Hissab

Privacy Policy

Last updated 22 September 2026

The short version

Who we are and what this covers

Hissab is made by Rawbytes Technologies ("we", "us"). This policy covers the Hissab web app and documentation at hissab.io, the Hissab Chrome extension, the hissab command-line tool, the @rawbytes/hissab npm package, and the Hissab agent skill. Hissab is open source; you can check everything described here in the source code.

Chrome extension

What it stores

The extension keeps the calculations you type in its own local storage on your device, so they are still there the next time you open it. They are never sent to us or anyone else. The first time a new version runs, it can copy calculations saved by an older version of the extension; that copy also happens entirely on your device.

What it can access

Nothing beyond its own popup. The extension requests no permissions: it cannot read or change the pages you visit, see your browsing history, or run in the background.

Network requests

The extension's code is all bundled with it; it loads no remote code. The only request it makes on its own is to download its typeface (Chillax) from fonts.cdnfonts.com. Like any web request, this shows the font host your IP address and browser version. It contains nothing you typed. The Hissab, Docs and GitHub links in the popup open a tab only when you click them.

Removing your data

Uninstalling the extension deletes everything it stored.

Web app (hissab.io)

What stays in your browser

Notebooks, settings, files you add, MCP server settings, skills, AI provider settings and API keys are stored in your browser (local storage and IndexedDB). We never receive them. To delete them, open Settings → Privacy & data → Clear all local data, or clear this site's data in your browser.

AI features (optional)

If you set up an AI provider, the app sends your prompt and the notebook content needed to answer it directly from your browser to that provider (for example OpenAI, Anthropic, Google or DeepSeek, or a custom endpoint you enter), using your API key. These requests don't pass through us, and we can't see them. The provider's own privacy policy applies to what you send it. If you connect an MCP server, the app talks to that server directly from your browser too.

Documentation search

When you search the documentation, what you type in the search box is sent to Algolia (DocSearch) to find matching pages.

Analytics

We count visits to hissab.io with Umami, which we host ourselves at analytics.rawbytes.com, and with Cloudflare Web Analytics. Neither uses cookies or tracks you across other sites. They record the page address, the referring site, and your browser, operating system, device type, screen size, language and approximate country. Umami works out your country from your IP address without storing the address itself. Your calculations and notebook contents are never sent to analytics.

Hosting and fonts

hissab.io is served by Cloudflare, which processes standard request data such as your IP address, browser and the page requested, to deliver the site and protect it from abuse. The app loads fonts from Google Fonts and fonts.cdnfonts.com, which receive the same kind of request data.

Command-line tool, npm package and agent skill

These run entirely on your computer. They include no telemetry and make no network requests; your expressions and results never leave your machine. Downloading them from npm, GitHub or a skills directory is governed by that service's own privacy policy.

What we don't do

Contacting us

If you email us, we use your address and message only to reply, and we keep them only as long as that conversation needs. You can ask us to delete them at any time. Questions about this policy go to support@hissab.io, or open an issue on GitHub.

Children

Hissab isn't directed at children under 13, and we don't knowingly collect personal information from them.

Changes to this policy

If how Hissab handles data changes, we'll update this page and the date at the top.