HeaderPilot Privacy Policy
Effective date: July 11, 2026
HeaderPilot is a local-first Chrome extension that lets users create request and response header rules for a selected website or, when explicitly chosen, for all HTTP and HTTPS websites.
Data handled by HeaderPilot
- The active tab URL and origin, used to display the current target and create site-scoped rules.
- User-created header names, values, operations, enabled states, and scope settings.
- Authentication-related values such as
Authorization, cookies, or API keys only when the user explicitly enters them. - The active tab URL during navigation when the optional Auto-connect tabs feature is enabled.
Storage and retention
Profiles and settings are stored locally using chrome.storage.local. HeaderPilot has no backend service. Data remains on the device until the user removes it, clears extension storage, or uninstalls the extension.
Data transmission and sharing
HeaderPilot does not send user data, browsing activity, header profiles, analytics, or diagnostics to the developer or third parties. When a rule is enabled, Chrome sends the configured header to websites matching the scope selected by the user. A global rule may send its configured header to every HTTP and HTTPS website visited while that rule is enabled.
HeaderPilot does not sell user data, use it for advertising, use it for creditworthiness or lending decisions, or allow humans to read it.
Permissions
activeTab: Reads the active tab URL after the user clicks HeaderPilot.declarativeNetRequestWithHostAccess: Applies user-defined header rules without reading page content.sidePanel: Displays the interface in Chrome's side panel.storage: Stores profiles and settings locally.- Optional website access: Requested for the user-selected site or global scope.
- Optional
tabs: Used only for the Auto-connect tabs feature.
Security
HeaderPilot contains no remote code, analytics, advertising SDKs, or third-party dependencies. Sensitive-looking values are masked in the interface. Because local extension storage is not a password vault, users should prefer short-lived development credentials.
Limited Use disclosure
HeaderPilot's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only for the extension's single user-facing purpose, is not transferred except as necessary to apply user-configured headers to user-selected websites, is not used for advertising, and is not made available for human review.
Changes
If this policy changes, the effective date will be updated and the revised policy will be made available through the Chrome Web Store listing.
Contact
For privacy questions, contact the developer using the support contact published on HeaderPilot's Chrome Web Store listing.