Yamlet
Privacy

Privacy policy

Yamlet runs on your machine. There is no account, no cloud service and no telemetry. Your API collections never leave your disk unless you send them somewhere yourself.

Last updated 7 October 2026

The short version

  • Yamlet has no account or telemetry and does not send data to a developer-operated service.
  • Your collections, environments and globals are plain YAML files in the folder you mount.
  • The app sends the API and OAuth requests you configure. If you pair the optional Chrome extension, it also receives encrypted cookie snapshots over the loopback connection.
  • This website uses Cloudflare Web Analytics, which does not use cookies or track you across sites.

The Yamlet app

Yamlet is a web app you run yourself from a Docker container. The container serves the interface to your browser at http://localhost:7878 and reads and writes files in the workspace folder you mount at /workspace. The recommended command binds the port to 127.0.0.1, so the app is reachable only from your own machine.

The app contains no analytics, crash reporting, update checks or usage tracking, and it does not require or offer an account.

Where your data lives

  • Collections, requests, folders, environments and globals are saved as YAML in your workspace folder. You decide whether to commit them to Git and where to push them.
  • Interface preferences such as open tabs, the selected environment and layout choices are stored locally, either in your browser or alongside the container on your machine.
  • Secrets such as tokens, passwords and API keys are stored wherever you put them. If they sit in an environment file that you commit, they will be in your repository, so keep sensitive values in a local, uncommitted environment.

Network requests the app makes

Yamlet only contacts the servers you point it at:

  • The API requests you send, from the editor, the collection runner or the CLI.
  • OAuth 2.0 token and authorization endpoints that you configure for a collection or request.
  • Anything your own pre-request or post-response scripts call.

Requests go directly from the container (or the CLI process) to those servers. Nothing is proxied through a Yamlet service, because there is no Yamlet service.

Yamlet Interceptor Chrome extension

The optional extension reads cookies only for sites you approve in its popup. This includes authentication cookies and cookies marked HttpOnly. It sends a snapshot to the Yamlet app running on this same computer so Yamlet can attach matching cookies to API requests. After approval, the extension refreshes those sites when cookies change and periodically while Chrome is running. It does not read page text, record browsing history, use analytics, or send data to a developer-operated server.

On localhost and 127.0.0.1 pages only, a small script passes pairing messages between the Yamlet page and the extension, so you do not have to copy a pairing code. It does not read the page's content. The extension pairs with a new Yamlet address only after you confirm it in the extension's own window. If Yamlet loses its saved pairing, the extension uses the same script to pair again with the address you already confirmed.

The extension stores the approved site list, local Yamlet address, and pairing credential in Chrome's local extension storage. It does not save copies of cookie values there. Cookie snapshots are encrypted with AES-GCM before transfer over the local loopback connection. The Yamlet container holds imported cookies in memory, and stores pairing credentials in its private data directory so a paired browser can reconnect after a restart. Cookie values are never written to workspace YAML.

You can remove the extension's browser settings by uninstalling it or choosing Forget connection in its popup. Forget connection also clears this browser's cookies from Yamlet and ends the pairing there when Yamlet is running. In Yamlet's Cookies dialog, you can delete cookies or choose Disconnect extensions to revoke pairings and clear browser-imported cookies. Chrome's site settings can revoke individual site permissions. Partitioned and incognito cookies are excluded from this version.

The use of information received through Chrome extension permissions adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Cookie data is used only for the extension's stated cookie sync feature. It is not sold, used for advertising, or made available to the developer or other people.

The command-line tool

The yamlet CLI from npm runs your workspace headlessly, for example in CI. It reads the same YAML files, sends the requests in them and prints results to your terminal or a report file. Like the app, it has no telemetry. Installing it goes through the npm registry, which is subject to npm's own policies.

This website

This site is static and hosted on GitHub Pages. It uses Cloudflare Web Analytics to count page views. It does not set cookies, does not use local storage for tracking and does not fingerprint visitors; it records aggregate figures such as page path, referrer, country and browser type. Fonts are loaded from Google Fonts.

GitHub, Cloudflare and Google may process standard request data such as your IP address when they deliver this site to you, under their own privacy policies. Pulling the container image from ghcr.io is handled by GitHub in the same way.

Contact

Questions about this policy, or found something that does not match it? Open an issue on GitHub or email piyushdoorwar+yamlet@gmail.com.

If this policy changes, the new version will be published on this page with an updated date.