Privacy Policy — HaoDev (Network Request to Bug Report)
一句话:HaoDev 不收集、不上传、不出售、不共享任何数据。
1. What the extension does with data
HaoDev runs as a Chrome DevTools panel. When you open DevTools and use the panel, it:
- Reads network request metadata (URL, method, status, timings, request and
response headers, request and response bodies) from the Chrome DevTools Network API
(
chrome.devtools.network). That API only exposes requests made by the tab whose DevTools window is currently open. - Stores the requests you explicitly pin in your browser's local IndexedDB
database inside the extension's own storage area, together with the timestamp, the page it came
from (the request's
Refererheader) and the size. - Writes a file to your downloads folder when you click export (Markdown, self-contained HTML, or JSON).
All three steps happen locally, inside your browser, on your machine.
2. What we do NOT do
- We do not transmit any data anywhere. The extension contains no
fetch, noXMLHttpRequest, noWebSocket, no beacon calls, and requests no host permissions. A static check for network APIs is part of the project's own test suite and runs on every change. - We do not collect analytics, crash reports, identifiers, or usage statistics.
- We do not read page content, inject scripts, or modify any website. The extension declares no content scripts and no host permissions.
- We do not sell or share data with third parties — there is no data to sell.
- We do not load or execute remote code. All code ships inside the extension package.
- We do not transmit data to any AI service or other processing service.
3. Permissions and why they are needed
| Permission | Why it is required |
|---|---|
storage |
Stores your preferences locally: whether auto-redaction is on, your custom redaction field names, export naming/template preferences, and the monthly counter. Nothing leaves the browser. |
unlimitedStorage |
Pinned evidence (including full response bodies, up to 256 KB each) is kept in IndexedDB. Without this permission Chrome may evict the database on storage pressure, which would silently destroy evidence the user deliberately saved. |
The extension deliberately requests no host permissions, no
tabs, no activeTab, no
scripting, and no content scripts.
4. Sensitive data and redaction
Pinned requests may contain credentials. HaoDev therefore includes a redaction engine:
- Redaction is applied when displaying and when exporting — never to the stored data. The local database always keeps the original values so that (a) rule changes can be re-applied to old records, and (b) a future request-replay feature remains possible.
- The redaction switch is yours to control. When it is off, exported files contain the original values, and the export dialog shows an explicit red warning before writing.
- File names are always redacted, independently of that switch, because file names travel further than file contents (download lists, search indexes, chat upload previews).
- The self-contained HTML export is always redacted, because that format exists to be handed to someone else.
5. Data retention and deletion
- Pinned evidence lives in your browser profile until you delete it. The panel provides per-record delete and a scoped "clear" action; deleting removes the record from IndexedDB immediately.
- Uninstalling the extension removes all of its storage, including pinned evidence, as part of Chrome's normal extension removal.
- Because nothing is transmitted, there is no server-side copy to delete, and we cannot recover anything for you.
6. Children
The extension is a developer tool. It is not directed at children and collects no personal information from anyone, including children.
7. Changes to this policy
Any change to this policy will be published at this URL, with the date at the top updated. Because the extension collects nothing, material changes are unlikely; if the project ever added any form of data collection, that would require a clear in-product disclosure and a permission change that Chrome would show to you on update.
8. Contact
Questions, bug reports, or privacy concerns: axing499@163.com
隐私政策(中文)
它对你的数据做了什么
- 读取网络请求元数据(URL、方法、状态码、耗时、请求与响应头、请求与响应体),
来源是 Chrome 的 DevTools Network API(
chrome.devtools.network)—— 该 API 只能看到 「当前这个 DevTools 窗口所检查的那个标签页」发出的请求。 - 把你主动点「固化」的请求存进浏览器本地 IndexedDB(扩展自己的存储区),
附带时间、来源页面(请求的
Referer头)和体积。 - 在你点导出时,把一个文件写进你的下载目录(Markdown / 单文件 HTML / JSON)。
这三步全部发生在本机浏览器内。
我们不做的事
- 不上传任何数据。 扩展代码里没有
fetch、没有XMLHttpRequest、 没有WebSocket、没有 beacon 调用,也没有申请任何 host 权限。 项目自己的测试脚本每次改动都会静态检查这一点。 - 不收集统计、崩溃报告、设备标识或使用行为。
- 不读取页面内容、不注入脚本、不修改任何网站(没有 content scripts,没有 host permission)。
- 不向第三方出售或共享数据 —— 没有可卖的数据。
- 不加载、不执行远程代码,全部代码随扩展包一起分发。
- 不把数据传给任何 AI 或云端处理服务。
权限与用途
| 权限 | 为什么需要 |
|---|---|
storage |
在本机保存偏好:自动脱敏开关、自定义脱敏字段名、导出命名与模板、本月采集计数。 |
unlimitedStorage |
固化下来的证据(含完整响应体,单条上限 256 KB)存在 IndexedDB。没有这个权限时 Chrome 可能在存储紧张时清掉数据库,等于静默销毁用户主动保存的证据。 |
扩展刻意不申请 host 权限、tabs、activeTab、
scripting,也不注入内容脚本。
敏感数据与脱敏
- 脱敏只在展示与导出时应用,不作用于存储。本地库里永远是原文, 这样规则更新后能对旧记录重新导出,将来做「重放请求」也不会丢原始请求头。
- 开关由你控制。关掉开关导出时文件里是原值,导出弹窗会先给一次明确的红色警告。
- 文件名始终脱敏(与开关无关)—— 文件名会出现在下载列表、系统搜索、 聊天软件上传预览里,传播得比文件内容更远。
- 单文件 HTML 导出一律强制脱敏,因为那个格式的存在意义就是「发给别人」。
数据保留与删除
- 固化的证据存在你的浏览器配置里,直到你自己删除。面板提供单条删除与按范围清空, 删除即从 IndexedDB 移除。
- 卸载扩展会随 Chrome 的正常卸载流程清除它的全部存储,包括固化的证据。
- 因为不上传,所以不存在服务端副本,我们无法也无需为你恢复任何数据。
儿童
这是开发者工具,不面向儿童,也不向任何人(包括儿童)收集个人信息。
政策变更
任何变更都会发布在本地址,并更新顶部的日期。
联系方式
axing499@163.com