Privacy Policy — HeaderHermit
Last updated: 27 September 2026
This Privacy Policy explains how HeaderHermit ("the extension", "we"), a browser extension for Google Chrome and other Chromium browsers published under the Forgeline developer brand, handles information. In short: the extension collects nothing, sends nothing, and makes no network requests of its own.
1. We do not collect any data
HeaderHermit has no account, no sign-up, no analytics, no crash reporting, no advertising and no remote configuration. It does not collect, transmit, sell or share any personal data, browsing history, website content or usage information. We never receive any of your data, because the extension never sends it anywhere.
2. What stays on your device
- Your profiles and rules (the headers you set, your mock responses and their settings) are saved
in your browser's extension storage (
chrome.storage.local) on this device. They are not synced to your Google account. - The result of the last rule update (for example, how many rules are active, or an error to show
you) is kept in memory (
chrome.storage.session) and cleared when the browser closes. - The sites you allowed are kept by the browser itself, as for any extension permission.
Removing the extension deletes all of this.
3. No network requests of its own
The extension's own pages and background code are forbidden by their Content Security Policy from connecting to any
server (connect-src 'none'), and the package contains no remote code. Our automated tests check this on
every build: they run the extension in a browser whose every outbound request is recorded, and require that the
extension caused none.
4. What the extension does on the sites you allow
- Header rules are applied by the browser's built-in rule engine (declarativeNetRequest) to requests your pages make anyway. The extension does not read the requests or their contents.
- Mocks: while the active profile contains a mock, a small script from the extension's package
runs on the sites you allowed and answers matching
fetch()and XMLHttpRequest calls with the response you wrote. Any request that is not mocked goes to the network untouched. The script only sees the address and method of a request the page itself makes, on your device, and never stores or sends them. - The extension works only on sites you allow: one at a time, or all sites if you choose "Allow on all sites". You can remove access at any time in the extension's settings.
5. Permissions
- declarativeNetRequestWithHostAccess — to add, change or remove request and response headers with the browser's built-in rule engine.
- storage — to save your profiles on this device.
- scripting — to run the extension's own mock script on the sites you allowed, only while a profile with a mock is on.
- activeTab — when you click the toolbar button, to read the current tab's address so the popup can offer "Allow on this site".
- Access to sites (optional) — never granted at install; you grant each site yourself, or all sites if you choose.
6. Import and export
Importing reads a file you choose, on your device. Exporting creates a file your browser saves where you tell it to. Neither sends anything anywhere.
7. Children
The extension is a developer tool, is not directed at children and collects no data from anyone.
8. Data security & retention
Because we don't collect or store your data on any server, there is nothing for us to breach, sell or retain. Your profiles remain in your browser until you delete them or remove the extension.
9. Changes to this policy
If a future version ever changes what is described here, this policy will be updated before that version is published, with a new "Last updated" date.
10. Contact
Questions? Email uamurtaza.apps@gmail.com.