Chrome Web Store
The published listing, permission justifications, data-use disclosure, privacy policy, screenshots, and extension behavior should remain consistent.
This page maps product behavior to common review questions. Legal applicability depends on the publisher, user, deployment, jurisdiction, and use case.
本ページは製品の取り組みを説明するもので、認証や法的見解ではありません。
| Topic | Product practice | Evidence and boundary |
|---|---|---|
| Single purpose | Website privacy and browser-visible data-flow inspection | Product pages, manifest description, and extension UI use the same narrow purpose. |
| URL クエリ最小化 | サニタイズ済みパラメーター名のみ | 値は検査・保持しません。 |
| Data minimization | Retain metadata and categories instead of typed values | No passwords, form values, Cookie values, storage values, bodies, or raw destination IPs in reports. |
| User choice | Optional history and Geo Insights | Both features are off by default and can be cleared or disabled. |
| ユーザー主導の比較 | 選択前後のチェックポイントとローカル証跡 | 同意UIを自動クリックせず、法的証明として表示しません。 |
| Transparency | Explainable evidence types, score limits, permissions, and third-party lookup | Privacy policy names ipwho.is and explains country-location limitations. |
| Limited use | Audit data is used only for the product's user-facing purpose | No sale, advertising profile, creditworthiness use, or unrelated transfer. |
| Security | Packaged code, bounded data, sanitization, and restrictive exports | Security page and responsible disclosure channel document the controls and limitations. |
| Optional local bridge | Dual opt-in and minimized evidence exchange with Agent Guard | No new Chrome permission; no value-bearing content or raw IP addresses; peer context cannot rewrite the audit. |
The published listing, permission justifications, data-use disclosure, privacy policy, screenshots, and extension behavior should remain consistent.
The design supports data minimization, purpose limitation, transparency, user choice, and local deletion. This is not a determination that a user or publisher is compliant.
SiteEgress does not sell or share audit data for cross-context behavioral advertising. Applicability and controller/business duties remain case-specific.
Organizations should separately assess browser policy, approved extensions, third-party lookup rules, retention, legal basis, and incident-response requirements.