Prelaunch legal review: this operational privacy draft must be reviewed for the final seller, vendors, jurisdictions, retention controls, and launch configuration.
Four separate data planes
1. Local scanner
Your ZIP, extracted source, manifest values, report, questionnaire answers, filenames, paths, hashes, domains, and permission list stay in the browser during the free scan. Detected URLs are not fetched.
2. Bounded product analytics
If enabled, analytics records only controlled product-flow events and coarse properties listed below. It must not record package content or user-entered policy text.
3. Commerce and email
Stripe will process payment information. ExtensionGate will retain only the purchase, entitlement, hashed/encrypted email data, refund, dispute, tax, and accounting facts needed to fulfill and restore a Release Pass. No package, report, questionnaire, finding, or detected domain enters checkout metadata or the entitlement database.
Resend will process activation and restore email. Its current standard service retains email data for 30 days and stores account/email metadata in the United States. Final processor terms, retention controls, and deletion procedures require owner review before checkout opens.
4. Direct support
Information deliberately emailed to support, billing, privacy, or security is processed to answer the request. Do not send packages, code, secrets, or customer data.
Browser storage and abuse prevention
Free scan, report, questionnaire, and packet state is ephemeral by default and is not written to local storage or IndexedDB. A paid entitlement may use an essential secure cookie until its expiration. Blocking that cookie does not prevent free scanning, but activation and restore cannot remain available without it.
Contact and restore forms use Cloudflare Turnstile only on those routes. Turnstile processes browser signals to distinguish automated abuse. ExtensionGate also applies rate limits. Turnstile is not loaded on the scanner or report route.
Infrastructure providers may temporarily process IP addresses for delivery and security. Product-event storage does not retain IP addresses.
Analytics schema
Allowed events are:
scan_started, scan_completed, scan_failed, finding_opened, finding_copied, example_report_viewed, questionnaire_started, questionnaire_completed, upgrade_viewed, checkout_started, checkout_completed, restore_requested, export_clicked, rescan_started, and post_report_survey_completed.
Allowed properties are controlled target-store, package-size, duration, overall-state, finding-count, export-format, fixture/demo, and acquisition channel buckets; the ruleset version; and one public rule ID only when a user manually opens that finding.
Forbidden fields include filename, path, hash, manifest value, extension name or version, source code, domain, permission list, questionnaire answer, privacy text, report JSON, email, raw referrer query, persistent IP address, browser fingerprint, and combined finding-ID sets.
Identifiers should be ephemeral. Raw bounded events, if temporarily needed, are retained no longer than 30 days before aggregation and deletion. Persistent IP storage and fingerprinting are prohibited.
Your choices and contact
Resetting or closing a free scan clears its in-memory state. Commerce deletion and access mechanics will be documented before sales. Privacy questions may be sent to privacy@extensiongate.com; mailbox delivery must be verified before launch.