Privacy policy
A tool for detecting surveillance cannot be one.
No account · No server · Nothing leaves your device
The short version
- Account, login, emailnone, there is nothing to sign up for
- Where observations gonowhere, there is no server
- Where they stayon your device, until you export or delete
- Runs on pages you visitno, there is no content script
- The reader is injectedinto one tab, while the popup is open
- And only fora site you switched on
- Permissions not requestedtabs, history, webNavigation, cookies
- So browsing history isabsent, not merely unused
What an observation contains
All 36 fields, read from the extension's own schema
- sku_namespace
- sku_id
- variant_key
- condition
- seller_id
- is_marketplace_third_party
- base_price_minor
- currency
- shipping_minor
- shipping_is_free_threshold_met
- tax_minor
- tax_is_included_in_display
- fees_minor
- discount_minor
- discount_source
- total_minor
- country
- region_or_state
- postal_prefix
- currency_requested
- device_class
- os_family
- browser_family
- is_logged_in
- has_loyalty_program
- network_class
- observed_at_utc
- stock_state
- is_promo_window
- promo_label_text
- ab_cookie_names_present
- page_experiment_ids
- repeat_observation_id
- method_version
- tier
- capture_integrity
- Location is recorded ascountry, region, 3 characters of a postcode
- Becausea full postcode beside a purchase is close to a name
- Device, OS and browser asfamilies, never versions
- Becausea rich device profile is itself an identifier
- Cookie namesrecorded
- Cookie valuesnever
- Becausethe names reveal an experiment, the values are private
What it refuses to record
Any of these 32 keys, at any depth, and the observation is thrown away
- url
- href
- full_url
- referrer
- referer
- page_title
- title
- query
- search_query
- search_term
- keywords
- ip
- ip_address
- client_ip
- precise_location
- latitude
- longitude
- lat
- lon
- geo
- cookie_values
- cookies
- user_id
- userId
- account_id
- session_id
- user_agent
- userAgent
- fingerprint
- canvas
- screen_resolution
- Also refusedany value that looks like an address or a path
- Whateverthe field is called
- Why so blunta sabotage test broke the careful version
- The old check tested fortext beginning with http
- What got through ita browsing trail inside a product identifier
- The extension's own idrotates every 24 hours
- So observations cannot bechained into a history, including by us
This website
- Analytics, tracking, cookiesnone set, none read
- Third partiesnone, no fonts, scripts, images or embeds
- Which is what letsthe content security policy deny by default
- Access logthe web server keeps none
- Scripts loadedtwo, both its own
- What they doread the scroll position, change class names
- What they never doa network call, a cookie, any storage
If any of this changes
- Nowhere to send an observationthe transmitting code does not exist
- Which matters becauseabsent code cannot be quietly reversed
- A setting you opted intoit is not that
- Pooling would still be bound bythe refusal list above
- A new field would requirea new published method version
- Announced inthe build log, before it ships
Both lists above are generated from extension/src/schema.js, the file that enforces them.
Last built with method v1.0.