Privacy notice
Clear about what SiteGuard handles.
Last updated July 15, 2026
Summary
SiteGuard 0.1.0 is local-first. It has no analytics, advertising, cloud account, payment connection, or remote SiteGuard server. Checks, optional screenshots, saved flows, settings, and reports stay in Chrome extension storage on the user's device.
When SiteGuard accesses a page
SiteGuard accesses only the active HTTP(S) tab after the user explicitly starts a release check, critical-flow recording, or guided rerun. It does not run continuously across browsing and does not request access to every website.
Data SiteGuard handles
Depending on settings and actions, SiteGuard may process or store:
- Website content: page title, metadata, DOM-based findings, selectors, short diagnostic messages, resource metadata, and an optional visible-tab screenshot.
- Web history: the user-selected page origin, sanitized URL, timestamp, and sanitized resource/request URLs.
- User activity: click, change, or submit action type, a short element label, selector, and timestamp for a saved critical flow. Typed values are not stored.
- Potential identifying content: screenshot capture is off by default and form/editable text is masked, but other visible page areas may still contain names or account information.
Input and secret handling
The recorder does not save ordinary text entered into form fields. Password, authentication, token, secret, session, and payment-like fields are treated as sensitive. URL query values, common tokens, email addresses, and long card-like numbers are redacted from short evidence strings where detected. These safeguards reduce exposure; they are not a guarantee that every confidential detail is removed.
Screenshots
Screenshot capture is off by default. When enabled, SiteGuard masks form and editable text before taking a compressed image of the visible tab. Other visible content, embedded frames, or custom page controls may still show personal or confidential information. Users should review reports before sharing them. JSON exports omit screenshots by default.
Network activity and third parties
SiteGuard does not send report data to its developer, analytics providers, advertisers, or payment services. During a user-started check, it may make a bounded number of same-origin HEAD requests to test link availability. It does not fall back to GET. It may also observe limited request and runtime metadata available to the current page; it does not collect HTTP bodies, headers, cookies, or saved passwords.
Storage, retention, and deletion
Completed checks, optional screenshots, flows, and settings usechrome.storage.local. Active recording and guided-rerun state use chrome.storage.session and end with the browser session. Retention limits are user controlled. Users can delete individual records or choose Delete all local data in SiteGuard Settings. Exported files remain under the user's control.
Permissions and remote code
SiteGuard requests only activeTab, scripting, and storage. It does not request browsing-history, cookie, password, webRequest, debugger, or all-sites permissions. All executable JavaScript and CSS is included in the extension package; SiteGuard does not download or execute remote JavaScript or Wasm and does not use eval or new Function.
Limited Use commitment
SiteGuard's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. SiteGuard does not sell or transfer user data for advertising, creditworthiness, lending, or purposes unrelated to repeatable website release checking. Version 0.1.0 does not transmit SiteGuard report data to the developer or permit developer personnel to read it.
Security
SiteGuard uses Manifest V3, packaged code, a strict extension content security policy, narrow permissions, bounded evidence, redaction, and local deletion controls. Users remain responsible for reviewing any report before exporting or sharing it.
Children
SiteGuard is a professional website-quality tool and is not directed to children.
Changes to this notice
Material privacy changes will appear here with a new update date and, when required, an in-product disclosure or consent step before the affected feature is enabled.