Skip to content

docs(privacy): a short policy that matches the store's answers and the code - #407

Merged
gololdf1sh merged 1 commit into
mainfrom
docs/395-privacy-policy
Oct 1, 2026
Merged

gololdf1sh merged 1 commit into
mainfrom
docs/395-privacy-policy

Conversation

@gololdf1sh

Copy link
Copy Markdown
Collaborator

Closes #395

…e code

The privacy policy said nothing about the user is collected and no third party is
involved, while the store's privacy answers declare personal information,
authentication, web history, user activity, website content and payment
information, and Polish with AI reaches an AI provider behind the instance. It
also described behaviour the code no longer has.

PRIVACY.md is rewritten as a short policy: what the extension handles, where it
goes (the user's instance; on app.testomat.io, Testomat.io, and Groq for Polish
with AI), what stays in the browser and for how long, what runs without a click,
the permissions, the user's switches and erase paths, a Limited Use statement,
and a contact. The README no longer says nothing runs without a click, nor that
the extension is not coming to the Chrome Web Store.

Three places where the code broke the policy's promises are fixed with it:
- an address inside a console message (the hook's own "Failed to load resource"
  among them) is trimmed in the log file and in the entry Attach quotes;
- a page whose title is Chrome's address placeholder is named by its host in a
  recorded step, so its query string no longer reaches the test;
- cardholder, cc-name, MM / YY, valid thru, CVV2 and CVC2 fields are masked.

Mutations through SCREENS_SRC, BG_MODULES and REC_MASK_SRC: 13 of 13 caught. In
real Chromium the previous build leaks ?token= into the log and into a step and
records a cardholder name; this one does not.

Closes #395

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@gololdf1sh gololdf1sh self-assigned this Oct 1, 2026
@gololdf1sh
gololdf1sh merged commit e7b0a71 into main Oct 1, 2026
1 check passed
@gololdf1sh
gololdf1sh deleted the docs/395-privacy-policy branch October 1, 2026 07:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PRIVACY.md contradicts the store's privacy answers and the code

1 participant