Loading...
Loading...
Legal
KeySpotter warns you when a website exposes secret API keys or test-mode payment keys. It runs entirely on your own device. There is no KeySpotter account, no KeySpotter server and no backend operated by the developer. The developer does not receive, store or have any access to your data.
This policy describes, in full, what data the extension collects, how it is handled, how and where it is stored, and the circumstances in which it is shared.
KeySpotter processes one category of user data, locally on your device.
What: The content of the web pages you visit:
How it is collected:
Why: To detect exposed secret keys and test-mode payment keys, and to show you the result.
None of this content is sent to the developer or to anyone else.
Website content is used for one purpose only: detecting exposed secret keys and test-mode payment keys, and showing you the result. It is not used for advertising, profiling, analytics or any other purpose.
All data stays on your device, in your browser’s extension storage.
| Data | Where | How long |
|---|---|---|
| Scan results for open tabs, including found values (so you can reveal or copy them) | Browser session storage | Deleted when you close the tab |
| A cache of script scan results, so the same script is not scanned twice | Browser session storage | Deleted when the browser closes |
| Settings (automatic scanning, on-site alerts) | Browser local storage | Until you change them or remove the extension |
| Sites you muted | Browser local storage | Until you unmute them or remove the extension |
| Markers of alerts already shown: one-way SHA-256 hashes, never the keys themselves | Browser local storage | 30 days |
KeySpotter shares no data with anyone. There are no analytics, no tracking and no servers.
| Third party | Purpose | Policy |
|---|---|---|
| None | n/a | n/a |
To scan a page, KeySpotter makes these requests:
/.well-known/security.txt is requested only when you click “Copy disclosure note”, from the site you are viewing, without cookies. Redirects are refused.KeySpotter never requests hidden or unlinked files on any website. The page’s API responses are read from the page’s own traffic, with no extra requests.
| Permission | Why |
|---|---|
storage | Keep settings, muted sites, per-tab results and the script-scan cache on your device |
scripting | Run the page scanner after you grant site access, and show the in-page alert |
activeTab | Scan the current page when you click “Scan this page” without automatic scanning |
| Optional access to all sites | Asked only when you turn on automatic scanning; never at install |
| Optional access to one site | Asked only when you click “Scan source maps” on that site |
KeySpotter is a developer tool. It is not directed at children and does not knowingly process children’s data.
If this policy changes, the “Last updated” date above will change, and the new policy will be published at this address before the changed extension version is released.
Questions or requests about this policy: hello@its-tahir.com
Email hello@its-tahir.com