← Incognito Toolkit

Privacy Policy — Incognito Toolkit

Last updated: 6 September 2026 · Applies to version 2.7

In short: the extension does not collect, sell, or transmit your personal data. It has no servers, no accounts, and no analytics. Everything it does happens locally in your browser, and every feature can be switched off.

1. Data we collect

None. We do not receive, store, or transmit any information about you, your accounts, your messages, or the pages you visit. There is no telemetry and no crash reporting.

2. Data stored on your device

Only your own settings: which features you have switched on, the date the optional block lists were last refreshed, and the version number last shown to you in the "what's new" page. These are kept with the browser's chrome.storage.local API, never leave your device, and are removed when you uninstall the extension.

3. Access to page content

To do its job, the extension reads and modifies pages while you browse — for example to detect a page imitating the Facebook login screen, to hide "Suggested" and "Sponsored" posts, to strip click-tracking from search results and shared links, and to stop "seen" and "typing" signals on Facebook, Messenger and Instagram. All of this runs on your device. No page content, message, or browsing history is ever sent anywhere.

4. Changes the extension makes to network requests

Using the browser's declarativeNetRequest API, and only for the features you have enabled, the extension may:

These rules are applied by the browser itself. The extension does not see the contents or the responses of your requests.

5. Browser settings the extension can change

With the privacy permission, and only while the matching toggle is on, the extension turns off ad-tracking features built into the browser: the Privacy Sandbox APIs (Topics, Protected Audience/FLEDGE, Attribution Reporting), hyperlink auditing, and speculative prefetching. A separate optional toggle blocks third-party cookies. When you switch a toggle off, the setting is handed back to the browser default — it is never forced to the opposite value. No data is read through this API.

6. Scripts the extension runs

All executable code ships inside the extension package. No remote code is ever downloaded or executed. One small optional script (which tells websites your Do-Not-Sell preference) is registered with the scripting permission only while the "privacy signals" toggle is on, and unregistered when you turn it off.

7. Block lists downloaded from the internet

If you enable an optional list ("crypto-mining & scam domains" or "pop-up ads"), the extension downloads that public list once per day from its official source on GitHub (raw.githubusercontent.com). This is a one-way download of a plain text file of domain names. No information about you, your settings, or your browsing is included in the request. As with any request to a website, GitHub can see your IP address at that moment; nothing else is sent, and these lists are off by default.

8. Permissions and why they are needed

PermissionWhy
storageSave your on/off settings locally.
declarativeNetRequestLet the browser block and clean requests as described in section 4.
alarmsSchedule the once-a-day refresh of the optional block lists.
privacyTurn off the browser's built-in ad-tracking features (section 5).
scriptingRegister/unregister the optional Do-Not-Sell signal script (section 6).
Access to websites
http://*/*, https://*/*
Required so the protections can run on the sites you visit, and so header and URL cleaning can be applied. Processing is local only.

9. Sharing and selling

We do not sell, rent, or share any data — because we do not collect any. No data is transferred to third parties for any purpose.

10. Children's privacy

The extension does not collect data from anyone, including children.

11. Changes to this policy

If this policy changes, the updated version is posted at this address with a new "last updated" date and the version it applies to.

12. Contact

Questions about this policy? Contact hypnguyen1209@gmail.com.