docs(privacy): a short policy that matches the store's answers and the code - #407
Merged
Merged
Conversation
…e code The privacy policy said nothing about the user is collected and no third party is involved, while the store's privacy answers declare personal information, authentication, web history, user activity, website content and payment information, and Polish with AI reaches an AI provider behind the instance. It also described behaviour the code no longer has. PRIVACY.md is rewritten as a short policy: what the extension handles, where it goes (the user's instance; on app.testomat.io, Testomat.io, and Groq for Polish with AI), what stays in the browser and for how long, what runs without a click, the permissions, the user's switches and erase paths, a Limited Use statement, and a contact. The README no longer says nothing runs without a click, nor that the extension is not coming to the Chrome Web Store. Three places where the code broke the policy's promises are fixed with it: - an address inside a console message (the hook's own "Failed to load resource" among them) is trimmed in the log file and in the entry Attach quotes; - a page whose title is Chrome's address placeholder is named by its host in a recorded step, so its query string no longer reaches the test; - cardholder, cc-name, MM / YY, valid thru, CVV2 and CVC2 fields are masked. Mutations through SCREENS_SRC, BG_MODULES and REC_MASK_SRC: 13 of 13 caught. In real Chromium the previous build leaks ?token= into the log and into a step and records a cardholder name; this one does not. Closes #395 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #395