Manifest V3 Certified • Zero Telemetry

Privacy Policy

Last Updated: September 3, 2026 • Extension Version: 10.5

100% Local In-Browser Processing: Source Code Viewer does not collect, store, transmit, or monetize your personal data or browsing activity. All source code extraction, syntax highlighting, secret scanning, source map reconstruction, and ZIP file generation happen entirely on your computer inside your browser's local sandbox.

1. Zero Telemetry & Data Collection Policy

Source Code Viewer (https://gokuthug1.github.io/scv) is engineered from the ground up as an offline-capable developer utility. We adhere strictly to the principle of data minimization:

  • No Tracking Scripts: The Extension contains zero telemetry SDKs, zero analytics scripts (such as Google Analytics, Segment, or Mixpanel), and zero tracking pixels.
  • No Personal Identifiers: We do not collect, read, or request names, email addresses, phone numbers, IP addresses, geolocation data, or hardware identifiers.
  • No Browsing History Recording: We do not log, retain, or transmit lists of URLs visited, search histories, or session timestamps.
  • No Sale or Transfer of Data: We do not sell, rent, license, or transfer user information or website content to data brokers, ad networks, or third parties under any circumstance.

2. Website Content Accessed & Scope of Processing

To inspect, format, and audit client-side web assets, the Extension accesses client-side files ephemerally from the web page currently loaded in your browser tab. Access is triggered only when you deliberately invoke the Extension (by clicking the toolbar action, opening the Side Panel, or clicking a context menu command):

  • DOM Markup & Documents: Rendered client-side HTML DOM trees and document metadata.
  • Stylesheets: Linked external stylesheets (<link rel="stylesheet">), inline style blocks (<style>), and encapsulated Shadow DOM styling.
  • Scripts: Linked external script files (<script src="...">), dynamic JavaScript chunks, and inline script tags.
  • Media & Binary References: Image sources (<img>), audio/video tags, web fonts, and linked web application manifests.
  • Source Maps: Publicly exposed source map files (.map) referenced by scripts or stylesheets, used exclusively to unbundle original development file trees for inspection.
  • Browser Storage Dump (Inspection Feature): When inspecting a page, readable client-side localStorage, sessionStorage, and active document cookies are structured into a downloadable state.json snapshot for local debugging purposes.

Ephemeral Processing Guarantee: All extraction, lexical tokenization, regex-based secret scanning, CSS coverage analysis, and beautification are computed in local browser memory and dedicated client-side Web Workers (js/worker.js). No website content is ever transmitted to an external server or proxy.

3. Local Storage, Caching, and IndexedDB

The Extension uses native browser storage APIs exclusively on your machine for session state and offline persistence:

  • chrome.storage.local: Temporarily holds serialized source data snapshots when passing inspected files between the extension popup, background service worker, and full-screen viewer tabs. These transient entries are automatically cleared once consumed.
  • IndexedDB (SourceCodeViewerDB): An isolated browser database that stores local code sessions, uncompressed binary assets (images, fonts), and reference snapshots for the local Diff Snapshot feature. Cached sessions in IndexedDB are automatically pruned after 2 hours of inactivity.
  • chrome.storage.sync: Stores non-personal configuration preferences (e.g. selected UI theme, line counter toggles, window mode, custom CSS overrides). This configuration is automatically synced by Chrome to your signed-in browser profile.

4. User-Initiated Third-Party Cloud Exports (Optional)

The Extension contains optional cloud and IDE export integrations designed to help developers test code snippets. These exports are entirely manual and never execute automatically.

When you explicitly click an export button, only the code snippets currently open are packaged and forwarded directly to the selected service under your direction:

  • VS Code Desktop: Packages an organized project archive (.zip) locally to your disk and initiates a local protocol handler (vscode://file/...).
  • VS Code for Web (vscode.dev): Navigates to official GitHub-hosted repository links on vscode.dev.
  • CodePen / JSFiddle / StackBlitz: Transmits an explicit HTTP POST form containing your selected HTML, CSS, and JS to the respective platform in a new browser tab.
  • GitHub Gist Export & Personal Access Tokens (PAT): If you choose to export snapshots to GitHub Gists, you may supply a GitHub Personal Access Token in Settings. This token is saved exclusively in your browser's secure chrome.storage.sync area. It is transmitted solely over encrypted HTTPS directly to GitHub's official API (https://api.github.com/gists) when creating your requested Gist.

5. Chrome Manifest V3 Permissions Justifications

Under Google Chrome's Manifest V3 standard, the Extension declares permissions strictly required for its single purpose as a developer inspection and export tool:

Permission Technical Justification
activeTab Grants temporary, user-invoked access to inspect the active browser tab when you click the extension icon or context menu item.
scripting Executes the local content extraction bridge (js/content-bridge.js) inside the web page context to read rendered DOM elements, stylesheets, and scripts without altering page behavior.
storage Saves user theme preferences, custom CSS overrides, and display configurations in chrome.storage.sync, and transfers extraction sessions via chrome.storage.local.
downloads Enables users to download individual extracted source files, unbundled source maps, and complete website asset ZIP archives directly to local disk.
contextMenus Registers quick right-click shortcuts ("Open Source Code Viewer", "Open in Side Panel", "Settings") for developer convenience.
unlimitedStorage Prevents browser quota errors in IndexedDB (SCVDB) and local cache when extracting large single-page applications or complex source map directory trees.
tabs Opens the full-screen viewer and options pages in dedicated browser tabs and captures the active tab title and URL to name downloaded archives accurately.
sidePanel Enables docking the source code viewer directly into Chrome's native Side Panel for simultaneous side-by-side inspection while browsing.
<all_urls>
(Host Permission)
Allows the background service worker to fetch external stylesheets, scripts, remote source maps, and binary assets referenced across diverse third-party CDNs and domains that would otherwise be blocked by page-level CORS restrictions.

6. Remote Code Declaration

Source Code Viewer complies strictly with Chrome Web Store policies prohibiting remote code execution:

  • All JavaScript (including parsers, formatters, lexers, and scanners), CSS stylesheets, HTML files, and graphic assets are 100% packaged locally within the extension package.
  • The Extension does not execute dynamic code via eval() or new Function().
  • No scripts, stylesheets, or dependencies are loaded from external CDNs, remote endpoints, or third-party cloud buckets.

7. Voluntary Donations & Third-Party Links

The Extension contains optional links to external developer support pages (e.g. Cash App). Clicking these links navigates you to an external payment processor in a standard browser tab. Source Code Viewer does not collect, handle, or store credit card numbers, bank accounts, or financial transaction details.

If you prefer not to see donation links, you can hide them entirely in the Extension Settings by enabling the Hide Donation Links option.

8. Updates to This Privacy Policy

We may update this Privacy Policy periodically to reflect new browser capabilities, Chrome Web Store policy updates, or version releases. Any revisions will be published to the canonical privacy URL (https://gokuthug1.github.io/scv/privacy) with an updated revision date at the top of the document.

9. Inquiries and Open Source Verification

Source Code Viewer is transparent and open-source. Developers and security auditors are welcome to review the codebase, report issues, or submit inquiries: