Privacy Policy

Last updated: 25 August 2026 · Applies to the Hemly browser extension and to this website.

Short version: Hemly collects nothing. There is no account, no analytics, no tracking and no server that stores anything about you. Everything the extension calculates happens inside your browser and stays there.

1. Who is responsible

Hemly is an independent tool for Vinted sellers, built and maintained by a single developer. It is not affiliated with, endorsed by or connected to Vinted. Questions about this policy go through the Support tab on the Hemly Chrome Web Store listing.

2. What Hemly collects

Nothing. Hemly has no backend, no database, no user accounts and no login. We do not collect, receive, transmit, sell or share any personal information — not your name, email address, Vinted username, listings, prices, sales, browsing history, IP address or device identifiers.

3. What the extension reads, and where it goes

When you visit one of your own Vinted pages, Hemly reads what the page has already rendered in your browser — the asking price, the item title, view and favourite counts, how long a listing has been up — and combines it with the costs you type in yourself (what you paid for an item, packaging, postage you cover). It uses that to show your profit, price statistics and a wardrobe overview.

All of it is written to your browser's local extension storage (chrome.storage.local), on your device, under a single key. None of it is uploaded, mirrored, backed up or synced to us or to anyone else. We cannot read it, and there is nowhere for us to read it from.

4. Network requests

As shipped today, the extension makes no network requests at all. Every release is checked for this: the built code must contain zero uses of fetch, XMLHttpRequest, sendBeacon and WebSocket before it can be published.

One exception is planned and is not live yet. When paid plans launch, the extension will contact Hemly's own licence server (a Cloudflare Worker we operate) to check whether your licence key is active. That check is limited to your licence status. Payments are handled entirely by Paddle (paddle.com), our merchant of record: card details are entered on Paddle's pages, never in Hemly, and we never see or store them. This policy will be updated with the effective date before that request ships, and the extension's requested permissions will change at the same time — which Chrome shows you before the update installs.

This website has exactly one page that makes a request of its own: /activate/, where a buyer collects their licence key after paying. It sends one thing to Hemly's licence server — the transaction reference from the Paddle checkout, either the one Paddle puts in the address or the one you paste from your receipt — and gets that purchase's licence key back. No cookie, no identifier, no account, nothing about you. Every other page on this site sends nothing at all.

Two further features described in our roadmap (remote updates to the page-selector configuration, and an optional listing translator) are not implemented. If either ships, this page will say exactly what is sent and when, before it is released.

5. No analytics, no tracking, no ads

The extension contains no analytics SDK, no telemetry, no crash reporter, no advertising and no third-party scripts of any kind. This website contains no analytics, no cookies, no tracking pixels, no embedded fonts and no external scripts either — the profit calculator on it runs locally in your browser, and the figures you type into it are never transmitted anywhere. The only outbound request this site can make is the licence lookup on /activate/ described in section 4, to our own server; it is not tracking, and it carries nothing about you.

This site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes the requests needed to deliver the page and keeps standard, short-lived infrastructure logs (such as IP address and user agent) for security and abuse prevention. We do not receive per-visitor data from it, and there is no visitor-level reporting on our side.

6. Permissions the extension asks for

  • Storage — to keep your costs, settings and wardrobe snapshot on your own device.
  • Access to Vinted domains — the extension only runs on Vinted's own websites (vinted.fr, vinted.de, vinted.pl and the other Vinted country domains), so it can draw its panel on the page you are looking at. It cannot run on any other site.

That is the complete list. Hemly is read-only by design: it never posts, bumps, edits, follows, or sends messages on your behalf.

7. Your data, your control

Because everything lives on your device, you are in full control. You can clear everything from the extension's settings, or remove the extension — uninstalling it deletes its local storage with it. There is no copy anywhere else, so there is nothing for you to request from us and nothing for us to delete on your behalf. If you would still like written confirmation of that for your own records, email us.

8. Children

Hemly is intended for people who sell on Vinted and is not directed at children. It collects no data from anyone, including children.

9. Changes to this policy

If this policy changes, the date at the top changes with it, and material changes — especially anything that would send data off your device — will be described here before the corresponding release is published.

10. Contact

Use the Support tab on the Hemly Chrome Web Store listing. We aim to reply within 48 hours.