YoslionDownload

Yoslion Download

Privacy Policy

What this website, the Yoslion Download desktop application and the browser extension do with information, described only as far as it is settled today.

Last updated 23 September 2026. This is the date the text was written, not a date on which it takes effect.

What this policy covers

This policy covers the website at download.yoslion.com, the Yoslion Download desktop application, and the Yoslion Download browser extension, all operated by Palacios Software Group LLC. Yoslion Download is not offered for sale yet, so the sections below describe the software as it is built rather than a live commercial service.

This website

This website does not use website analytics, advertising trackers or third-party tracking cookies, and it sets no cookies of its own.

The only third-party script it can load is Paddle.js, and only on the checkout page, where it is what opens a payment. No other page of this site loads a third-party script. What Paddle stores in your browser inside its own checkout is covered by Paddle’s terms rather than by this policy, which does not make promises on Paddle’s behalf.

Buying a license creates an activation code in your browser. It stays in that page while you are buying and is not stored on your device by this site; the copy you keep is the one you download or copy yourself. The code is never sent to Palacios Software Group and never reaches our servers. Paddle is given only a one-way digest of it, which identifies your purchase and cannot be turned back into the code. That is why nobody here can recover it for you, and why the checkout asks you to save it before you pay.

Serving a page over the internet still involves a request. The provider that hosts this site may process ordinary request information, such as an IP address and a browser user agent string, in order to deliver the page and to keep the service running. That is a property of how the web works rather than a choice this site makes about you.

Recovering a lost purchase

The activation code for a purchase is created in your browser and nobody here ever receives it, so it cannot be looked up or resent. Purchase recovery is the way back, and it is the first thing on this site that processes an email address. This section says exactly what happens to it.

What is sent, and to whom. When you use Recover your purchase and enter an email address, that address is sent to Paddle, our Merchant of Record, because Paddle holds the customer record and is the only authority on whom an address belongs to. If a recoverable purchase is found, the address is also sent to Resend, the email provider that delivers the message, so that a six-digit code can reach that mailbox. Both process it under their own terms.

What is not stored. The licensing database holds no plaintext email address for recovery — not in a column, not as a digest, not in an index and not in a log line. What it stores is the identifier the payment provider uses for the customer, the digest of the code that was sent, and when each of those expires. The recovery’s own diagnostic logs record a fixed category per request and never an address, a customer, a purchase or a code.

What your browser keeps. While a recovery is in progress, this site keeps the ceremony’s state in your browser’s session storage, which belongs to that one tab and is discarded when the tab closes. It holds the values needed to continue after a reload; it deliberately does not hold your email address or the six-digit code. Nothing is written to local storage, to IndexedDB or to a cookie.

The new code never reaches us either. The replacement is generated in your browser exactly as a purchase code is. Only a one-way digest of it is sent, which is what the licensing service binds your purchase to and which cannot be turned back into the code. That is why you are asked to save it before the recovery finishes.

None of this is advertising or marketing. Your address is used to find your purchase and to deliver one code, and for nothing else; recovery adds no analytics, no tracking pixel and no telemetry, and the email it sends carries no open or click tracking.

Diagnostic logs in the application

Yoslion Download writes a diagnostic log to your own machine, under the application data directory for your user account. That log is local. It is not uploaded, and the application does not use a crash reporting service.

The log is deliberately narrow. Addresses are reduced to their scheme and host, storage faults are recorded as a category rather than verbatim, and file system paths are not written to it at all. It is size-bounded, so it cannot grow without limit on your disk.

The browser extension

Yoslion Download offers an extension for Chrome and for Firefox on the desktop. The extension downloads nothing itself, and it does not communicate with us.

There are two ways a download reaches the application. You can right-click a link and choose Download with Yoslion. Or you can start a download in the browser as usual, and the extension hands it over instead of letting the browser fetch it.

That second one starts switched on. When you install the extension in Chrome or Firefox, capturing browser downloads begins enabled, so downloads you start go to Yoslion Download. One click in the extension’s toolbar popup turns it off. Your choice is kept on your computer: updating the extension does not change it, and nothing turns it back on for you.

What is passed, and where it goes. The web address of the download — the link you chose, or the address of the download you started. Where the browser can tell the extension more about the response, that travels too: the address the download finally came from if it was redirected, the kind of file the site says it is, its size, and a validator the site uses to identify that exact version of the file. Those last few are not always available, and the handover carries only the ones that are. They are there so the application can name the file correctly and resume it if the transfer is interrupted.

All of it travels over your browser’s native messaging channel to the Yoslion Download application on the same computer, which is a connection between two programs on your own machine. It does not reach a Yoslion or Palacios Software Group server, and the extension makes no network request of its own. The application then downloads the file from that address, exactly as the browser itself would have.

When a download needs you to be signed in. Some files are served only while you are signed in to the site. The extension can ask the site the way your browser would, so many of those downloads work instead of failing. This is off until you turn it on, and two separate things have to happen before it does anything: you switch on Use my browser session for downloads that need a login in the extension’s popup, and your browser asks you to grant the extension permission for that site. Installing the extension is neither of them, and either one alone does nothing.

What is read, and how narrowly. For the one address you are downloading, the cookies your browser would itself have sent to it. Four fields of each are kept: its name, its value, the path it applies to, and whether it is restricted to HTTPS. A cookie partitioned to another site is not used at all. A cookie is only ever used for a path it already applies to, so one limited to a subfolder is not sent to a different folder of the same site.

Where it goes, and how long it lasts. To the Yoslion Download application on the same computer, over your browser’s native messaging channel, together with the address. The application then presents that cookie to the website you are downloading from, because that is the only way the site will serve the file to you rather than refuse it — the same cookie your browser would have sent to the same site for the same request. It does not reach a Yoslion or Palacios Software Group server, and the extension makes no network request of its own.

The application holds it in memory for the life of that one transfer and discards it when the transfer ends; it is not written to disk, not written to the application’s database, and not written to its diagnostic log. It is used to complete the download you started and for nothing else — not to identify you, not shared, not sold, and not for advertising.

What this does not cover. Signing in is not one mechanism, and this handles one of them. A site that serves its file only after a form is submitted, or that builds the file inside the page rather than serving it from an address, or that identifies you by something other than a cookie, is not covered by this. The application reports that it could not complete such a download rather than saving whatever the site returned instead.

If you keep separate sessions. In Firefox, a download you start inside a container is handed over with that container’s cookies and not with your default ones. A cookie the browser has restricted to another site’s context is not used at all, rather than being sent as though it were an ordinary one.

Why the browser asks about browsing data. Chrome and Firefox both require an extension to declare the categories of data it handles, and a web address falls under those categories. The declaration describes what the extension handles on your machine. It is not a statement that we receive any of it, because we do not.

What is stored, and where. In the browser’s own extension storage, on your computer: whether capturing is on; the result of the most recent handover, as a short status code with no address or file name in it; and downloads currently being handed over, which do include their address until the handover finishes. That last list holds at most 64 entries and is discarded after 24 hours. None of it is sent anywhere.

The extension records no clicks or keystrokes, contains no analytics and no advertising, and asks for no access to the content of the pages you visit. Nothing it handles is sold, used for advertising, or used to assess creditworthiness.

Capturing browser downloads automatically is currently offered by the Chrome and Firefox extensions. It is not currently offered by the Safari extension. Anything we offer for Safari in future will be described here once it exists.

Network communication

The core job of a download manager is to contact servers. When you add a download, the application connects to the address you gave it, and to any address that address redirects to.

Separately from transfers, functions such as licensing, commerce and software updates require communication with the services that operate them, when those functions apply to your installation. This policy will describe those communications specifically before any of those functions is offered to the public.

Telemetry and analytics

There is no product telemetry and no website analytics at this time. If that ever changes, this policy will say so before the change is released, not afterwards.

Purchases and customer records

Because Yoslion Download is not offered for sale yet, there are no customer accounts, orders or license records. When purchasing opens, orders will be processed by Paddle.com as Merchant of Record, and Paddle will handle payment details under its own privacy terms. This policy will state what we hold for a purchase before the first sale is accepted.

What the licensing service holds for a purchase today is narrow, and it is worth stating because purchase recovery depends on it: the identifier Paddle uses for the customer, the digest of the activation code, the license record and its status. No name, no address, no email address and no payment detail.

Your rights

Depending on where you live, you may have rights over personal information that relates to you, such as the right to ask what is held, to have it corrected, or to have it deleted. Nothing in this policy is intended to limit a right you have under applicable law.

  • Requests are handled through the contact below.
  • Where a request concerns a purchase, the payment provider involved may also hold records under its own policy.

Contact

Changes to this policy

This policy will change as the product moves toward release. The date at the top of the page records when the text was last written.