Browser Extension Privacy Policy

Last updated: 2026-08-03

What This Policy Covers

This policy applies to the Truvizy browser extension for Chrome, Microsoft Edge, Firefox and Safari, including Chromium browsers such as Brave, Opera and Vivaldi that install the same package. It describes what the extension collects, what it never collects, why each browser permission is requested, and how to exercise your rights. Where the extension relies on a Truvizy account, our general Privacy Policy also applies. If the two ever conflict for extension behaviour, this document governs. Contact: privacy@truvizy.app.

What the Extension Collects

URLs you choose to scan: when you start a scan, the address of the content being analyzed is sent to our servers for processing. This happens only when you explicitly ask for a scan. Account information: if you sign in through the extension, we store your email address, display name and subscription status to manage your account and credits. Preferences: your settings, such as auto detect on or off, notification choices and default scan mode, are stored locally in the browser. Scan results and history: scores, evidence breakdowns, timestamps and platform identifiers are stored in your account when signed in, or locally in the browser when you use the extension as a guest. Anonymous usage counts: aggregated non identifying statistics, such as how many scans ran per platform and per scan type, which are not linked to an individual user.

What the Extension Never Collects

The extension does not collect, read, store or transmit any of the following. Browsing history: it does not log or transmit the sites you visit. Personal content: it does not read your emails, messages, documents or files outside the specific item you choose to scan. Passwords and credentials: it never accesses saved passwords, autofill data or authentication tokens belonging to other sites. Keystrokes and form inputs: it does not log typing or monitor form fields. Financial information: card and bank details are never handled by the extension, payments happen on truvizy.app through our payment processor. Location: your geographic location is not accessed or stored. Contacts and social connections: not accessed. Video and audio content: frames and audio captured for the instant on device check are analyzed in memory and discarded, they are never uploaded and never written to disk.

On-Device Analysis

The instant check, including the page scam warning, the badges on social platforms, the selected text check and the passive verdict badge during browser based video calls, runs entirely inside your browser. No video frames, no audio and no page content leave your device for that step. The analysis file the extension needs is downloaded once from truvizy.app and cached locally in your browser, after which the instant check works without contacting our servers at all. The optional deep scan is different and is always initiated by you: it sends the specific link or media you selected to our backend for a fuller analysis, and consumes a credit.

Permissions and Why Each One Is Requested

Every browser receives only the permissions its engine can actually use, so the Firefox and Safari builds request fewer than Chrome and Edge. activeTab, all browsers: read the address of the current tab when you start a scan. storage, all browsers: keep your history, preferences and sign in state on your device. contextMenus, all browsers: add the Truvizy entries to the right click menu so you can check a link, image, media item or selected text. scripting, all browsers: insert the in page component that draws badges and warnings. notifications, all browsers: show a desktop alert when a scan finishes while you are on another tab, or when a page looks dangerous. tabs, all browsers: notice when you move to a supported platform so the in page component activates, and open results in the panel. alarms, all browsers: schedule housekeeping such as expiring cached verdicts and resetting daily counters. offscreen, Chrome and Edge only: host the on device analysis in a hidden document, because those browsers cannot run it in the background worker. Firefox and Safari have no such API and are not granted this permission, their background page performs the analysis directly. sidePanel, Chrome and Edge only: offer Truvizy as a persistent side panel. Firefox uses its own sidebar mechanism, which needs no permission, and Safari has no side panel. contextualIdentities and cookies, Firefox only: open a link you flagged as suspicious inside an isolated container so that site cookies and storage never touch your main browsing session. Truvizy does not read, export or transmit cookie values.

Access to All Sites

The extension requests access to all sites. This is required because scam and phishing pages appear on arbitrary domains, and protection limited to a fixed list of platforms would miss exactly the sites that matter most. The page analysis behind that warning runs on your device and page content is not transmitted. In practice the extension actively interacts with: any site you visit, for the on device page warning; YouTube, TikTok, Instagram, X and Facebook, for the video and post badges; Google Meet, Zoom, Microsoft Teams, WhatsApp Web and Discord, for the passive verdict badge during video calls; our backend, for authentication, deep scans and account sync; and truvizy.app, to download the analysis file once and cache it.

How We Use Your Data

We use what we collect only to: analyze the content you submit and return a result; manage your account, credits, history and progress; improve detection quality using anonymous aggregated usage counts; and answer you if you contact support. We do not sell, rent or trade your personal data, and we do not share it with advertising networks or data brokers. The extension itself shows no advertising.

Where Your Data Is Stored

Account linked data, such as scan history, credits and progress, is stored in our managed database hosted in the Canadian region (ca-central-1), encrypted in transit with TLS 1.2 or higher and encrypted at rest. Guest history and extension preferences stay in your browser local storage and are never transmitted unless you sign in and choose to sync. Deep scan submissions are processed and the result returned, the submitted media is not retained afterwards. Our infrastructure providers are companies that may be subject to lawful access requests under the laws applicable to them, and we apply the safeguards described here wherever data resides.

Third-Party Services

The extension relies on a small set of processors. Our managed database and authentication provider stores account information, scan results and history. Our analysis backend receives the link or media you explicitly submit for a deep scan. Our product analytics provider receives non identifying usage events such as scan counts by platform and scan type. Payment processing happens only on the Truvizy website, never inside the extension, and no payment data is shared from the extension. We do not share data with any party outside this list.

Data Retention

Scan history is kept while your account is active, and you can delete individual scans or your whole history at any time. Account data is kept until you delete your account, after which associated data is permanently removed within 30 days. Guest data stays in your browser until you clear browser data or uninstall the extension. Media submitted for a deep scan is processed in real time and not retained after the result is produced. Frames and audio used by the instant on device check are discarded as soon as the check completes and are never stored. Anonymous aggregated statistics are kept in non identifying form.

Your Rights

All users can access the data held about them from the account dashboard on truvizy.app, delete individual scans or the entire account, export scan history, and correct account information from profile settings. Users in the EU and EEA have the rights granted by the GDPR: access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent. Our legal basis is legitimate interest for providing the scan you request, and consent for optional analytics. Users in California have the rights granted by the CCPA, including the right to know, to delete, to opt out of sale (we do not sell personal information), and to non discrimination. Users in Quebec have the rights granted by Law 25, including access, rectification, de indexing and portability. To exercise any of these rights, write to privacy@truvizy.app. We answer within 30 days.

Children

The extension is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided personal information through the extension, write to privacy@truvizy.app and we will delete it.

Changes to This Policy

When this policy changes materially we update the date shown on this page, note the change in the extension release notes, and publish the updated text here before the corresponding extension version reaches the stores. Continued use of the extension after an update means you accept the revised policy. Questions about this policy: privacy@truvizy.app.