# Header Pilot Privacy Policy

Last updated: July 16, 2026

Header Pilot is provided by ZHEMBER. This policy explains what data the extension handles, why it is needed, where it is stored, and whether it is shared.

## Data handled by the extension

Header Pilot handles the following data only to provide its request-header rule features:

- Rule configuration entered by the user, including group and rule names, URL patterns, selected tab or tab-group identifiers, request-header names, operations, and values.
- Browser context for open tabs and tab groups, including tab identifiers, titles, URLs, window identifiers, group membership, group names, and colors. This context is used to display available targets and compile tab-scoped rules.
- Temporary synchronization status, such as the number of active rules and configuration errors.

Header values may contain authentication information if the user deliberately enters credentials or tokens. Header Pilot does not request or generate such credentials, and users should avoid saving sensitive values on shared devices.

Header Pilot does not read page content, response bodies, form data, personal communications, or browsing history beyond the open-tab context needed for its visible tab and tab-group targeting features.

## How data is used

The extension uses this data only to:

- show, edit, validate, and organize the user's rules;
- identify the current or selected tab and tab group;
- compile enabled rules into Chrome Declarative Net Request rules; and
- set, overwrite, or remove request headers on requests that match the user's rules.

When a rule matches, the header names and values configured by the user become part of the outgoing request to the website selected by that rule. This transmission is initiated by the user's configuration and is necessary for the extension's single purpose. No copy is sent to the developer.

## Storage and retention

Durable rule configuration is stored locally on the user's device using `chrome.storage.local`. Synchronization status is stored in `chrome.storage.session` and may be discarded when the browser session ends. Open-tab context is otherwise processed in memory.

Configuration remains until the user edits or deletes it, clears the extension's storage, or uninstalls the extension. Header Pilot does not provide cloud synchronization or a developer-operated backup service.

## Data sharing, sale, and remote services

Header Pilot:

- does not transmit user data to the developer or developer-operated servers;
- does not sell or rent user data;
- does not share user data with third parties for advertising, analytics, creditworthiness, or any unrelated purpose;
- does not display personalized advertising; and
- does not permit humans to read user data.

The extension contains no analytics SDK and executes no remote code.

## Limited Use disclosure

Header Pilot's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's prominent, user-facing request-header rule features. It is not transferred for unrelated purposes, used for personalized advertising, or made available for human review except where required by law and permitted by applicable policy.

## Security

Header Pilot relies on Chrome's extension sandbox and storage APIs. Because local extension storage should not be treated as a secrets vault, users should avoid storing sensitive authentication values on shared or untrusted devices. The extension does not transmit data to developer-operated infrastructure.

## Changes to this policy

If Header Pilot's data practices change, this policy and the Chrome Web Store disclosures will be updated before the changed practices are introduced. Material changes will also be disclosed as required by Chrome Web Store policy.

## Contact

For privacy questions or deletion requests, contact hi.zhember@gmail.com. Users can delete all locally stored extension data by removing Header Pilot from Chrome or clearing the extension's stored data.
