Privacy policy

Effective date: 2026-10-10. Applies to the HeaderVault browser extension for Chrome, Firefox and Opera.

Summary

Your data does not leave your browser. HeaderVault makes no network requests, has no analytics or telemetry, and does not collect, sell or share any data.

What HeaderVault stores

HeaderVault stores the settings you create — profiles, header names and values, URL filters, resource types, the active profile, the pause state and the interface language — in your browser's local extension storage (storage.local). Header values can include tokens or cookies you enter; they are used only to build the header rules your browser applies.

This data stays on your device. It is not synced to other devices or accounts and is removed when you uninstall the extension.

What HeaderVault does not do

  • It does not send any data to the developer or to third parties, and contains no remote code.
  • It does not collect browsing history, page content, personal information or usage statistics.
  • It does not read the content of the pages you visit; it only asks the browser to change request and response headers according to your rules.

Export files

Data leaves the extension only when you export it: clicking Export saves a JSON file to your device. That file contains your header values, including tokens, so keep it private. HeaderVault never creates exports by itself.

Permissions

  • declarativeNetRequestWithHostAccess — applies your header rules through the browser.
  • storage — keeps your settings in local extension storage.
  • Access to all sites (optional) — requested when you enable your first header, because the browser applies header rules only on sites the extension can access. You can withdraw or limit it at any time in your browser's extension settings.

Changes and contact

If this policy changes, the new version will be published on this page with a new effective date. Questions: [email protected].