect, use, disclose, and safeguard your data.
WHAT WE COLLECT
Browsing history
none
Page content you view
only what you send Briefly
Account required
no
Files you open
never uploaded
Install identifier
random, Pro only
Processing happens on your device, except the summaries Briefly asks a model for. See the full policy below.
1. Introduction
WaaFaa is committed to protecting your privacy. This Privacy Policy outlines how we collect, use, and protect your information when you visit our website or use our services.
2. Information We Collect
We may collect personal information, usage information, cookies and similar data needed to improve your experience.
3. Browser Extension Data
Our browser extensions — Hide Shorts, Reels & Stories, PDFCraft, ImagePolish, Formatly, FileLens, Profile Tags, LeadProof and Briefly — do their work in your browser. Hide Shorts, Reels & Stories hides selected content, such as short-form video. PDFCraft converts images to PDF and merges PDFs. ImagePolish inspects images and removes hidden information from them. Formatly restyles text you are writing. FileLens renders Markdown and JSON files you open. Profile Tags stores private labels you add to profiles. Briefly summarises the article on a page you choose. LeadProof scans a website you choose and extracts published business contact details from it. Your in-extension settings (for example, which content types to hide) are stored locally on your device and are never sent to our servers. Any file you open in PDFCraft or ImagePolish is processed entirely on your own device and is never uploaded to us or to anyone else. The extensions do not collect, transmit, or store your browsing history or the content you view, and we do not track your activity across websites.
LeadProof
LeadProof asks for no website access at install. It cannot reach any site until you name one and press Scan, at which point your browser asks you to grant that one origin. It then reads that site’s public pages and extracts business contact details published on them. Everything it finds — leads, evidence, source URLs and scan history — is stored only on your own device, and none of it is ever sent to us or to anyone else. Page content, discovered addresses, people’s names, company names and scan counts never leave your browser.
Beyond the site you ask it to scan, LeadProof can make only two other network requests, both switched off by default and each needing a separate permission you grant: api.freemius.com, when you activate a Pro licence key, which receives the key and a random install identifier; and cloudflare-dns.com, if you switch on mail-server verification, which receives the domain of an address and never the address itself. That install identifier identifies an installation, not a person. LeadProof shows only information a website has published itself, which is not the same thing as permission to market to it — how you use the results, and your compliance with GDPR, CAN-SPAM and equivalent laws, remains your responsibility.
Briefly
Briefly is the one extension here that does not do all of its work on your device. Summarising an article needs a language model, and that model runs somewhere else. Everything below is about where the text goes and who receives it.
Briefly asks for no website access at install and has no background activity. It reads nothing until you click its icon, and then only the article in that one tab. If the page has no readable article, or is short enough to simply read, it says so and sends nothing at all.
On the free tier we receive nothing. Briefly runs on an API key you obtain yourself from a provider you choose, and the article text goes from your browser straight to that provider under the agreement you hold with them — not through any server of ours. What that provider then does with the text is governed by their terms, which we are not a party to and cannot make promises about. Briefly names the recipient on screen before the first request, and warns you where a provider’s free tier trains on what you submit.
On Pro we run the model, so the text does reach our server — carrying no identifier of you. The request that proves your licence and the request that carries your reading are two separate calls: the first sends an install identifier and no page text, and returns a short-lived opaque token recording a tier and an expiry and nothing else; the second sends the article with that token and no identifier of any kind. Article text is used to produce your summary and is not stored, logged or used for training. A salted device hash used only to stop one licence being shared across many machines is kept for 48 hours and joined to nothing.
Your settings, your API key and the summaries you save stay in your own browser until you delete them. Removing the key in Settings also withdraws the network permission. The full detail is in Briefly’s own privacy policy.
Advertising in the extension popup
The Hide Shorts, Reels & Stories extension is free and is funded by promotional content shown inside its own popup — and nowhere else. This applies to that extension only: PDFCraft, ImagePolish, Formatly, FileLens, Profile Tags, LeadProof and Briefly carry no advertising of any kind. Nothing is ever added to YouTube, Facebook, Instagram, or any other website you visit. There are two kinds: a single contextual ad supplied by AdsOnBread, an advertising network for browser extensions, and two in-house promotional slots whose content we serve ourselves.
Pro is ad-free. An active Pro entitlement hides every promotional slot, and no ad is requested from AdsOnBread at all, so the rest of this section does not apply to a Pro installation.
Each time the popup is opened, free installations request the current in-house slot content from our own server at https://waafaa.com/wp-json/hide-shorts-reels/v1/ads. That request carries no identifier of any kind — no User ID and no query parameters — and returns the same response for every installation. As with any web request our server sees the connecting IP address, which is not stored alongside any identifier or used to build a profile.
To request that ad, the AdsOnBread SDK stores a randomly generated token and a 24-hour expiry time in local extension storage, and sends the unexpired token, your browser language, and ad impressions and clicks to AdsOnBread. This is used only to limit how often you are shown the same ad, for billing accuracy, and to prevent fraud. AdsOnBread also derives a coarse country from the network request. This information is not used for behavioural advertising or for profiling you across websites.
The token is random and rotates every 24 hours. It is not tied to your name, email, account, or browsing history, and neither the extension nor AdsOnBread receives the pages you visit or the content you choose to hide. The stored token is removed by clearing extension storage or uninstalling the extension. See the AdsOnBread privacy policy for their server-side retention schedule.
To check Pro access, the extension sends a randomly generated install User ID to our entitlement API at https://waafaa.com/wp-json/hide-shorts-reels/v1/entitlement. That ID identifies an installation, not a person — it is not your Google, YouTube, Facebook, or Instagram account. If you purchase a Pro subscription, we process only the licence details needed to verify your entitlement (such as the email associated with your purchase); all payments and billing data are handled by Freemius as our Merchant of Record. For details specific to each extension, see its listing on the Chrome Web Store, and the Hide extension privacy policy.
4. How We Use Your Information
We use information to provide services, respond to inquiries, improve products, send opted-in updates, prevent fraud and meet legal obligations.
5. How We Share Your Information
We do not sell your personal information. We may share information with trusted service providers, legal requirements and business transfers.
6. Data Security
We implement industry-standard security measures to protect data from unauthorized access, alteration, disclosure or destruction.
7. Your Rights
You may request access, updates, deletion, opt-out, restriction or withdrawal of consent by contacting privacy@waafaa.com.
8. Cookies
You can manage cookie preferences through your browser settings. Disabling cookies may affect website functionality.
9. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices.
10. Changes to This Policy
We may update this Privacy Policy from time to time and will post the new policy with an updated date.
11. Contact Us
Email: support@waafaa.com. Phone: +880 16871 66885. Address: Deshipara, Gazipur Sadar, Gazipur, Bangladesh.

