Skip to content

← Back to Lux

Lux Privacy Policy

Last updated: September 6, 2026

1. Summary

Lux is a new tab dashboard for Chrome, Brave and other Chromium browsers. It runs in your browser and keeps your data on your device. There is no Lux account, no analytics, and no server of ours that stores your information.

Lux operates one piece of infrastructure: a small, stateless relay that helps connect certain accounts, refreshes their access tokens, and forwards feedback you choose to send. It stores nothing. Everything else happens between your browser and the services you connect to it.

This policy covers the Lux browser extension and this website. It explains what Lux reads, why, where it goes, and what you can do about it.

2. Who operates Lux

Lux is built and operated by an individual developer, not a company. You can reach the developer at hyun@hyunwk.me. The extension’s source code is public at github.com/hyunwoo312/lux, so the claims below can be checked against the code that makes them.

3. What Lux stores on your device

Your dashboard settings and anything you create in it stay in your browser. That includes your widget layout, tasks, notes, quick links, watchlists, followed teams and preferences. Lux holds them using the browser’s chrome.storage.local API. Nothing in this category is sent anywhere.

Lux also uses chrome.storage.session for one short-lived value during AniList sign-in. It is cleared when the sign-in finishes or the browser closes.

Images you upload for a wallpaper or an Image widget are converted and kept as files in the extension’s own browser storage. They are never uploaded to Lux or anywhere else.

4. Accounts you connect

Every account is optional. Nothing connects until you ask it to, and each provider grants only the access its widget needs. In all cases the data is fetched directly from the provider to your browser.

Access tokens

When you connect Google, Microsoft, Spotify, GitHub or AniList, the resulting OAuth tokens are stored on your device. Google, Microsoft and GitHub need a confidential client secret to issue those tokens, which a browser extension cannot hold safely, so their exchange goes through the Lux relay described in section 11.

Where sign-in happens

Connecting Google, Microsoft, Spotify, GitHub or AniList sends your browser to that company’s own sign-in page, where you enter your credentials. Lux never sees or fetches those pages, and your password is never typed into Lux.

Account identity

Lux reads basic profile details such as your email address or username, for the single purpose of showing you which account is connected.

Google Calendar and Outlook Calendar

Read-only. Lux reads your upcoming events to display them in the Calendar widget. It never creates, edits or deletes an event.

GitHub

Lux reads your contribution activity, notifications, pull requests, and the repositories you watch along with their latest releases. The token GitHub issues carries the reposcope, which GitHub defines as account-wide read and write access to your repositories, including private ones. Lux asks for it because it is the only scope that lets private contributions count in your graph, and uses it only to read. Lux writes only to your notifications, and only when you act: marking one read, marking all read, or unsubscribing from a thread. It never changes a repository.

Spotify

Lux reads your current playback and available devices to show and control what is playing, and reads your saved tracks and playlists for the widget’s library view. Search sends the words you type to Spotify, which searches its whole catalogue. Playback changes happen only when you press a control.

AniList

Lux reads your anime and manga lists, your notifications, and the recent activity of people you follow. AniList offers no read-only scope, so the token it issues is account-wide. Lux writes only when you act deliberately: the like button, the episode and chapter counters, adding a title to your Planning list, moving a title to Watching or Reading, and mark-all-read. It makes no other change to your account.

AniList sign-in redirects briefly through a page on this site atlux.hyunwk.me/anilist/callback. That page reads the token from the address bar and hands it to the extension. The token travels in the URL fragment, which browsers never send to a server.

5. Services Lux contacts without an account

Several widgets read public data. None of them involves an account, an API key, or anything that identifies you.

  • Weather. When you add a place, the text you type is sent toOpen-Meteo’s geocoder to find it. After that, only the chosen place’s coordinates are sent to fetch its forecast. Lux does not read your device location, and your chosen location stays on your device.
  • Stocks. Lux fetches public quotes from Yahoo Finance for the ticker symbols on your watchlist, and sends the text you type when you search for a symbol to add. Yahoo publishes the same data on two hosts, and Lux tries the second if the first fails. When your watchlist is empty, or you open the stock search with nothing typed, Lux asks for the public trending list to make suggestions, and that request says nothing about you.
  • Sports. Lux fetches public scoreboards from ESPN for the league you pick. Only the league, and a date range where you narrow it, is sent. If ESPN’s main host fails, the same request goes to its public mirror. The teams you follow stay on your device.
  • News. Lux fetches public RSS headlines from Google News, The New York Times, the BBC, The Guardian, NPR and Yahoo News for the edition you choose. The search box sends only the words you type. The Trending tab fetches Google’s public trending-searches feed for your chosen region; only the region code is sent, the request carries no cookies, and it is not tied to any Google account you are signed in to elsewhere.

Where a news feed offers a thumbnail, the image loads from the publisher’s own image host. Those hosts are chosen by the publisher, not by Lux. Turning off Load images renders plain headlines and contacts no image host at all.

6. Optional browser access

Lux installs with a small set of permissions and asks for the rest only when you turn on a feature that needs them. You can review and revoke them at any time in Settings.

Granted at install

  • Storage. Holds your dashboard on your device. Lux also requests unlimited local storage so that a large wallpaper is not dropped when the browser runs low on space.
  • Favicons. Draws the small site icons beside your links using Chrome’s own local favicon service. No request leaves your machine to fetch them.
  • Search. Lets Lux hand a query to whichever search engine you have already set as your browser default. Lux does not choose the engine and does not see the results.
  • Identity. Used for the Chrome sign-in flow described above.

Requested only if you enable the feature

  • Bookmarks, history and most-visited sites. Read on your device to fill the Quick Access widget and to answer what you type into the command palette.
  • Open and recently closed tabs. Two Quick Access sections and the command palette need these, and all stay off until you switch them on. Recently closed needs it because Chrome otherwise withholds a closed tab’s title and address. Open tabs reads the title, the address, and whether a tab is playing audio, so it can list them and act on the one you click.

Lux never injects anything into the pages you visit and never records where you browse. The tab list is drawn fresh each time you open a new tab and is gone when you close it.

7. How Lux uses this data

Lux uses this data only to render the features you have turned on. There is no advertising, no profiling, no model training, and no purpose beyond the widget in front of you. Lux does not sell your data and has nothing to sell it to.

8. How your data is protected

The safeguards below apply to everything Lux touches, including sensitive data such as your calendar events and your account email.

  • Encrypted in transit. Every request Lux makes travels over HTTPS with TLS. That covers the services you connect, the Lux relay, and the public weather, stock, news and sports sources.
  • Isolated on-device storage. Settings and tokens are held inchrome.storage.local, which is sandboxed to the Lux extension and separated by your browser profile and your operating-system account. Websites cannot read it, other extensions cannot read it, and it is never synced to a cloud service.
  • Minimised, and never sent to a Lux server. Lux requests only the scopes the features you enable actually require. Provider data is fetched straight to your browser and processed there. Your calendar and account data never pass through a server we run.
  • Not shared, sold or profiled. Your data is not passed to third parties, not used for advertising, not used to train any model, and not read by any human at Lux.
  • Revocable by you. Disconnecting an account deletes its tokens from your device. Clearing the extension’s data or uninstalling it removes everything Lux holds. You can also revoke access from the provider’s own security settings, such as yourGoogle Account third-party access page.

No method of transmission or storage is completely secure. Lux reduces its exposure by holding as little as possible and running no server that could be breached for your data. If a security incident occurs that affects you, the developer will notify affected users and any regulator where the law requires it.

9. Storage and retention

Because Lux stores nothing off your device, retention is entirely in your hands. Settings and tokens remain in your browser until you disconnect an account, clear the data, or uninstall the extension.

Widget data is held as a cache on your device so a new tab is ready immediately. A cache that has gone unused for seven days is swept the next time a new tab sits idle. Settings → Storage & Backup shows what Lux is currently holding, and its Clear cachebutton drops every cache at once.

The relay keeps nothing at any point, including the tokens it exchanges and the feedback it forwards.

10. Sharing

Lux does not sell, rent or trade your data. Requests go only to the services behind the widgets you use: the accounts you connect, Open-Meteo for weather, Yahoo Finance for stocks, the news publishers’ public feeds, ESPN for scores, and the Lux relay for the two jobs described below.

If you send feedback, that message is forwarded to a privateDiscord channel the developer uses for support.

11. The Lux relay

Google, Microsoft and GitHub require a confidential client secret to exchange and refresh access tokens, and a browser extension cannot hold a secret safely. Lux therefore runs a small stateless relay on Cloudflare with two jobs. For sign-in, it takes a single-use sign-in code, or an expiring refresh token, swaps it with the provider for a fresh access token, and returns that to your browser. Its other job, forwarding feedback you choose to send, is described in the next section.

The relay has no database and writes no logs of your personal information. Your tokens live on your device. For sign-in, the relay hears from Lux at those two moments only; the rest of the time each widget talks to its provider directly from your browser.

The relay never sees your calendar, your profile or anything else a widget reads. It handles the token exchange and nothing more, which is why it can hold no data even in principle.

12. Feedback you send

Lux includes a feedback form, and it is entirely user-initiated. Nothing is sent unless you open the form, write a message and press send. Lux has no automatic error reporting, no crash reports, no usage analytics and no background telemetry of any kind.

What a submission contains:

  • The category you pick (bug, idea or other) and the message you write.
  • Diagnostics, unless you untick the box, which is on by default. These are the Lux version, your browser and operating system, which widget types are on your dashboard, and which provider names you have connected. The exact text is shown on screen before you send.

Feedback never includes the contents of your widgets. No note or task text, no links, no calendar content, no tokens and no account identifiers. Diagnostics record that a Calendar widget exists and that Google is connected, never what is in it or whose account it is.

As with any internet request, Cloudflare sees the connecting IP address at the network edge as a property of how the network works. The Lux endpoint does not read that address, does not store it, and does not forward it to Discord.

13. Google user data and Limited Use

Lux’s use of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.

The Google data Lux accesses is your calendar events (calendar.readonly) and your account email address (userinfo.email). Lux uses it only to show your events and name the connected account, both on your device.

None of it is transferred to others, used for advertising, or read by humans, and none of it trains any artificial intelligence or machine-learning model. It is safeguarded by the measures in How your data is protected: encrypted in transit, held only in isolated on-device browser storage, and never routed through a server we operate. The Lux relay exchanges the Google token and stores nothing at any point. No calendar event and no profile detail passes through it; those are fetched directly from Google to your browser.

14. Your rights and choices

Lux holds no copy of your data, so most requests you might make of a company are things you can do yourself, immediately, from inside the extension.

  • Access. Settings → Storage & Backup lists everything Lux is holding.
  • Deletion. Disconnect an account to delete its tokens, clear the caches from the Storage & Backup screen, or uninstall the extension to remove everything at once.
  • Portability. Settings can export your entire configuration to a file you keep, and import it again on another machine.
  • Withdrawing consent. Disconnect any account at any time, in Lux or from the provider’s own security settings. Optional browser permissions can be revoked the same way.
  • Objection and restriction. There is no processing to object to beyond the features you switch on, and switching one off ends it.

Depending on where you live, you may have rights under laws such as the GDPR or the CCPA, including the right to complain to your data protection authority. Lux does not sell personal information and does not share it for cross-context behavioural advertising. If you want to exercise a right or raise a concern, write tohyun@hyunwk.me.

15. This website

This site is a set of static pages describing Lux. It sets no cookies, runs no analytics, embeds no trackers, and has no login. It is served by Cloudflare, which handles the connection and sees the requesting IP address as part of delivering the page.

The only page here that handles any data of yours is the AniList callback described above, which passes a token from the address bar to the extension without sending it to a server.

Lux links out constantly, and by design. A news headline opens the publisher’s site, a repository opens on GitHub, an anime page opens on AniList. Once you follow a link you are on that company’s property and their privacy policy applies, not this one. Lux has no control over what they collect.

17. International transfers

Lux does not transfer your personal data internationally, because it does not collect it centrally. Your data stays on your device. When a widget contacts a provider such as Google, Microsoft or Spotify, that request goes directly from your browser to that company, under their own policy and their own infrastructure.

The relay runs on Cloudflare’s global network and may process a token exchange at a location near you. It holds nothing at any of them.

18. Changes to this policy

If this policy changes, the updated version is posted at this address with a new date at the top. Material changes to what Lux accesses will also appear in the release notes for the version that introduces them.

19. Contact

Questions, requests and complaints all go to the same place:hyun@hyunwk.me. The developer reads and answers them directly.