objekt.my

Privacy policy — Objekt Match

Last updated 2026-09-24. Applies to the browser extension “Objekt Match” for Chrome/Chromium and Firefox.

The short version

The extension keeps a local index of Discord trade posts so you can match them against your own objekts. What it captures is kept in your browser. It has no account of its own and no analytics. The only server it talks to is objekt.my, the developer’s own site, for the three things listed under “What leaves your device” below. On objekt.my pages it only listens for a list of missing objekts you send it by pressing a button.

What it collects

From the server channels you open, unless you have paused capture in that channel, and only from messages already rendered on screen in your own Discord tab. Capture is on in every server channel by default once you agree to it:

  • the message author’s displayed name,
  • the message text,
  • the message timestamp,
  • Discord’s channel and message ids, used as storage keys so the same post is not stored twice.

It also stores what you type into the panel: your want list, your Cosmo nickname if you enter one, and your pace and page settings.

To pace searches so Discord does not refuse them, it also keeps, on your device only: when each search request was sent over the last 10 minutes, how long result pages took to load, the slower pace Discord last pushed a search to, which codes were searched in the last 30 days, and when searching was last paused for a rate limit. These are never sent anywhere.

What it does not collect

  • Your Discord token, password, email or account id.
  • Direct messages or group DMs, or anything you have not opened.
  • Attachments, images, voice, or embeds — text bodies only.
  • Browsing history, or any activity on sites other than Discord. On objekt.my it reads nothing but the list you send it (see “On objekt.my pages” below).
  • Analytics, telemetry, crash reports, or usage statistics of any kind.

Where it is stored

In your browser, on your device:

  • captured posts in IndexedDB (database objekt-discord-capture), on the extension’s own origin;
  • settings, your want list (including one sent from objekt.my, and the list it replaced, kept for a day so you can undo), and your agreement record in extension storage.

The extension does not upload, back up, or sync its index. Uninstalling the extension removes both. Clear captured posts in the panel empties the index at any time.

What leaves your device

Everything below goes only to objekt.my, over requests that carry no cookies and no credentials from the extension. Nothing is sent to Discord by the extension, and no third party, advertiser, or analytics provider is involved.

  1. Card art. As you type your want list, the season, collection number and member of each line are sent to objekt.my’s public collection search, to show the card’s picture instead of a bare code. This happens as you type, without a button press. Nothing about your Discord activity is included.
  2. Opening a search in objekt.my/match. When you press Open in match, the posts from your last search — the author names, text and timestamps described above — are handed to an objekt.my/match tab (opened or reused) through a script the extension injects into it. Nothing is sent until you press the button. The match page keeps those posts in your browser’s storage rather than uploading them, with two exceptions: links to external trade lists found inside posts are fetched through objekt.my’s server so the lists can be imported, and if you are signed in to objekt.my, a one-way hash of each post you mark as seen — not its text — is saved to your account so it stays hidden on your other devices. The Download buttons in Settings write a file to your downloads folder instead, if you would rather keep a file.
  3. Inventory lookup. If you type a Cosmo nickname and press Load, the extension requests your objekts for that nickname from objekt.my once. The nickname is the only thing sent. Skip it by typing your haves instead.

Access to objekt.my is a required permission — the extension cannot do its job without it — but each request above happens only when its trigger occurs (typing a want, pressing Open in match, pressing Load), not merely because the permission is held.

On objekt.my pages

On objekt.my pages the extension listens only for a list of missing objekts you send by pressing a button, and stores that want list locally. It reads nothing else from objekt.my pages and sends nothing back except that it is installed.

  • What it listens for. Two kinds of message the page posts to itself: “is the extension installed?”, and a list of missing objekts — up to 40 names such as “SeoYeon CC101”, plus your Cosmo nickname if the page knows it. It is only sent when you press Find on Discord or Add to Objekt Match.
  • What it does with that list. Makes it the want list in the extension’s panel, keeping the list it replaced so Undo can put it back. Your nickname is filled in only if the extension has none; one you typed is never overwritten. Then it switches to the Discord tab you used last, with its panel open, or opens Discord if you have no tab there.
  • What it answers. That it is installed, and its version number, so the page can offer the button. Nothing else.
  • What it does not do there. Read the page, your objekt.my account, or its cookies; make any request; or run on any site other than objekt.my and Discord.

Other people's posts

A captured post is somebody else’s writing, and their display name is personal data. You are the one collecting it, so treat it that way: keep exports to yourself, delete them when the trade is done, and clear the index when you are finished. The extension does not publish, share, or aggregate what you collect.

Automated search

If you separately agree to it, the extension can type your objekt codes into Discord’s own search box and click through the result pages. This is automation of your Discord account, which Discord’s Terms of Service do not permit, and Discord may act on accounts that use it. It collects nothing beyond what is listed above, is off by default, and requires its own separate agreement.

Your choices

  • Capture is off until you agree. After that it is on in every server channel you open; pause it from the panel in any channel you do not want read.
  • Withdraw consent stops the extension reading Discord at all; the reader is detached, not just paused.
  • Clear captured posts deletes the index.
  • Removing the extension deletes everything it holds.

Contact

Questions or a deletion request: open an issue at github.com/sharkbeans/objekt-tools, or use the developer contact on the extension’s store listing.

Not affiliated with Discord, MODHAUS or COSMO.