Privacy Policy — Chrome extensions

Effective date: 2026-08-19  ·  Last updated: 2026-08-22

This policy covers the browser extensions published by sskplay (“we”, “our”) on the Chrome Web Store. It replaces our general app policy for these items, which describes Android apps and does not reflect how an extension works.

Extensions covered:

Kaching — Play Order Alerts

Kaching is a personal notification tool. It has no server, no account, and no operator other than you. It runs entirely inside your browser, using the Google Play Console session you are already signed in to, and sends messages through a Telegram bot that you create and control.

What it accesses

DataWhyWhere it goes
Your Google Play Console session cookie (SAPISID) To sign the request to Google’s own orders endpoint, exactly as the Play Console page does when you open it yourself Never leaves your browser. The cookie value is not transmitted; only a one-way SHA-1 hash of it is sent to Google, which is the authentication scheme Google’s own Console uses
Order records from your Play Console — order ID, product name, package name, buyer country, amount, payout, timestamp, and whether the order was charged or refunded To build the notification text Only to the Telegram bot you configured
Your Telegram bot token and chat ID To deliver the notification Stored locally in your browser; sent only to api.telegram.org
Messages sent to your bot To answer the /today, /week and /month commands Read from api.telegram.org on a recurring check. Only messages from the chat you configured are acted on; anything else is discarded beyond the chat’s name and ID, which are kept locally so the Find chat ID button still works

What it does not do

Permissions and why each is requested

PermissionReason
alarms Schedules the periodic check.
storage Stores your settings, the list of order IDs already announced so the same order is not sent twice, the per-day tallies behind the running totals, and the exchange rates read off your own settled orders.
cookies Reads the SAPISID cookie for play.google.com to sign the request to Google’s orders endpoint. The value itself is never transmitted — only a one-way hash, as described above.
declarativeNetRequest Sets the Origin header on the extension’s own request to that endpoint. Google validates the request signature against this header, so it has to match play.google.com.
Host: play.google.com Reads the session cookie used to sign the request.
Host: playconsolemonetization-pa.clients6.google.com The Play Console orders endpoint the extension reads from.
Host: api.telegram.org Delivers the notification to the bot you configured.

Where data is stored

In chrome.storage.local on your own machine. Uninstalling the extension removes it. Reset history in the extension’s settings clears all of it.

Individual order records are not retained. What is kept is a rolling list of recently seen order IDs, so the same order is not announced twice; a tally per day of amounts, order counts and refund counts, holding roughly a year of days, which is what the running totals and the /today, /week and /month commands are answered from; the exchange rates read off your own settled orders, so a figure can be shown in the currency you are paid in; and the name and ID of chats that have messaged your bot. None of it leaves your machine.

Third parties

Messages are delivered through Telegram using a bot you create. Once delivered, those messages are governed by Telegram’s privacy policy. You can revoke the bot at any time with /revoke in @BotFather, which immediately stops delivery.

Order data is read from Google Play Console under your own signed-in session, governed by Google’s privacy policy.

Children’s privacy

These extensions are developer tools intended for adults operating a Google Play developer account. They are not directed at children and we do not knowingly collect information from children.

Changes to this policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top of this page.

Contact