Lawha · لوحة — Privacy Policy
Last updated: 18 August 2026
Lawha does not collect, transmit, sell, or share any personal data. It makes no network request of its own — the one exception is the Feeds feature, which fetches only the RSS or Atom URLs you explicitly add, directly from your browser to that feed's own server. Everything else it knows about you stays in your own browser, and you can confirm all of this yourself in DevTools → Network: with Feeds off, it is empty; with Feeds on, it shows exactly the feed addresses you added and nothing else.
What Lawha is
Lawha is a Chrome extension that replaces the new tab page and adds a tab sidebar. It is free, has no accounts, no subscription, and no backend server of any kind.
Data we collect
None. There is no analytics, no telemetry, no crash reporting, no advertising identifier, and no remote server for any of it to be sent to. No data ever leaves your device.
Data stored locally on your device
The following is saved using Chrome's own storage APIs and stays in your browser. Deleting the extension deletes all of it.
- Your shortcuts — the addresses and labels you add
- Your notes — the text you write
- Your reading queue — pages you save for later
- Your scene, palette, layout, language and numeral preferences
- Your background image, if you choose one from your own disk
- Tab access timestamps, used to mark a tab you have not looked at in a day
- A list of currently open tab addresses, so a browser crash does not lose your session
- Your feed subscriptions, if you use Feeds — the URLs you added and the last ten headlines fetched from each
Preferences are small and are stored with Chrome Sync so they follow you between your own signed-in devices — that is Chrome's own sync, under your Google account, not a Lawha server. Everything containing your content — notes, shortcuts, reading queue, images — is stored locally only, and never syncs anywhere.
Permissions, and exactly what each is for
- tabs
- To list the tabs open in the current window in the side panel and to switch, pin, mute or close them; to find them in the command palette; to record the list of open addresses so a crash does not lose your session; and to count them for the toolbar badge if you turn that on. Lawha reads tab titles and addresses; it cannot read the contents of any page.
- bookmarks
- To display your bookmark folders on the new tab page and find bookmarks in search.
- history
- To display your recently visited pages on the new tab page and find them in search. History is read at the moment the page is drawn and is never stored by Lawha, never aggregated, and never transmitted.
- storage
- To save your preferences, notes, shortcuts and reading queue, as described above.
- favicon
- To show site icons next to tabs, bookmarks and shortcuts. These come from Chrome's own local favicon cache — no icon is fetched from the internet.
- sidePanel
- To display the sidebar.
- alarms
- To refresh your feeds roughly every 30 minutes in the background, if you use Feeds, without keeping a connection open. Unused otherwise.
- offscreen
- To parse the RSS/Atom XML a feed returns. Chrome's background service worker has no DOM, so this creates a hidden, invisible page purely to read that XML — it is never shown, and never navigates anywhere.
- host_permissions (all URLs)
- Required so the background service worker can fetch the feed URLs you add in Feeds — Chrome only bypasses a site's cross-origin restrictions for a service worker when the manifest grants this. It is used only for the fetch() calls Feeds makes to addresses you typed in yourself. Lawha has no content scripts and cannot read, modify, or inject anything into any web page you visit; this permission does not change that.
Feed subscriptions
If you use the Feeds feature, Lawha fetches the RSS or Atom feed URLs that you add. Those requests go directly from your browser to that feed's own server — there is no Lawha server in between, and the feed content is stored locally on your device, the same as your notes or shortcuts. Lawha does not aggregate, analyse, or transmit which feeds you follow or what you read. Feeds is off by default; nothing is fetched unless you turn it on and add a feed yourself.
Network requests
Lawha makes none of its own. Fonts, icons, the five built-in Scenes and every other asset ship inside the extension; colours are computed on your machine. The one exception is Feeds, described above: a request to a feed URL you added yourself, and nothing else. Feeds is off by default, and the extension code that fetches a feed only ever runs when you turn Feeds on and add one — if you never do, nothing is ever requested from anywhere but the extension's own package.
Scenes you import
A Scene is a plain JSON file describing colours and layout. Importing one from someone else changes only how Lawha looks. A Scene contains no code and has no route to your notes, shortcuts, or any other data — that boundary is enforced in the extension's own storage layer, not left to convention.
Children
Lawha collects no data from anyone, of any age.
Changes to this policy
If this policy ever changes, the date at the top of this page changes with it. Material changes to what is stored or why will be described here rather than quietly swapped in.
Contact
Questions about this policy or about Lawha's handling of data: hassanbil999@gmail.com