ProxyCeptor Privacy Policy
Last updated: September 30, 2026 • Effective immediately for all users of the ProxyCeptor Chrome Extension, SDK, and Cloud Platform.
Privacy Summary: Local-First by Design
ProxyCeptor is built for developers and QA engineers. Your network requests, responses, headers, cookies, and session replays stay 100% on your local machine. We do not track your browsing habits, inject ads, sell your data, or transmit your network traffic to our servers. Remote connections are made exclusively when you explicitly connect to ProxyCeptor Cloud to sync your team's mocking rules or use your own Google Gemini API key for request analysis.
1. Data That Stays on Your Device
Mocking Rules, Snippets & Settings
All rules you create (URL patterns, status codes, synthetic JSON bodies, header modifications, delays) and custom JavaScript/CSS snippets are stored in your browser's local extension storage (chrome.storage.local). They never leave your device unless you manually export them or choose to sync them to your ProxyCeptor Cloud workspace.
Captured Network Traffic
Network logs (URLs, HTTP methods, status codes, request and response headers, and payloads) are captured solely to populate the DevTools Network Inspector and verify rule execution. This data is held temporarily in memory and session storage (chrome.storage.session). It is never sent to ProxyCeptor servers or third parties.
Session Replay Data
When session recording is enabled, DOM structure, mouse movements, and console logs are buffered in the active tab's volatile memory. This data is never automatically transmitted. It leaves your machine only if you manually click "Export Replay" to download a self-contained HTML file.
2. External Communications (Opt-In Only)
The extension only makes network requests in the following explicit, user-initiated circumstances:
- ProxyCeptor Cloud Synchronization: If you connect the extension using an API key or log in with your email, the extension contacts
https://api.proxyceptor.comto fetch your workspace's rules or save new rules. Captured network traffic and page content are never uploaded to Cloud. - AI Analysis with Google Gemini: If you configure your personal Google Gemini API key in Settings and click "Analyze with AI" on a specific request, that single request's details are sent directly to Google's API under your credentials and subject to Google's Privacy Policy.
- Custom CDN Rule Feeds: If you configure a custom remote rules URL in Settings, the extension fetches that JSON file over HTTPS to load shared rules into your local cache.
- Self-Contained Export Playback: Exported session replay HTML files reference standard open-source player assets from public CDNs (
cdn.jsdelivr.net) during playback in a browser.
3. Browser Permissions & Why We Need Them
In accordance with Google Chrome Web Store policies, each requested permission is strictly scoped to the extension's core functionality:
| Permission | Purpose & Justification |
|---|---|
storage | Saves your interception rules, custom snippets, preferences, and session traffic logs locally. |
scripting | Injects the fetch/XHR network interception shim and custom scripts into web pages you choose to debug. |
activeTab | Enables popup and context menu actions on the currently active tab without persistent background tracking. |
declarativeNetRequest | Applies header modifications, redirects, and request blocks directly via Chrome's high-speed native engine. |
webRequest | Passively observes network traffic events to populate the DevTools Network Inspector and log matched rules. |
alarms | Schedules periodic background synchronization with ProxyCeptor Cloud when connected. |
contextMenus | Adds convenient right-click options to toggle interception, sync rules, or export session replays. |
downloads | Allows saving exported session replay HTML files and HAR network logs to your local downloads folder. |
notifications | Provides non-intrusive status alerts when background cloud sync or export tasks finish. |
<all_urls> | Required because developers test and mock APIs across arbitrary local, staging, and remote domains. |
4. What We Never Do
- We do not sell, rent, or trade your data to data brokers, advertisers, or third parties.
- We do not include third-party tracking, analytics, or behavioral telemetry inside the extension.
- We do not execute remotely hosted code in violation of Chrome Web Store policies. All extension logic is bundled in the packaged CRX.
- We do not access or use your data for creditworthiness, lending, or profiling.
5. Managing & Deleting Your Data
You maintain complete control over all data handled by ProxyCeptor:
- Clear Local Data: Open the extension → Settings → Danger Zone → click "Clear ALL Data" to instantly delete all stored rules, snippets, and cache.
- Uninstalling: Removing the extension from Chrome automatically deletes all local storage and session data.
- Cloud Account Deletion: If you have created a ProxyCeptor Cloud account, you can manage or delete your account and workspace rules at app.proxyceptor.com or by emailing our team.
Questions or Privacy Requests?
If you have questions about this Privacy Policy, your data, or compliance, please contact our privacy and engineering team directly: