ShelfPrice
Privacy policy

A tool for detecting surveillance cannot be one.

No account · No server · Nothing leaves your device

The short version

  • Account, login, emailnone, there is nothing to sign up for
  • Where observations gonowhere, there is no server
  • Where they stayon your device, until you export or delete
  • Runs on pages you visitno, there is no content script
  • The reader is injectedinto one tab, while the popup is open
  • And only fora site you switched on
  • Permissions not requestedtabs, history, webNavigation, cookies
  • So browsing history isabsent, not merely unused

What an observation contains

All 36 fields, read from the extension's own schema

  • sku_namespace
  • sku_id
  • variant_key
  • condition
  • seller_id
  • is_marketplace_third_party
  • base_price_minor
  • currency
  • shipping_minor
  • shipping_is_free_threshold_met
  • tax_minor
  • tax_is_included_in_display
  • fees_minor
  • discount_minor
  • discount_source
  • total_minor
  • country
  • region_or_state
  • postal_prefix
  • currency_requested
  • device_class
  • os_family
  • browser_family
  • is_logged_in
  • has_loyalty_program
  • network_class
  • observed_at_utc
  • stock_state
  • is_promo_window
  • promo_label_text
  • ab_cookie_names_present
  • page_experiment_ids
  • repeat_observation_id
  • method_version
  • tier
  • capture_integrity
  • Location is recorded ascountry, region, 3 characters of a postcode
  • Becausea full postcode beside a purchase is close to a name
  • Device, OS and browser asfamilies, never versions
  • Becausea rich device profile is itself an identifier
  • Cookie namesrecorded
  • Cookie valuesnever
  • Becausethe names reveal an experiment, the values are private

What it refuses to record

Any of these 32 keys, at any depth, and the observation is thrown away

  • url
  • href
  • full_url
  • referrer
  • referer
  • page_title
  • title
  • query
  • search_query
  • search_term
  • keywords
  • ip
  • ip_address
  • client_ip
  • precise_location
  • latitude
  • longitude
  • lat
  • lon
  • geo
  • cookie_values
  • cookies
  • user_id
  • userId
  • email
  • account_id
  • session_id
  • user_agent
  • userAgent
  • fingerprint
  • canvas
  • screen_resolution
  • Also refusedany value that looks like an address or a path
  • Whateverthe field is called
  • Why so blunta sabotage test broke the careful version
  • The old check tested fortext beginning with http
  • What got through ita browsing trail inside a product identifier
  • The extension's own idrotates every 24 hours
  • So observations cannot bechained into a history, including by us

This website

  • Analytics, tracking, cookiesnone set, none read
  • Third partiesnone, no fonts, scripts, images or embeds
  • Which is what letsthe content security policy deny by default
  • Access logthe web server keeps none
  • Scripts loadedtwo, both its own
  • What they doread the scroll position, change class names
  • What they never doa network call, a cookie, any storage

If any of this changes

  • Nowhere to send an observationthe transmitting code does not exist
  • Which matters becauseabsent code cannot be quietly reversed
  • A setting you opted intoit is not that
  • Pooling would still be bound bythe refusal list above
  • A new field would requirea new published method version
  • Announced inthe build log, before it ships

Both lists above are generated from extension/src/schema.js, the file that enforces them.

Last built with method v1.0.