HeaderDeck Privacy Policy
Effective date: July 25, 2026
HeaderDeck is a local-first Chrome extension for creating site-scoped rules that modify HTTP request and response headers and, when the user configures an Inspect rule, display selected response-header information.
Data HeaderDeck handles
HeaderDeck may process the following data only to provide user-configured features:
- Profile configuration, including target domains, URL matching conditions, Header names and Header values entered by the user.
- The URL, hostname, request method, resource type and response headers of a network request while determining whether a user-created rule matches.
- Rendered Inspect output, which can include a response-header value or URL selected by the user's template, together with the Header name, hostname and update time.
- Extension preferences and local diagnostics such as rule counts and stable error codes.
HeaderDeck is not designed to collect health, financial, location or personal communications data. Users should create rules only for sites and data they are authorized to access.
Storage and retention
- Persistent profiles, settings and recovery copies of corrupted
configuration are stored in
chrome.storage.localon the user's device. They remain until the user deletes them, clears the extension's storage or uninstalls HeaderDeck. - Temporary tab profiles and rendered Inspect results are stored in
chrome.storage.session. They are cleared when their tab or browser session ends, when navigation invalidates them, when the user clears them, or when HeaderDeck is disabled. - The complete matched request URL and original response-header collection are not persisted as Inspect result fields. A rendered label or link can nevertheless contain data the user explicitly selected with a template.
- YAML files and clipboard content are created only after a user-initiated
import, export, paste or copy action. Safe exports replace all configured
setvalues with{{SECRET}}.
Sharing and external processing
HeaderDeck has no account system, analytics, advertising, telemetry or remote backend. It does not sell, transfer or upload user data to the developer or third parties. All matching, modification, inspection and storage happen inside the extension and Chrome.
HeaderDeck's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Chrome API data is used only to provide or improve HeaderDeck's single purpose. It is not used for advertising, creditworthiness or lending, and is not made available to humans except when the user gives affirmative consent for a specific interaction or when required for security, abuse prevention or legal compliance.
Website hosting
The HeaderDeck extension does not connect to the HeaderDeck website and does not transmit extension configuration, request metadata or inspected Header values to the website or Cloudflare.
When a person voluntarily visits headerdeck.com, Cloudflare processes
ordinary network request information, such as the visitor's IP address,
browser user agent, requested URL and request time, as the website's hosting
and security provider. The website does not use accounts, advertising,
analytics, tracking cookies or third-party fonts, and website request
information is not associated with data handled by the extension.
Permissions
HeaderDeck requests access to websites so user-created profiles can operate on
the sites the user selects. It uses Chrome's Declarative Net Request API to
modify headers and read-only Web Request events to inspect selected response
headers. It does not request blocking Web Request access or extraHeaders.
The side panel, active-tab, navigation and storage permissions support the
extension's interface, tab-scoped behavior, result lifecycle and local data.
Security and user control
Profiles are restricted to explicit target domains. Header values are omitted from logs and stable error messages. Sensitive Header values are masked in the interface by default and redacted from safe exports. Users can disable all rules immediately with the global switch, delete individual profiles and Inspect results, or uninstall the extension to remove its stored data.
Changes
Material changes to this policy will be published with a new effective date before the corresponding extension update is released.
Contact
For privacy or support questions, open an issue at https://github.com/zzzgydi/headerdeck/issues or email zzzgydi@gmail.com.
HeaderDeck 隐私政策
生效日期:2026 年 7 月 25 日
HeaderDeck 是一款本地优先的 Chrome 扩展,用于创建按站点生效的 HTTP 请求及响应 Header 修改规则,并在用户配置 Inspect 规则后显示选定的响应 Header 信息。
HeaderDeck 处理的数据
HeaderDeck 只为实现用户主动配置的功能而处理以下数据:
- 用户填写的配置,包括目标域名、URL 匹配条件、Header 名称和 Header 值;
- 判断规则是否匹配时临时处理的请求 URL、主机名、请求方法、资源类型和响应 Header;
- Inspect 渲染结果,包括用户模板主动选择的响应 Header 值或 URL,以及 Header 名称、主机名和更新时间;
- 扩展设置和本地诊断信息,例如规则数量与稳定错误代码。
HeaderDeck 并非用于收集健康、财务、位置或私人通信数据。用户只应为其有权 访问的站点和数据创建规则。
存储与保留
- 持久配置、设置和损坏配置的恢复副本保存在用户设备的
chrome.storage.local,直到用户删除、清除扩展存储或卸载 HeaderDeck; - 临时标签页配置和 Inspect 渲染结果保存在
chrome.storage.session,会在 标签页或浏览器会话结束、导航使结果失效、用户清空结果或关闭 HeaderDeck 时删除; - Inspect 结果字段不会持久化完整的匹配请求 URL 和原始响应 Header 集合。 但渲染文案或链接可能包含用户通过模板主动选择的数据;
- YAML 文件和剪贴板内容只在用户主动导入、导出、粘贴或复制时产生。安全
导出会把所有已配置的
set值替换为{{SECRET}}。
共享与外部处理
HeaderDeck 不提供账户、分析、广告、遥测或远程后端,不会向开发者或第三方 出售、传输或上传用户数据。所有匹配、修改、检视和存储都在扩展与 Chrome 内部完成。
HeaderDeck 对通过 Chrome API 获得的信息的使用遵守 Chrome Web Store 用户 数据政策(包括 Limited Use 要求)。Chrome API 数据仅用于提供或改进 HeaderDeck 的单一用途,不用于广告、信用评估或借贷;除用户就特定交互明确 同意,或安全、滥用防护及法律合规确有需要外,不会向任何人员开放。
官网托管
HeaderDeck 扩展不会连接 HeaderDeck 官网,也不会向官网或 Cloudflare 传输 扩展配置、请求元数据或 Inspect 检视到的 Header 值。
当用户主动访问 headerdeck.com 时,Cloudflare 作为网站托管和安全
服务商会处理正常的网络请求信息,例如访问者的 IP 地址、浏览器 User-Agent、
请求 URL 和请求时间。官网不使用账户、广告、分析、跟踪 Cookie 或第三方
字体,网站请求信息不会与扩展所处理的数据相关联。
权限
HeaderDeck 申请网站访问权限,以便用户创建的配置能在用户选择的站点工作。
扩展通过 Chrome Declarative Net Request API 修改 Header,通过只读 Web
Request 事件检视选定的响应 Header,不申请阻塞式 Web Request 或
extraHeaders。侧边栏、活动标签页、导航和存储权限用于界面、标签页配置、
结果生命周期和本地数据。
安全与用户控制
每个配置都必须指定目标域名。Header 值不会进入日志和稳定错误消息;敏感 Header 值默认在界面中遮盖,并在安全导出中脱敏。用户可以通过全局开关立即 停用所有规则、删除单个配置和 Inspect 结果,或卸载扩展以删除其存储数据。
变更
如本政策发生重大变化,我们会在相应扩展更新发布前更新生效日期和政策内容。
联系方式
隐私或支持问题请提交至 https://github.com/zzzgydi/headerdeck/issues,或发送 邮件至 zzzgydi@gmail.com。