Extension
Privacy policy
This covers the CrawlCheck browser extension. Every claim below is checkable by reading the source, and each one says which version it applies to.
What reaches crawlcheck.io, from version 1.0.0
- The domain you ask about, when you press “Two vantages”. The extension sends the site’s domain to
GET /api/flowto fetch CrawlCheck’s edge reading of it, then compares that reading with what your own connection receives. Only on that button; never in the background. No page content, no path, no cookies. - Anonymous usage counts, to
POST /api/ext/event: the event name (installed, updated, popup opened, a tool pressed, a verdict’s class counts), the extension version, a random install id created on your device, and small counters. Never a URL, a domain, page content, a licence key or anything typed. The server refuses any field that could carry one, and stores daily totals only. Switch it off with the checkbox in the popup footer; the choice is honoured at once. - Your licence key, if you enter one:
GET /api/licence/check, at most once every 24 hours, with the key and nothing else. - A Data Axle listing page, from version 1.0.1, only when you press “Data Axle listing” and have saved a licence key: the extension reads the phone number the current page declares, fetches Data Axle’s public search page for that number from your browser, and posts that search page and the site’s domain to
POST /api/nap/observe, so the site’s CrawlCheck report can show whether the business is listed. The server accepts it only for a domain on your licence. Without a saved key the answer is shown in the popup and nothing is sent.
Versions up to 0.9.1 sent none of the first two: they made only the licence check.
What stays on your device
- Measurements you run, held in the browser’s local and session storage. They are never sent anywhere and you can clear them by removing the extension.
- Your licence key, if you have one, the random install id, and your usage-count choice.
- The last run, so the popup reopens where you left it.
Requests to sites you measure
When you measure a page, the extension requests it as each named crawler and as your browser. Those requests are sent with credentials: "omit", so your cookies, sessions and logins are never attached. The extension identifies itself honestly and does not impersonate an operator’s crawler to obtain access it would not otherwise be given.
Sharing and sale
Nothing is shared with, sold or transferred to third parties; the usage counts stay at crawlcheck.io. Nothing is used for advertising, creditworthiness or lending, or to train anything. There is no remote code and no advertising network.
Permissions, and the feature each one exists for
declarativeNetRequest— a request cannot set its ownUser-Agentfrom a page, so a session rule is the only supported way to ask for a page as a named crawler. One rule exists at a time and it is removed in afinallyblock.scriptingandactiveTab— read timings and the rendered DOM of the tab you are looking at, when you ask. It reads and returns; it writes nothing to the page.tabs— read the active tab’s address so the popup measures the site you are on, and clear a tab’s saved check when it navigates away or closes.storage— the local items listed above.contextMenus— one right-click item.- Host access to all sites — you choose which site to measure and it is not a site we can predict. That choice is the entire function.
Support
For help with the extension, a bug report or a question, email hello@crawlcheck.io. What each tool measures and how to use it is on the extension page.
Changes and contact
Material changes are published on this page with the date they took effect. Questions: hello@crawlcheck.io.
Last updated 23 September 2026 (1.0.1: the Data Axle listing check; 1.0.0: Two vantages and anonymous usage counts). The extension currently published is version 0.9.1.