Scope
SiteEgress helps users inspect and understand browser-visible privacy and data-flow behavior on websites they visit. It reports destinations, known services, form metadata, permission requests, browser-fingerprinting-related signals, Cookie names, browser-storage key names, security context, and optional country-level network-location estimates.
SiteEgress is an inspection and transparency tool. It is not an antivirus product, legal compliance certification, proof of malicious intent, or guarantee that a website does not collect data.
Information processed
To produce an audit, packaged content scripts and the extension service worker may process the current page origin and hostname; destination hostnames; resource types and transfer channels; request methods; form action, method, field count, password-field presence, and broad field-name categories; Cookie names; Local Storage and Session Storage key names; permission events; fingerprinting-related API events; and selected page-security metadata.
SiteEgress does not intentionally retain typed form values, passwords, Cookie values, browser-storage values, authorization headers, request or response bodies, complete query strings, or URL parameter values.
Reports contain evidence metadata, not the private values users type into websites.
Runtime data minimization
SiteEgress classifies only bounded, sanitized URL query parameter names. Parameter values are not inspected for personal-data, credential, token, email, or phone patterns.
Page-world events are projected into event-specific schemas, allowlisted, sanitized, and bounded before they enter extension state. DOM mutation discovery is incremental, debounced, and capped.
The Geo response observer is registered only while Geo Insights is enabled. Turning the feature off removes the observer, aborts active lookups, clears bounded in-memory lookup state, and rejects late results.
Local service intelligence
Service cards use a packaged directory and local domain matching. There is no background vendor-directory lookup. Opening an official reference is a user-initiated visit to a third-party website.
Saved visit baselines
Baselines are saved explicitly by the user, with up to 40 origins and one baseline for each of four scenarios per origin. They remain until deletion, replacement, capacity eviction or uninstall.
Stored fields are limited to origin, hostnames, service or signal categories, counts, scores, coverage and time bounds. Paths, parameter values, page or request bodies, typed values and raw IP addresses are not retained in these baselines.
Privacy Checkpoints and receipts
Privacy Checkpoints compare two minimized browser-visible evidence windows for the same origin, commonly before and after a privacy or Cookie choice. The user makes the choice manually; SiteEgress does not click consent controls or store the wording of the selected option.
A checkpoint stores bounded metadata such as origin, capture/window timestamps, score, coverage, destination hostnames, known service names and categories, aggregate signal counts, optional country-code aggregates, and browser-reported GPC or DNT state when visible. It excludes typed values, page text, request or response bodies, URL parameter values, Cookie or storage values, and raw destination IP addresses.
The local store is limited to eight checkpoints per site and forty sites. A Privacy Receipt is created only after an explicit export action and remains on the user's device unless the user chooses to share it. A comparison is technical evidence, not proof that a legal consent choice was honored or violated.
Version 1.2 adds no new Chrome permissions. Checkpoints use existing local storage and the existing Side Panel.
Privacy choice tests
You operate the website’s privacy controls yourself. A test records the selected service, expected presence and a 10–120 second observation window. Parameters are session-scoped, bounded to 40 tabs; stale windows are ignored after 120 seconds.
Reports describe supported browser-visible evidence, not legal compliance. A service not observed during one window is not proof that it stopped collecting data.
Redacted diagnostics
Diagnostics are generated and exported only on request. They describe collection and local feature state; the diagnostic export excludes website origins and hostnames. This is separate from an audit or baseline, which may contain necessary destination metadata.
Geo Insights
Geo Insights is optional and disabled by default. When a user enables it, SiteEgress may use Chrome's browser-visible response metadata to obtain a destination server IP address. Local and private addresses are classified on the device. A unique public destination-server IP may be sent to ipwho.is solely to obtain a country code and continent code.
The lookup request does not include page text, form values, the full page URL, Cookie values, report contents, or user account information. The raw destination IP is kept only transiently in service-worker memory, is deduplicated to reduce lookups, and is not written to reports, local history, exports, or persistent extension storage.
A displayed country is an estimate of the network server location observed by Chrome. CDN routing, anycast, proxies, caches, load balancers, and multi-region infrastructure can change the apparent country. Geo Insights does not prove legal data residency or where an organization ultimately stores or processes data.
Third-party lookup: ipwho.is. Geo Insights stays off until the user explicitly enables it.
Optional local bridge
SiteEgress can connect locally to the separately installed Agent Guard extension. The bridge is disabled by default in both products and requires explicit opt-in on each side.
Shared fields are limited to normalized origins or destination hostnames, known service/action categories, aggregate scores and counts, policy outcomes, confidence, and bounded evidence metadata. Page text, typed values, passwords, secrets, Cookie or Storage values, request bodies, URL parameter values, and raw destination IP addresses are excluded.
Agent Guard context cannot change a SiteEgress audit. SiteEgress context cannot approve, grant, block, or otherwise control an Agent Guard action. The products remain independently installable and usable.
The bridge adds no Chrome API permission and sends no bridge data to a developer server.
Local storage and retention
Live reports are stored in chrome.storage.session and normally disappear when the browser session ends or the tab report is removed. User preferences are stored in chrome.storage.local.
Local history is optional. If enabled, compact snapshots may include the site origin or hostname, score, destination hostnames, known service names and categories, aggregate signal counts, country-code aggregates, and save time. Raw IP addresses and private field values are not included. Users can clear history at any time.
Reports and exports
A user can export the current report as JSON, CSV, standalone HTML, or a printable page that can be saved as PDF. Exports are created on the user's device and are not uploaded to SiteEgress.
Exports can contain site hostnames, third-party destinations, known service names, evidence labels, scores, and country-code aggregates. Users should review an export before sharing it outside their device.
Permissions and website access
storage keeps session reports and user-controlled local settings. sidePanel displays the audit beside the page. webRequest observes non-blocking response metadata required for optional Geo Insights. HTTP and HTTPS host access lets packaged content scripts inspect normal websites from document start and lets webRequest receive response metadata.
SiteEgress does not request webRequestBlocking, declarativeNetRequest, notifications, cookies, history, downloads, tabs, or remote-code permissions. It cannot inspect Chrome internal pages or the Chrome Web Store.
Your choices and deletion
You can leave Geo Insights, the companion bridge and history disabled, pause or reset an audit, delete or replace visit baselines, clear checkpoints and history, cancel a privacy-choice test, delete your exported files, or uninstall the extension. These controls operate on separate features and storage namespaces.
Disabling Geo Insights removes its response observer and clears current location aggregates and pending lookup state. Disabling either companion bridge stops new summary exchange. Uninstalling removes Chrome-managed extension storage; files you exported remain on your device until you delete them.
Contact and policy changes
Privacy questions can be sent to privacy@siteegress.com. Material changes to data handling will be reflected in this policy and, where required, disclosed before the new processing begins.
This policy covers the extension, not analytics on siteegress.com. Extension audit data is not sent to the website’s analytics service.
Website analytics is documented separately