HeaderDeck Privacy Policy

Effective date: July 25, 2026

HeaderDeck is a local-first Chrome extension for creating site-scoped rules that modify HTTP request and response headers and, when the user configures an Inspect rule, display selected response-header information.

Data HeaderDeck handles

HeaderDeck may process the following data only to provide user-configured features:

HeaderDeck is not designed to collect health, financial, location or personal communications data. Users should create rules only for sites and data they are authorized to access.

Storage and retention

Sharing and external processing

HeaderDeck has no account system, analytics, advertising, telemetry or remote backend. It does not sell, transfer or upload user data to the developer or third parties. All matching, modification, inspection and storage happen inside the extension and Chrome.

HeaderDeck's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Chrome API data is used only to provide or improve HeaderDeck's single purpose. It is not used for advertising, creditworthiness or lending, and is not made available to humans except when the user gives affirmative consent for a specific interaction or when required for security, abuse prevention or legal compliance.

Website hosting

The HeaderDeck extension does not connect to the HeaderDeck website and does not transmit extension configuration, request metadata or inspected Header values to the website or Cloudflare.

When a person voluntarily visits headerdeck.com, Cloudflare processes ordinary network request information, such as the visitor's IP address, browser user agent, requested URL and request time, as the website's hosting and security provider. The website does not use accounts, advertising, analytics, tracking cookies or third-party fonts, and website request information is not associated with data handled by the extension.

Permissions

HeaderDeck requests access to websites so user-created profiles can operate on the sites the user selects. It uses Chrome's Declarative Net Request API to modify headers and read-only Web Request events to inspect selected response headers. It does not request blocking Web Request access or extraHeaders. The side panel, active-tab, navigation and storage permissions support the extension's interface, tab-scoped behavior, result lifecycle and local data.

Security and user control

Profiles are restricted to explicit target domains. Header values are omitted from logs and stable error messages. Sensitive Header values are masked in the interface by default and redacted from safe exports. Users can disable all rules immediately with the global switch, delete individual profiles and Inspect results, or uninstall the extension to remove its stored data.

Changes

Material changes to this policy will be published with a new effective date before the corresponding extension update is released.

Contact

For privacy or support questions, open an issue at https://github.com/zzzgydi/headerdeck/issues or email zzzgydi@gmail.com.


HeaderDeck 隐私政策

生效日期:2026 年 7 月 25 日

HeaderDeck 是一款本地优先的 Chrome 扩展,用于创建按站点生效的 HTTP 请求及响应 Header 修改规则,并在用户配置 Inspect 规则后显示选定的响应 Header 信息。

HeaderDeck 处理的数据

HeaderDeck 只为实现用户主动配置的功能而处理以下数据:

HeaderDeck 并非用于收集健康、财务、位置或私人通信数据。用户只应为其有权 访问的站点和数据创建规则。

存储与保留

共享与外部处理

HeaderDeck 不提供账户、分析、广告、遥测或远程后端,不会向开发者或第三方 出售、传输或上传用户数据。所有匹配、修改、检视和存储都在扩展与 Chrome 内部完成。

HeaderDeck 对通过 Chrome API 获得的信息的使用遵守 Chrome Web Store 用户 数据政策(包括 Limited Use 要求)。Chrome API 数据仅用于提供或改进 HeaderDeck 的单一用途,不用于广告、信用评估或借贷;除用户就特定交互明确 同意,或安全、滥用防护及法律合规确有需要外,不会向任何人员开放。

官网托管

HeaderDeck 扩展不会连接 HeaderDeck 官网,也不会向官网或 Cloudflare 传输 扩展配置、请求元数据或 Inspect 检视到的 Header 值。

当用户主动访问 headerdeck.com 时,Cloudflare 作为网站托管和安全 服务商会处理正常的网络请求信息,例如访问者的 IP 地址、浏览器 User-Agent、 请求 URL 和请求时间。官网不使用账户、广告、分析、跟踪 Cookie 或第三方 字体,网站请求信息不会与扩展所处理的数据相关联。

权限

HeaderDeck 申请网站访问权限,以便用户创建的配置能在用户选择的站点工作。 扩展通过 Chrome Declarative Net Request API 修改 Header,通过只读 Web Request 事件检视选定的响应 Header,不申请阻塞式 Web Request 或 extraHeaders。侧边栏、活动标签页、导航和存储权限用于界面、标签页配置、 结果生命周期和本地数据。

安全与用户控制

每个配置都必须指定目标域名。Header 值不会进入日志和稳定错误消息;敏感 Header 值默认在界面中遮盖,并在安全导出中脱敏。用户可以通过全局开关立即 停用所有规则、删除单个配置和 Inspect 结果,或卸载扩展以删除其存储数据。

变更

如本政策发生重大变化,我们会在相应扩展更新发布前更新生效日期和政策内容。

联系方式

隐私或支持问题请提交至 https://github.com/zzzgydi/headerdeck/issues,或发送 邮件至 zzzgydi@gmail.com