EXT-09 · Dossier
Privacy — DitherLab
Last updated: August 9, 2026
DitherLab is a local-first image-processing extension. It does not operate its own backend service, collect analytics, track browsing activity, sell data, or use data for advertising. An optional DitherLab Premium license is sold and validated by Dodo Payments.
Data processed
Images, animated GIFs, videos, and palettes that a user deliberately opens, drops, pastes, or imports are processed locally on the user's device to create previews and exports. These files are not transmitted to the developer or any third party.
DitherLab saves the current media queue and recipe in extension-scoped IndexedDB so the last local session can be restored after the studio closes. It may also save interface preferences, custom palettes, style-board selections, portable recipe settings, and—if Premium is activated—the license key, Dodo activation-instance identifier, generated installation identifier, and last validation time in extension-scoped browser storage. This information is used only to restore studio state and verify the Premium entitlement.
Purchase and license validation
Purchasing Premium opens a Dodo Payments checkout page. Payment and receipt information entered there is handled by Dodo Payments under its own terms and privacy policy; DitherLab does not receive or store card or bank details.
When a user activates, checks, exports with, or deactivates a Premium license, the extension sends the license key and activation-instance information to Dodo Payments over HTTPS. A random installation identifier is included in the device name so the user can distinguish activations. No imported image, palette, recipe, browsing history, or website content is included in these requests.
Optional local automation
Local automation is off by default. If a user chooses Local tools and enables it, Chrome asks for the optional localhost and 127.0.0.1 host permissions. DitherLab then communicates with a separately installed DitherLab MCP process on this device through port 3472. The local MCP client can inspect the open studio, operate requested controls, import files the user or client explicitly names, and receive generated exports. This traffic stays on the loopback interface and is not sent to the developer or a cloud service. The permission can be revoked from the same dialog at any time.
Data not collected or shared
DitherLab does not collect or share imported media, financial information, browsing history, website content, location, communications, or usage telemetry. The only authentication-related data sent outside the device is the Premium license and activation information described above. Persistent network access is limited to live.dodopayments.com for license operations; the separate loopback origins are optional, user-initiated, and device-local. DitherLab does not request access to arbitrary websites or browser-tab contents.
User controls and retention
The most recent queue is retained locally for session restore until the user clears the queue, chooses Clear local data, or removes the extension. Clear local data removes the saved session, recipes, palettes, preferences, and optional localhost permission; it does not delete files the user previously exported elsewhere. Premium users can deactivate the current device from the license window, which removes the stored license after notifying Dodo Payments. Removing the extension removes its extension-scoped local data according to Chrome's storage behavior, but users should deactivate first if they want to free a Dodo device activation.
Policy changes
This notice will be updated before DitherLab adds analytics, accounts, cloud image processing, or any other data collection or external transmission beyond license verification and user-enabled device-local automation. Any such change will also be prominently disclosed to users before data is collected.
Contact
Questions and privacy requests can be filed at <https://github.com/magare/extaroid/issues>.