ZTint Privacy policy
Who this is from
ZTint is published by Warewolf Technologies, which is the data controller for the purposes of this policy — though as set out below, there is no data to control: nothing is collected and nothing leaves your device.
Summary
ZTint does not collect, transmit, or sell any data. It has no servers and makes no network requests of any kind. Everything it stores stays in your browser, on your device.
What ZTint stores
ZTint keeps the following in the browser’s extension storage, storage.local,
which is local to the browser profile on the device you are using. It does not
use storage.sync, so none of it is copied between your devices or into a
browser account.
| Stored | What it is |
|---|---|
enabled | Whether tinting is switched on |
tint | Tint strength, 0–60% |
tintHover | Hover tint strength, 0–80% |
multiTagOff | Whether messages with several tags are left untinted |
shortcuts | Whether ZTint’s keys (T, U, Y and 1–9) are switched on |
sites | The Zimbra sites you added yourself, as origins (e.g. https://mail.example.com) |
detected | Zimbra sites ZTint recognised, if auto-detect is on, in the same form |
autoDetect | Whether auto-detect is switched on |
That is the complete list. No message content, no email addresses, no tag names, no browsing history, and no identifiers of any kind are stored.
What ZTint can see
On a site you have granted access to, ZTint reads the page’s structure in order to work out what colour each row should be. Specifically it reads:
- the background colour of a tag pill (modern client), or the pixels of the tag icon image (classic client, where the colour exists nowhere else);
- tag names and their icon colours from the sidebar tag list;
- each message row’s
aria-label, to take the name of the first tag on the row; - in the classic client, when you press Y or a number, the tag names listed in Zimbra’s own Tag menu, to see which tags the selected messages have.
Zimbra writes the sender and subject into that same aria-label. ZTint reads
the string, takes the tag name from the front of it, and discards the remainder.
Nothing from it is kept in storage or sent anywhere.
While ZTint’s keys are switched on, it also listens for key presses and pointer movement on the Zimbra page:
- In the modern client it acts on T, U, Y and the number keys 1 to 9, and only while the pointer is over a message row and you are not typing in a field.
- In the classic client it acts on Y and the number keys 1 to 9, and only while messages are selected in Mail and you are not typing in a field.
- While one of Zimbra’s tag dialogs is open, in either client, it acts on the number keys 1 to 9 in that dialog instead, and in the modern client on Enter pressed on one of the dialog’s tickboxes. Every other key is left alone.
- It keeps the pointer’s last position on the page, so it knows which row you are pointing at, and forgets it when the pointer leaves the page.
- For a key pressed while it is still acting on an earlier one, it notes which message the key is for — in the classic client, which selected messages — until it has acted on it. That note is the messages’ identifiers in the page, held in the page’s memory only.
- It notes whether the previous key began one of Zimbra’s own two-key shortcuts, such as M then U, so as not to take a key that belongs to Zimbra. That note is a single key, kept for about a second.
- For Y, it notes which message it last changed — in the classic client, which selected messages — and which tag it moved them to, so that pressing Y again moves the same tag on. That note is the messages’ identifiers in the page and one tag name, held in the page’s memory only until the next Y or until the page is reloaded.
None of this is recorded, stored or sent anywhere. What you type is never collected.
ZTint does not read message bodies, attachments, contacts, calendars, passwords, cookies, or authentication tokens, and it never sends a message. The only change it can make to your mail is to a message’s tags, and only when you press one of its keys: T opens Zimbra’s own Tag dialog for you to use, U removes the message’s tags through that same dialog, Y moves the message on to the next tag through it, and a number key adds that tag or takes it off again — in the classic client, Y and the numbers go through the Tag menu on the mail toolbar. In a tag dialog you have open, the number keys tick or choose tags and Enter saves them, just as clicking would. All of it works Zimbra’s controls exactly as the mouse would, so Zimbra’s own permissions and checks apply, and ZTint makes no request of its own to your mail server.
When you open the popup, ZTint reads the address of the tab you are on so it can offer to add that site and tell you whether a Zimbra client is present. That address is used to render the popup and is only saved if you choose to add the site.
Permissions, and why each is needed
| Permission | Why ZTint asks for it |
|---|---|
storage | To remember the settings and site list above |
scripting | To run the tinting stylesheet and script on the Zimbra sites you have granted |
activeTab | To read the current tab’s address when you open the popup, so it can offer to add that site |
| Access to a site you choose | To tint the message list on that site, and to provide ZTint’s keys there |
| Access to all sites (optional) | Only if you switch on Find Zimbra on any site |
The all-sites permission is optional. It is never requested at install, and ZTint works without it. It exists because Zimbra is self-hosted — it may be at any address — so recognising a client automatically requires the ability to look. Where it is granted, ZTint checks each page for a Zimbra client and does nothing whatsoever on pages where it does not find one. You can withdraw it at any time by switching the option off, or through your browser’s own extension settings.
What ZTint never does
- It makes no network requests. The extension contains no
fetch, noXMLHttpRequest, no WebSocket, and no remote scripts. - It has no analytics, telemetry, crash reporting, or usage measurement.
- It has no account, login, or user identifier.
- It shows no advertising.
- It does not sell, share, or transfer data to anyone, because it never collects any in the first place.
Removing your data
Uninstalling ZTint deletes everything it has stored. You can also clear items
individually: remove a site with the × beside it in the popup, which also
hands back that site’s permission, and use Reset to defaults to restore the
appearance settings. ZTint’s keys are switched off under Keyboard in the
popup.
Children
ZTint is a display and keyboard utility for an email client. It is not directed at children and collects no data from anyone.
Changes to this policy
Any change will be published with a new “last updated” date. Because ZTint collects nothing, a change would only ever narrow what it can see, not widen it. If that ever ceased to be true, it would be stated here plainly and before the version making the change was released.
(version 1.2.0). Keys were added: T and U in the modern client; Y and the number keys, for the message you point at in the modern client and for the selected messages in the classic client; and the number keys and Enter in either client’s tag dialog. They widen what ZTint looks at on a Zimbra page to include key presses and the pointer’s position, and let it change a message’s tags when you press one of those keys, as described under “What ZTint can see” above. ZTint still collects, stores and sends none of it.
Contact
Questions about this policy, or about anything ZTint does with data, email [email protected].