This policy explains what the PAA Box Chrome extension, PAA Box Pro and the paabox.com website do with your data. The short version: PAA Box works inside your browser, and your questions, answers and history stay there. Pro adds a daily license check with paabox.com, and Stripe handles payments.
Effective 28 September 2026
Who we are
PAA Box is made by BlogStorm (“we”, “us”, “our”), based in Dyer, Indiana, United States. BlogStorm runs the PAA Box extension, the paabox.com website and PAA Box Pro. The extension was previously published as “BlogStorm: People Also Ask Tool”. This policy covers it under both names.
Questions about privacy? Email hello@paabox.com.
The short version
- The free extension runs only on Google search results pages.
- It reads the People Also Ask questions on the page you are looking at, when you press the button to start.
- The free extension makes no network requests of its own and sends nothing anywhere. It has no account, no analytics and no tracking.
- Your questions leave your browser only if you download them.
- PAA Box Pro is not on sale yet. When it is, your questions, Google’s answers and your history still stay in your browser. Pro checks your license with paabox.com about once a day, sending only a device token. Nothing you unpack is sent to us or to any AI provider.
- If you buy Pro, Stripe handles your card. We keep your email, your subscription details and hashed copies of your license key and device tokens.
- Our website sets no cookies of its own and counts visits without cookies or personal data.
- We do not sell your data, and we do not use it for advertising.
The free PAA Box extension
What it reads
The extension runs only on Google search results pages: google.com, plus any Google country domains you approve. On those pages it:
- Checks whether the page has a People Also Ask box, so it can show its button and panel.
- When you press the button to start (called “Unpack” in PAA Box), opens questions in the box and reads the questions Google shows, down to the depth you pick.
- Reads your search term from the page address, to label your download.
The free version reads questions only. Google’s answers and source links are read only in Pro’s “With answers” mode, described below. It does not read other websites, your browsing history, your Google account or anything on the page outside the People Also Ask box and the search term.
Google sees the clicks
To unpack the box, the extension clicks the questions for you, the same way you would by hand. Google then loads more questions and answers from its own servers, as part of your normal search session. Google handles that activity under Google’s privacy policy.
Where it keeps things
- Your unpacked questions stay in the memory of the open tab. They are gone when you leave or close the page, unless you download them. From the version that adds Pro, finished unpacks of Pro users are also saved in the extension’s own storage in your browser (see “Saved history” below). They never leave your browser.
- A few settings are saved in your browser’s storage for the Google page: your chosen mode and depth, whether the panel is open, and which “What’s new” note you have seen. Because they are stored for the Google page, Google’s own page code could read them too. They contain no questions, answers or search terms. They stay until you clear your browser’s site data for Google.
What leaves your browser, and when
- Download CSV. Saves a file on your computer. Nothing is sent anywhere.
- Links. The panel links to paabox.com, blogstorm.ai and the extension’s Chrome Web Store review page. Clicking the toolbar icon on a page that is not a Google search opens google.com. These are ordinary page visits that happen only when you click.
The free extension makes no other network requests. All of its code ships inside the extension. It does not load or run code from anywhere else.
Older versions
Versions published as “BlogStorm: People Also Ask Tool” (1.0.4 and earlier) work a little differently. They always read Google’s answers and source links. They also have a “Write blogs using BlogStorm” button. Pressing it opens the BlogStorm app at app.blogstorm.ai in a new tab, with your search term and questions (not the answers or source links) in that page’s web address, so BlogStorm’s servers receive them when the page loads. What happens in the BlogStorm app is covered by BlogStorm’s privacy policy. PAA Box has no such button.
Permissions, and why it asks for them
- Google search pages on google.com (required). To show the panel and read the People Also Ask box.
- Google country domains, such as google.co.uk or google.ca (optional). Requested only when you click the toolbar icon on a search page on that domain. You can say no, and you can remove them later in Chrome’s extension settings.
- activeTab. Lets the toolbar icon open the panel on the Google search tab you are on when you click it.
- scripting. Adds the panel to the Google country domains you approved, or to the current tab when you click the icon.
- storage. Gives the extension its own private storage area in your browser. From the version that adds Pro, it keeps your saved unpacks there and, if you connect Pro, your device token and subscription status.
Versions 1.0.4 and earlier ask only for access to Google search pages on google.com.
PAA Box Pro (when it launches)
PAA Box Pro is not on sale yet. This section describes how Pro is built for launch. If that changes before launch, we will update this policy first.
Your research stays in your browser
- In “With answers” mode, the extension also reads Google’s answer and source links for each question it opens.
- Your question sets, Google’s answers and source links, your history, AKA plans, question maps, outlines and JSON copies are all built and kept in your browser.
- None of it is sent to paabox.com, to BlogStorm or to any AI provider. AKA plans are built in your browser by fixed rules, not by an AI model.
Saved history, on your computer
From the version that adds Pro, each completed unpack is saved in the extension’s own storage in your browser while you have Pro. Free users’ unpacks are not saved.
- Each saved unpack holds your search term, the Google domain, the mode, the depth, the date and time, the questions and, in “With answers” mode, Google’s answers and source links.
- The extension keeps your latest 200 unpacks and deletes older ones automatically.
- Saved unpacks are never sent to us.
- Pro users can view saved unpacks on the dashboard’s History page. Anyone with saved unpacks can delete them all from the dashboard’s Account page, including after Pro ends. Removing the extension deletes all of them.
Buying Pro
You buy Pro on paabox.com. Checkout and the customer portal, where you manage or cancel your subscription, are run by Stripe. Your card details go to Stripe only. We never see or store them. Stripe handles payment data under Stripe’s privacy policy.
For Pro, we keep only:
- Your email address, from checkout.
- Your Stripe customer ID and subscription ID.
- Your subscription status and dates, such as when your trial ends and when you renew.
- Your license key, stored only in hashed (scrambled) form.
- A device token for each browser you connect, stored only in hashed form, with the time it last checked in.
We use these to run your subscription, check your license, send you your license key and tell you about your subscription, for example before a price change.
Connecting a browser
To switch Pro on in a browser, the extension opens paabox.com, where you enter your license key and email. paabox.com then gives that browser its own device token. One license works in up to 3 browsers.
- The extension keeps the device token, your email and your subscription status in its own storage in your browser.
- About once a day, the extension checks your license with paabox.com. The check sends only the device token. paabox.com replies with your subscription status.
- You can disconnect a browser at any time. That asks paabox.com to revoke its device token and deletes the token from your browser.
Only pages on paabox.com can pass a connection to the extension. The Pro version also asks for the alarms permission, which it uses to check once a minute whether the AI assistant connection described below should be running.
Using PAA Box from an AI assistant
Pro includes an optional bridge that lets AI assistants such as Claude or Cursor use PAA Box. It is off until you switch it on in the dashboard, and it works only with Pro. It runs entirely on your own computer. Nothing goes through our servers.
- The bridge needs a separate small program, paabox-mcp, which your AI app runs on your own computer. It listens only on your computer (address 127.0.0.1, port 17865 by default). It has no account and no analytics, and it saves nothing.
- When the bridge is on, the extension connects to that program and tells it the extension version and the email on your Pro license.
- Through the bridge, your AI assistant can ask PAA Box to search Google and unpack the results in a new tab or window in your Chrome, list and read your saved unpacks, or build an AKA plan.
- Searches run this way are limited to one every 20 seconds and 30 an hour. They happen in your own browser, so Google sees them as your searches.
- PAA Box sends nothing to any AI provider. Whatever your AI assistant reads through the bridge is handled by that assistant’s provider under its own terms.
- The extension does not check which program answers on that port. Any program on your computer listening there could make the same requests. Only switch the bridge on for a computer you trust.
The paabox.com website
Hosting
paabox.com runs on WordPress, hosted by Hostinger, behind Hostinger’s content delivery network and LiteSpeed cache. Like any website, the server receives your IP address, browser details, the page you asked for and the time. Our host may keep these in standard server logs for security and troubleshooting.
Fonts from Google
Our pages load fonts from Google Fonts. Your browser fetches them from Google’s servers, so Google receives your IP address and browser details. See Google’s privacy policy.
Cookies
paabox.com does not set any cookies of its own. When you buy or manage Pro, checkout and the customer portal open on Stripe’s own site, which has its own cookies and privacy policy.
Visitor counts
We count page views with Koko Analytics, a WordPress plugin that runs on our own server. It uses no cookies. It keeps only totals, such as how many times each page was viewed. It stores no personal data and shares nothing with anyone else.
The “Notify me” form
The form does not send anything to us by itself. It opens your own email app with a message addressed to hello@paabox.com. We receive only what you choose to send. We use your email address to tell you when PAA Box Pro goes on sale and to reply to you. Ask us at any time and we will delete it.
Emailing us
Mail to hello@paabox.com is hosted by Hostinger and is also forwarded to our team’s main inbox. We use what you send only to reply and to help you.
Uninstall feedback
If you remove the extension, we may show a short page asking why. Answering is optional. If you answer, your chosen reason and any comment you type are sent to our server. We don’t ask for your name or email, so please leave them out of the comment. Like any web request, it reaches our server with your IP address, which may appear in standard server logs.
Google Search Console
We use Google Search Console to see how paabox.com shows up in Google search. It gives us summary search data from Google. It adds no code or cookies to our pages.
Links to other sites
Our site links to the Chrome Web Store, which Google runs, to BlogStorm and to Stripe. Those sites have their own privacy policies.
Chrome Web Store Limited Use
PAA Box’s use of information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. In particular:
- We use data from the extension only to provide and improve PAA Box’s People Also Ask features, as described in this policy.
- We transfer it only when needed to provide those features, to comply with the law, to protect against malware, spam, fraud or abuse, or as part of a merger, acquisition or sale of assets with your explicit consent first.
- We never sell it, never transfer it to data brokers, never use it for advertising, and never use it to decide credit-worthiness or for lending.
- No person reads it unless you agree (for example, when you ask for support), it is needed for security or to comply with the law, or it has been combined and anonymized for internal operations.
Who else is involved
- Google runs the search pages the extension works on, serves our website fonts, runs Search Console and runs the Chrome Web Store.
- Hostinger hosts paabox.com and the hello@paabox.com mailbox.
- Stripe processes Pro payments and runs checkout and the customer portal. It receives your card details and the email address you give at checkout.
- Your AI assistant’s provider, for whatever your assistant reads through the AI assistant bridge, if you switch it on. PAA Box itself sends nothing to it.
- Authorities, if the law requires us to share data.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
How long we keep data
- Unpacks in the free extension: until you leave the page, unless you download them.
- Extension settings: in your browser until you clear your site data for Google.
- Saved history (from the version that adds Pro): your latest 200 unpacks, on your computer, until you delete them or remove the extension.
- Device token (Pro): in your browser until you disconnect or remove the extension. We keep a hashed copy with your license.
- Pro subscription records (email, Stripe IDs, subscription status and dates, hashed license key and device tokens): while you have Pro, and after that for as long as we need them for accounting, tax and legal reasons.
- Website visitor counts: kept as totals, with no personal data.
- Server logs: for as long as our host keeps them.
- Emails and uninstall feedback: as long as we need them to reply or to improve PAA Box, or until you ask us to delete them.
Your choices
- You can use the free extension without an account or a license.
- The free version reads questions only. Google’s answers are read only if you have Pro and choose “With answers” mode.
- Nothing you unpack leaves your browser unless you download it or let your AI assistant read it through the bridge.
- You can disconnect a browser from your Pro license, switch the bridge off and cancel Pro at any time.
- Removing the extension deletes everything it keeps in its own storage.
Your rights
Depending on where you live, for example in the EU, the UK or California, you may have the right to:
- See the personal data we hold about you and get a copy.
- Correct it or have it deleted.
- Object to, or ask us to limit, how we use it.
- Withdraw consent you gave us.
- Complain to your data protection authority.
Email hello@paabox.com to use any of these rights. We will not treat you differently for using them. Most of what PAA Box handles never reaches us, because it stays in your browser. You control that data directly.
Legal bases (EU and UK)
We use personal data to provide the features you ask for, for our legitimate interest in running, securing and improving PAA Box and our website, and with your consent where you choose to send us something. You can withdraw consent at any time.
Where data is processed
Our providers, including Stripe, may process data in other countries, including the United States. Where the law requires it, we use appropriate safeguards for these transfers.
Security
The extension talks to paabox.com over encrypted HTTPS. We store license keys and device tokens only in hashed form. Card details are handled by Stripe and never reach us. The AI assistant bridge stays on your own computer. No system is perfectly secure. If you spot a problem, please tell us.
Children
PAA Box is a tool for content and SEO work. It is not meant for children under 16, and we do not knowingly collect their data.
Changes to this policy
We will update this policy when the extension or the website changes, including before PAA Box Pro launches. We will change the date at the top. If a change is significant, we will give notice, for example in the extension’s “What’s new” note or on this site.
Contact
PAA Box is run by BlogStorm. Email us at hello@paabox.com.