MPmanhdev

Persona

Privacy Policy

Last updated

Persona is a browser extension that lets you present a different device identity to websites. It is built to work entirely on your device: no server, no analytics, no crash reporting and no accounts.

In short: your settings stay in Chrome's extension storage on your computer, the extension never sends anything on its own, and no data is sold, shared or transferred to anyone.

What the extension stores

  • Your settings: default device, per-site rules, custom devices you create, and preferences. Stored with chrome.storage.local on your computer, and synced by Chrome only if you have Chrome Sync enabled for extensions.
  • Per-tab choices, stored with chrome.storage.session, which Chrome clears when the browser closes.

What the extension reads

  • The URL of the tab you are looking at, in memory only, to decide which device rule applies and to show the site name in the popup. URLs are never stored and never sent anywhere.

What the extension sends

  • Nothing automatically. Persona has no server, no analytics, no crash reporting and no accounts.
  • When you click Run check in the scorecard, the inspected tab makes one request to a header-echo service (by default https://httpbin.org/headers; you can change it in Settings) so that the extension can show you which request headers a server receives. That request contains the spoofed headers and no personal data. The response is displayed to you and discarded.

What the extension changes on websites

  • With a device active for a tab, Persona rewrites the User-Agent, Accept-Language and sec-ch-ua* request headers of that tab and injects a script that makes JavaScript report the same device. It does not read, collect or modify page content.

Third parties

  • No data is sold, shared or transferred to third parties.

Permissions

Every permission the extension asks for, and what it is used for:

PermissionWhy
declarativeNetRequestRewrites the User-Agent, Accept-Language and sec-ch-ua* request headers to match the device you picked. Rules are generated from your choices and removed when you switch back to your real identity. No blocking or redirect rules are used.
Host permission: all URLsHeader modification needs host access for every site you want to test, and you may pick any site. The same access lets the device script run on the pages you are spoofing. The extension does nothing on a page unless a device is active for that tab.
scriptingInjects, at document start, a self-contained function that makes navigator, userAgentData, screen, devicePixelRatio and pointer/hover media queries report the chosen device. The scorecard also uses it to read those values back. The code ships inside the package; nothing is fetched remotely.
webNavigationTells the extension the moment a navigation commits so the device script can run before any page script, in every frame.
tabsReads the active tab's URL and id to pick the right rule (tab override, then site rule, then default), show the current site in the popup, set the per-tab toolbar badge, and reload the tab after you switch device.
storageSaves your settings: default device, site rules, custom devices and preferences (storage.local). Per-tab overrides live in storage.session and vanish when the browser closes.

Remote code: none. All JavaScript is bundled in the package. The extension loads no remote scripts, uses no eval and fetches no WebAssembly from the network.

Data usage

As declared in the Chrome Web Store privacy practices form:

Data typeCollected
Personally identifiable informationNot collected
Health informationNot collected
Financial and payment informationNot collected
Authentication informationNot collected
Personal communicationsNot collected
LocationNot collected
Web historyNot collected. Tab URLs are read in memory to pick a rule, never stored or transmitted.
User activityNot collected
Website contentNot collected
  • User data is not sold or transferred to third parties, outside of the approved use cases.
  • User data is not used or transferred for purposes unrelated to the extension's single purpose.
  • User data is not used or transferred to determine creditworthiness or for lending purposes.

Changes to this policy

If this policy changes, the new version is published at this URL with an updated date.

Contact

Manh Pham · manhpv151090@gmail.com