HeaderPilot Privacy Policy

Effective date: July 11, 2026

HeaderPilot is a local-first Chrome extension that lets users create request and response header rules for a selected website or, when explicitly chosen, for all HTTP and HTTPS websites.

Data handled by HeaderPilot

Storage and retention

Profiles and settings are stored locally using chrome.storage.local. HeaderPilot has no backend service. Data remains on the device until the user removes it, clears extension storage, or uninstalls the extension.

Data transmission and sharing

HeaderPilot does not send user data, browsing activity, header profiles, analytics, or diagnostics to the developer or third parties. When a rule is enabled, Chrome sends the configured header to websites matching the scope selected by the user. A global rule may send its configured header to every HTTP and HTTPS website visited while that rule is enabled.

HeaderPilot does not sell user data, use it for advertising, use it for creditworthiness or lending decisions, or allow humans to read it.

Permissions

Security

HeaderPilot contains no remote code, analytics, advertising SDKs, or third-party dependencies. Sensitive-looking values are masked in the interface. Because local extension storage is not a password vault, users should prefer short-lived development credentials.

Limited Use disclosure

HeaderPilot's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only for the extension's single user-facing purpose, is not transferred except as necessary to apply user-configured headers to user-selected websites, is not used for advertising, and is not made available for human review.

Changes

If this policy changes, the effective date will be updated and the revised policy will be made available through the Chrome Web Store listing.

Contact

For privacy questions, contact the developer using the support contact published on HeaderPilot's Chrome Web Store listing.