PermissionPilot Privacy Policy
This Privacy Policy explains how the PermissionPilot — Privacy & Consent Manager Chrome extension handles information when you use it.
Effective date: July 25, 2026
Last updated: July 25, 2026
PermissionPilot works locally in your Chrome profile. It does not require an account, does not use analytics or advertising, and does not send privacy-audit records, cookie values, browsing history, or website-permission information to the developer or to external servers.
1. About PermissionPilot
PermissionPilot helps users review and manage privacy-related website settings from a local dashboard.
After the user explicitly starts a scan, PermissionPilot may inspect the current website's browser-permission states, look for supported cookie-consent signals, identify known consent-management indicators, and calculate an explainable privacy-risk estimate.
PermissionPilot does not continuously monitor browsing and does not automatically accept or reject cookie banners.
2. Information PermissionPilot may process
When the user explicitly scans a website, PermissionPilot may temporarily process limited information associated with that site, including:
- The website origin, hostname, and page title
- Browser-permission states for supported categories
- The names of cookies associated with the scanned website
- The names of supported consent-related local or session storage keys
- Indicators associated with recognized consent-management systems
- Aggregate consent-purpose and vendor counts when compatible data is exposed
- The date and time of the scan
- Risk explanations generated from detected permission and consent signals
PermissionPilot may inspect a recognized consent-cookie value temporarily when parsing compatible consent information. Raw cookie values are not stored in the audit record.
3. Information PermissionPilot does not intentionally collect
PermissionPilot is not designed to collect or store:
- Passwords or authentication credentials
- Form entries
- Private messages, email content, or page communications
- Payment-card information
- Complete browsing history
- Full webpage text or document content
- Raw cookie values in saved audit records
- Authentication tokens
- Network request or response bodies
4. How information is used
Information processed by PermissionPilot is used only to provide its user-facing privacy-audit and consent-management features:
- Displaying privacy-sensitive browser-permission states
- Identifying supported consent-related signals
- Calculating and explaining a local privacy-risk estimate
- Saving user-created audit records locally
- Helping the user revoke selected browser permissions
- Removing supported consent cookies after an explicit request
- Removing supported consent-related storage entries after an explicit request
- Clearing broader site data only after a separate warning and confirmation
- Searching, filtering, importing, exporting, or deleting local audit records
PermissionPilot does not use this information for advertising, marketing, credit decisions, identity profiling, or unrelated purposes.
5. Local storage
PermissionPilot stores extension preferences, onboarding status, and user-created audit records locally in storage associated with the extension in the user's Chrome profile.
A local audit record may include the website origin, detected permission states, consent indicators, aggregate counts, risk level, risk explanations, and scan time.
PermissionPilot does not maintain a developer-operated account, cloud database, or synchronization server.
6. Website scanning
A website scan begins only after the user explicitly activates PermissionPilot on a regular HTTP or HTTPS webpage.
PermissionPilot does not automatically scan every website the user visits. It does not request permanent access to all websites as part of normal installation.
When additional site access is needed for a specific cleanup action, PermissionPilot may request optional access for the selected website at runtime.
7. Permission and consent cleanup actions
PermissionPilot may offer actions that change browser settings or remove website data. These actions are not performed automatically.
- Browser permissions are changed only after the user selects the relevant site and explicitly requests revocation.
- Supported consent cookies are removed only after the user explicitly requests that action.
- Supported consent-related local or session storage entries are removed only after the user explicitly requests that action.
- Broader site-data cleanup requires an additional warning, confirmation, and optional Chrome permission.
Removing cookies, permissions, or broader site data may sign you out, reset website preferences, or affect related subdomains. Review the selected site and action before confirming.
8. Risk score limitations
PermissionPilot's privacy-risk score is an explainable heuristic based on detected browser permissions and supported consent signals.
The score is not a legal, regulatory, compliance, or security certification. Websites use many different consent systems, so some settings may be unavailable, incomplete, or shown as unknown.
9. Browser permissions
PermissionPilot uses Chrome permissions only to provide its disclosed privacy-audit and consent-management features.
- activeTab: Provides temporary access to the current webpage after the user explicitly activates PermissionPilot.
- scripting: Runs packaged audit and supported cleanup functions on the authorized webpage.
- storage: Stores preferences and user-created audit records locally in the user's Chrome profile.
- sidePanel: Displays the PermissionPilot dashboard beside the current webpage.
- contentSettings: Reads supported per-site Chrome permission settings and changes them only after an explicit user request.
- cookies: Reads cookie names for the selected site, temporarily parses supported consent information, and removes recognized consent cookies only after an explicit user request.
- browsingData: An optional permission requested only when the user chooses broader site-data cleanup and confirms the warning.
- optional host access: Requested at runtime only for selected websites when an action requires access beyond the current active tab.
10. Data sharing and external transmission
PermissionPilot does not sell, rent, share, or transmit audit records, cookie values, website-permission states, consent information, or extension settings to advertisers, data brokers, analytics providers, or other third parties.
The extension does not use:
- Analytics services
- Advertising networks
- Tracking pixels
- Remote logging services
- Developer-operated external servers
- Remotely hosted executable code
11. Exporting and importing audit records
PermissionPilot may allow users to export local audit records to a file and later import a compatible backup.
Exported files are created only after the user requests them. Once exported, those files are protected according to the security of the user's device and any location where the user chooses to store or share them.
12. Data retention and deletion
Local audit records and preferences may remain in the Chrome profile until the user deletes them, clears extension data, resets the extension, or removes PermissionPilot.
Because PermissionPilot does not maintain a developer-operated account or server-side database, there is no separate online account or remote audit history that must be deleted.
13. Optional support link
PermissionPilot may include an optional link to support independent development through Buy Me a Coffee.
PermissionPilot does not contact that service automatically. A connection to Buy Me a Coffee occurs only if the user explicitly opens the support link. The external service's own terms and privacy policy apply after the user leaves the extension.
14. Data security
PermissionPilot reduces external exposure by processing information locally and by avoiding developer-operated servers.
However, no local storage system can guarantee absolute security. Anyone who can access an unlocked device or Chrome profile may be able to access locally stored extension information.
15. Children's privacy
PermissionPilot is not specifically directed toward children. The extension does not knowingly collect information from children through a developer-operated server.
16. Chrome Web Store Limited Use disclosure
PermissionPilot's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Information accessed through Chrome APIs is used only to provide or improve PermissionPilot's disclosed, user-facing privacy-audit and consent-management functionality. It is not used for advertising, unrelated profiling, or other undisclosed purposes.
17. Changes to this Privacy Policy
This Privacy Policy may be updated when PermissionPilot's functionality, data practices, or legal obligations change.
The effective date and last-updated date at the top of this page will be revised when material changes are published.
18. Contact
Questions about PermissionPilot or this Privacy Policy can be sent to: