Privacy Policy — Baseera Security Scanner

Effective Date: 22 April 2026 · Last Updated: 9 June 2026 · Contact: 0xbaseera@gmail.com

This Privacy Policy describes how the Baseera Security Scanner Chrome extension (the "Extension") collects, uses, stores, and shares information when you use it. By installing and using the Extension you agree to the practices described below.

1. What the Extension Does

Baseera is a passive web vulnerability scanner. When you click "Start Scan" on a webpage, the Extension reads the page's DOM (HTML, scripts, forms, headers exposed to JavaScript) to detect security weaknesses such as cross-site scripting, SQL injection patterns, leaked API keys, missing security headers, and 24 other vulnerability classes. The scan is user-initiated only — no automatic background scanning occurs.

2. Information We Collect

2.1 Information stored locally on your device

The Extension stores the following data in chrome.storage.local, which never leaves your device unless you explicitly log into a Baseera account (see § 2.2):

2.2 Information sent to the Baseera backend (only if you sign in)

If you are signed in, completed scan results are sent over HTTPS to the Baseera backend you have configured, so they appear in your Bugs Dashboard. Each transmitted record contains:

If you are not signed in, nothing is sent to any server. All scanning runs entirely on your device.

2.3 Information we do NOT collect

We do not collect, transmit, sell, or share any of the following:

3. How Information Is Used

Information collected by the Extension is used only to:

We do not use your data for advertising, profiling, resale, or any purpose unrelated to the single purpose of the Extension (passive vulnerability scanning).

4. Data Storage and Security

5. Third-Party Services

The Extension does not include third-party analytics, advertising, crash reporting, or tracking SDKs. The only network destinations the Extension contacts are:

The Baseera website at baseera-three.vercel.app (separate from the Extension itself) uses Vercel Analytics and Vercel Speed Insights to measure site performance and aggregate visitor counts. These are cookieless, do not use fingerprinting, do not track individual users across sessions, and do not collect personally identifiable information. We use them only to understand site traffic and Core Web Vitals so we can improve the experience. The Extension itself does not call Vercel Analytics.

6. Permissions Explained

PermissionWhy we need it
activeTabTo run scanners against the tab you choose to scan.
scriptingTo execute scanner functions inside the active tab's DOM.
storageTo remember your login, settings, and recent results locally.
tabsTo read the URL of the active tab and open the dashboard.
<all_urls> (host permission)Baseera is a security scanner — it must be able to run on any site you choose to scan. Scanning is always user-initiated.

7. Your Choices and Rights

8. Children's Privacy

The Extension is not directed at children under 13 and we do not knowingly collect data from children under 13.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date at the top. Continued use of the Extension after changes constitutes acceptance.

10. Contact


This extension is provided "as is" without warranty of any kind.

← Back to home