Privacy policy
Your data, plainly explained.
Last updated: 25 July 2026
1. What the extension does
Higgsfield Automation is a browser extension that automates bulk image and video generation on higgsfield.ai. It lets you enter or import prompts, optionally add reference images, run those prompts through the Higgsfield page open in your browser, and download finished images or videos to your computer.
2. User data collected or handled
| Data category | What is handled | How it is used | Where it is stored | Who receives it |
|---|---|---|---|---|
| Authentication information | Email address, Firebase user ID, Firebase ID token, email verification state, and the basic profile returned for Google sign-in. For email/password sign-up, Firebase stores the password hash; the extension developer does not receive the plaintext password. | To sign you in to the extension, keep the extension session active, verify email status, and recognize the same extension user across sessions. | Google Firebase Authentication servers and browser IndexedDB used by the Firebase Web Extension SDK. | Google Firebase Authentication and Google OAuth services. |
| Personally identifiable information | Email address and, when Google sign-in is used, the display name and profile picture URL returned by Google. | Only for extension sign-in and displaying the signed-in account in the side panel. | Google Firebase Authentication servers and browser IndexedDB. | Google Firebase Authentication and Google OAuth services. |
| User-provided and website content | Prompts typed into the side panel, prompts imported from TXT/CSV/XLS/XLSX files, optional reference images, filenames, generated media URLs, and generated images or videos returned by higgsfield.ai. | To submit the requested generation jobs, monitor progress, match outputs to prompts, produce a local report, and download the resulting files. | Prompt and imported-file content is handled locally by the extension while you use it. Generated downloads are stored in your browser's Downloads folder. Selected reference images are represented locally during the current session. | higgsfield.ai receives prompts and selected reference images when you start a run. Generated media is downloaded from Higgsfield or its media hosts through your browser session. |
| Extension settings and local activity state | Selected mode, output count, pacing and retry settings, concurrency, wait limits, folder and filename preferences, interface language, welcome preference, resume state, and cached selector configuration. | To remember your preferences, support resume behavior, and keep the automation compatible with the Higgsfield page. | Browser extension storage on your device, primarily chrome.storage.local. The selector configuration contains no prompt or account content. |
Settings are not sent to the extension developer. Selector configuration requests go to the developer-operated Cloudflare Pages endpoint and do not attach prompts, files, generated media, email addresses, Firebase IDs, or Higgsfield credentials. |
3. Data not collected
- The extension does not collect general browsing history or track websites outside higgsfield.ai.
- The extension does not use analytics, telemetry, advertising SDKs, or third-party tracking.
- The extension does not store, request, or transmit your higgsfield.ai login credentials.
- The extension does not send your prompts, settings, generated files, or download logs to a developer-operated analytics service.
- The extension does not collect location, health, or personal communications data.
4. How data is collected
- Extension sign-in: you enter an email/password or start Google sign-in. Google Firebase Authentication and Google OAuth handle authentication.
- Prompt entry and import: you type prompts or select a TXT/CSV/XLS/XLSX file. The extension reads the selected file locally to extract prompt text.
- Reference images: you select local image files for workflows that use images. The extension uses them only for the generation run you start.
- Higgsfield automation: when you click Run, the extension applies your prompts and images to the higgsfield.ai page using your existing browser session.
- Settings: when you change extension settings, they are saved in extension storage on your device.
5. User consent
Data handling begins only after you take the corresponding action: signing in, importing a prompt file, selecting reference images, changing settings, or starting a run. Removing the extension stops further data handling by the extension.
6. How data is used
- Authentication information is used only to operate extension sign-in and maintain that session.
- Prompts, imported files, and reference images are used only for the Higgsfield generation workflow you request.
- Generated media URLs are used to identify completed outputs and download them.
- Folder and filename preferences are used only to organize files in your Downloads folder.
- Settings, resume state, and cached selector configuration are used only to operate the extension.
7. Storage and retention
- Firebase Authentication: Firebase retains authentication records while the associated extension account exists, unless deleted earlier.
- Browser IndexedDB: Firebase stores a local sign-in session so you do not need to sign in every time.
- Extension storage: settings, preferences, resume state, and selector cache stay on your device until reset, extension data is cleared, or the extension is removed.
- Queue and action log: active run state is maintained by the extension while needed for the current workflow and can be cleared through the interface or by removing extension data.
- Downloads: generated files remain in your local Downloads folder until you delete them.
8. Sharing and disclosure
The extension shares data only as needed to provide its stated functionality:
- Google Firebase Authentication and Google OAuth: receive authentication information when you sign in, create an extension account, sign out, verify email, or refresh the session.
- higgsfield.ai: receives the prompts and reference images you choose to run and returns the generated media.
- Developer-operated hosting: Vercel serves the official public pages at deepakthapa.dev. Cloudflare Pages serves the extension's selector configuration. These requests do not attach your prompts, images, generated media, email address, Firebase user ID, Higgsfield credentials, or browsing history. As with normal HTTPS hosting, Vercel or Cloudflare may process standard request metadata such as IP address, user agent, timestamp, and requested URL for security and delivery.
The extension does not provide user data to advertising networks, data brokers, analytics providers, or unrelated third parties.
9. Network requests
- Requests to higgsfield.ai and its media hosts, driven by your existing Higgsfield browser session and the settings selected on that page.
- Requests to Google Firebase Authentication and Google OAuth hosts only for sign-in and session management.
- Requests to www.deepakthapa.dev when you open public product or support pages.
- Requests to higgsfield-automation.pages.dev for selector configuration. Selector requests do not include prompts or account content.
10. Security
- Network requests made by the extension use HTTPS.
- The extension does not put prompts, authentication tokens, or user identifiers in query strings sent to developer-operated endpoints.
- The extension does not execute remote code. Remote selector configuration is JSON data, not executable JavaScript.
11. User control and deletion
- You can sign out from the side panel.
- You can reset extension settings from the Settings tab.
- You can remove local extension data by clearing extension storage or removing the extension.
- You can delete generated files from your Downloads folder at any time.
- For deletion of Firebase Authentication records associated with your extension sign-in, contact the developer below.
12. Children
The extension is intended for users 18 and older and does not knowingly collect data from children.
13. Changes to this policy
Changes will be posted at this URL with an updated date.
14. Contact
Questions or deletion requests can be submitted through the Contact page or sent to thapadeepak726@gmail.com.