Chrome Web Store
The published listing, permission justifications, data-use disclosure, privacy policy, screenshots, and extension behavior should remain consistent.
This page maps product behavior to common review questions. Legal applicability depends on the publisher, user, deployment, jurisdiction, and use case.
This page explains product practices and is not a certification or legal opinion.
| Topic | Product practice | Evidence and boundary |
|---|---|---|
| Single purpose | Website privacy and browser-visible data-flow inspection | Product pages, manifest description, and extension UI use the same narrow purpose. |
| Query-string minimization | Sanitized parameter names only | Parameter values are not inspected or retained; the result remains browser-visible technical evidence. |
| Data minimization | Retain metadata and categories instead of typed values | No passwords, form values, Cookie values, storage values, bodies, or raw destination IPs in reports. |
| User choice | Optional history and Geo Insights | Both features are off by default and can be cleared or disabled. |
| User-controlled comparison | Manual before/after Privacy Checkpoints and local receipt export | The extension never clicks consent controls and never presents the result as legal proof. |
| Transparency | Explainable evidence types, score limits, permissions, and third-party lookup | Privacy policy names ipwho.is and explains country-location limitations. |
| Limited use | Audit data is used only for the product's user-facing purpose | No sale, advertising profile, creditworthiness use, or unrelated transfer. |
| Security | Packaged code, bounded data, sanitization, and restrictive exports | Security page and responsible disclosure channel document the controls and limitations. |
| Optional local bridge | Dual opt-in and minimized evidence exchange with Agent Guard | No new Chrome permission; no value-bearing content or raw IP addresses; peer context cannot rewrite the audit. |
The published listing, permission justifications, data-use disclosure, privacy policy, screenshots, and extension behavior should remain consistent.
The design supports data minimization, purpose limitation, transparency, user choice, and local deletion. This is not a determination that a user or publisher is compliant.
SiteEgress does not sell or share audit data for cross-context behavioral advertising. Applicability and controller/business duties remain case-specific.
Organizations should separately assess browser policy, approved extensions, third-party lookup rules, retention, legal basis, and incident-response requirements.