Clear and factual

Privacy policy

How Mist stores preferences and how optional weather and feedback use external services.

Last updated: August 20, 2026

Mist — Minimal New Tab does not sell personal data. The extension does not send product analytics or telemetry: preferences stay in your browser. The public Mist website uses the limited, cookie-free analytics described below. Weather and favicon requests are sent directly from your browser to the services described below. Feedback uses a developer-operated Netlify function only after you choose to submit.

Local storage

Preferences including theme, shortcuts, groups and name are stored in Chrome extension storage in your browser. New custom-theme images are resized and re-encoded locally before storage with their four selected colors. Mist does not automatically upload them. A custom-theme image leaves your device only when you export the configuration or explicitly confirm creation of a private appearance link. Custom shortcut icons are not included in appearance links.

Review-prompt dates, theme-change counts and choices are also stored locally only to avoid asking for a review too early or too often. They are not sent to an analytics service.

Appearance sharing — optional

Selecting Share appearance in Mist opens this website with a preview in the URL fragment. That preview contains either an official theme identifier or a locally re-encoded custom background with its four selected colors, plus whether the clock, search and shortcut sections are visible. URL fragments are not included in requests to the website server, and nothing is stored until you review the preview and select Create private link.

Private appearance links never contain shortcut names or URLs, groups, weather settings or locations, names, tab identity, or custom shortcut icons. Before a custom background is stored, you must confirm that you have the right to share it and understand that anyone with the link can view and download it. Netlify stores the allowlisted appearance payload—including the re-encoded image and four-color palette for a custom theme—creation and expiration dates, and a hash of a deletion secret. Analytics are disabled on the creation and private preview pages. Links are marked noindex and expire after 30 days. An hourly, bounded cleanup follows an expiry-date index, retries transient failures, and reports an unhealthy run instead of silently advancing past undeleted records. A link can be deleted earlier from the browser used to create it while its local deletion secret remains available.

To limit abuse, the server derives a salted, day-specific hash from the connection IP address and permits at most five successful reservations per three-minute window and 20 creations per day. Invalid requests are rejected before reserving quota, and failed creations release their reservations. The server does not store the IP address itself. Expired quota markers use the same indexed cleanup.

Community Hall of Fame — optional

If you choose Publish wallpaper, the custom background, its Mist color palette, the title, optional description, optional nickname, publication date, detected dimensions and file size become public in the wallpaper gallery. An omitted nickname is displayed as “Anonymous”. Publications are permanent until moderated or deleted following a valid request. Visitors can vote or report a publication; those actions do not expose their identity publicly.

Mist derives salted hashes from connection IP addresses to enforce three publications per day, eight per week, one vote and one report per wallpaper. It stores the hashes rather than the IP addresses. A perceptual image fingerprint rejects re-encoded duplicates. Do not publish an image unless you have the right to make it publicly available.

Market widgets — optional

After you add a market widget, the extension sends the selected market symbol and normal connection information to this website’s quote endpoint. The endpoint uses a server-side credential to request the quote from Twelve Data. Twelve Data receives the symbol and the server’s connection information, not your shortcuts, name, weather location or other Mist preferences.

Successful quote responses may be cached at the website edge for one hour. The extension treats a local quote as current for 12 hours and may display it for up to 72 hours as an offline fallback. Market symbols, labels and cached quotes remain in extension storage and are excluded from appearance-sharing links.

To limit abuse, the endpoint derives a salted, minute-specific hash from the connection IP address and accepts at most 10 uncached quote requests per minute. Only short-lived quota markers are stored; the IP address itself is not stored. An hourly, bounded cleanup removes expired markers and reports incomplete runs for retry.

Weather — optional

You can enter a city or postal code, or allow Mist to estimate an approximate city from your IP address. Mist does not request precise browser geolocation. Depending on your choice, weather may contact:

These providers receive normal connection information, including your IP address. Mist does not store your IP address. Cached location and weather data are removed when weather is disabled.

Shortcut icons

Google favicons are enabled by default for shortcuts without a custom icon. Mist sends only the shortcut domain to Google’s favicon service; Google also receives normal connection information, including your IP address. Mist does not send the shortcut label, path, query string or other preferences. You can disable Google favicons in Settings > Shortcuts, after which Mist uses its bundled local icon. See Google’s privacy policy.

A custom shortcut icon is resized, stored and displayed locally and always takes priority over the Google favicon.

Website analytics

The public website uses Umami to count aggregate page views, visits, referrers, device categories, countries and selected actions such as opening the Chrome Web Store listing. Mist configures this analytics without advertising cookies, cross-site tracking, fingerprinting or a persistent account identifier.

Analytics are used only to understand whether the website is useful and which public pages help visitors. Search text, extension shortcuts, extension preferences, weather locations and feedback content are not included. The private administration dashboard displays aggregate reports and is restricted to allowlisted administrator accounts.

Feedback — optional

Opening the feedback form sends nothing. After you select Send feedback, Mist sends the chosen feedback type, summary, description, optional contact, extension version and browser user-agent to a developer-operated Netlify function. The function creates a private issue in the developer’s GitHub repository.

Mist does not attach your shortcuts, name, theme, search data or weather data to feedback. Netlify and GitHub receive the connection information needed to process the request.

Use and sharing

Data is used only to provide optional appearance sharing, weather, market widgets, favicon and user-initiated feedback functions and the aggregate website measurement described above. Mist does not use data for advertising, behavioral profiling or sale. The extension itself does not transmit usage telemetry.

Your choices and deletion

Disable weather to remove its cached data. Remove market widgets from Settings > Widgets. Edit or remove shortcuts from Mist at any time. Uninstalling Mist or clearing its extension data removes locally stored preferences and cached quotes.

Private appearance links expire after 30 days. The creating browser can delete one earlier while its local deletion secret remains available.

To request deletion of submitted feedback or optional contact information, contactaurelien.luxeyy@gmail.com with enough information to identify the message.

Security and contact

All transmissions described in this policy use HTTPS.

For privacy questions or support, visit Mist support or emailaurelien.luxeyy@gmail.com.