Legal

JSONPeek Privacy Policy

Last updated 2026-07-11

The short answer

JSONPeek formats and converts JSON locally, starts with no website access, makes no network requests, and collects nothing.

JSONPeek formats raw JSON pages into a foldable, searchable tree and converts JSON, YAML and CSV — entirely on your machine. Local-first is the whole product, not an afterthought.

What we collect

Nothing. JSONPeek has zero telemetry and makes no network requests at all: no analytics, no usage data, no crash reports, no account. It collects nothing about the pages you visit or the JSON you view or convert. This is enforced in the build, not just promised — a red-line check fails the release if any outbound-network or remote-code pattern appears in the shipped code, and an end-to-end test asserts the viewer makes zero outbound requests.

What JSONPeek stores, and where

  • Your language choice (if you pick one instead of following the browser) is stored locally on your device using the browser's extension storage (storage.local, under the key jsonpeek.locale.v1). It never leaves your machine and is not synced across devices.
  • The sites you allow automatic formatting on are held by the browser's own permission system, not by us. You grant and revoke them yourself, and revoking takes effect immediately.
  • The JSON you view or convert is processed in memory in the current tab and is never stored, uploaded, or transmitted.

Permissions and why they are requested

JSONPeek installs with no access to any website — no host permissions and no declared content scripts, so it can see no page until you ask it to.

  • activeTab, scripting — let you format the JSON on the current tab when you click the toolbar icon. This is a one-time action on that single tab, with no permanent access.
  • storage — stores your language choice locally (see above).
  • Optional host access (<all_urls>) — requested only if you turn on automatic formatting, either for a single site (from the popup) or for all sites (from onboarding or settings). The browser shows its own confirmation prompt, and you can revoke it at any time. JSONPeek does not read data from sites you have not authorized, and it only ever touches a page that is raw JSON — never an ordinary web page.

Remote code

JSONPeek contains no remotely-hosted code. All executable logic ships inside the extension package; there is no eval, no external script, and no remote configuration. The JSON, YAML and CSV you give it are treated as data, never as code.

Feedback you send us

The extension itself sends nothing. If you want to reach us, feedback is handled on the product website; the extension does not contain a reporting form and transmits no diagnostics.

Changes to this policy

If this policy changes materially, we update the Last updated date above and revise the extension's listing on the stores where it's published. Continued use after an update means the revised policy applies.

Contact

Questions: email [email protected].

Data controller / legal entity: Extensionsly — MDL Asia Sdn Bhd (Co. No. 1517967-A), Malaysia.

Not affiliated with or endorsed by Google, Microsoft, or Mozilla.

Extensionsly — MDL Asia Sdn Bhd (Co. No. 1517967-A), Malaysia