Privacy Policy — Capture to Faraday

Last updated: August 21, 2026

"Capture to Faraday" ("the extension") is a browser extension that lets you capture manual pentest findings — with an optional screenshot — directly into your own self-hosted Faraday instance, without leaving the page you are testing.

This document explains what data the extension touches, where it is stored, and who it is shared with.

1. Summary

2. Data the extension collects and why

Data Why it's collected Where it's stored Shared with
Faraday server URL (baseUrl) So the extension knows which Faraday instance to talk to chrome.storage.local (your device only) Nowhere — used only to build requests to your own server
Faraday API token To authenticate requests on your behalf chrome.storage.local (your device only) Sent only to your own Faraday server, as an Authorization header
Faraday username, last verified date Cosmetic ("Connected as …") and to confirm the token is still valid chrome.storage.local (your device only) Not shared
Last used workspace name Convenience — pre-fills the workspace selector next time chrome.storage.local (your device only) Not shared
Active tab's URL, title, and a screenshot of the visible page To let you attach page context and visual evidence to a finding Kept only in memory while the extension popup is open; discarded when you close it without submitting Sent to your own Faraday server only if you click Submit
Finding text you type (title, description, severity, CWE, tags, etc.) This is the content of the vulnerability report you're creating Kept only in memory while the popup is open Sent to your own Faraday server only if you click Submit

The extension never reads or stores your browsing history, cookies, or the content of any page other than the one active tab you are actively working on when you open the popup.

3. Where your data goes

All network requests the extension makes go to the Faraday server URL that you entered in the extension's Options page — nowhere else. The extension has no backend of its own, no analytics SDK, and no crash-reporting service. There is no telemetry of any kind.

Once you submit a finding, the report (and screenshot, if included) is stored on your Faraday server, subject to that server's own retention and access policies — the same as if you had entered it directly through the Faraday web UI.

4. Permissions the extension requests, and why

The extension does not request broad access to all websites, browsing history, cookies, or any permission beyond what's listed above.

5. Data retention and deletion

6. Third parties

The extension does not integrate with, or send data to, any third-party service (no analytics, no advertising networks, no crash reporting, no cloud sync). The only external endpoint it ever contacts is the Faraday server address you provide.

7. Children's privacy

This extension is a professional security-testing tool and is not directed at children. It does not knowingly collect data from children.

8. Changes to this policy

If this policy changes, the "Last updated" date above will be revised and the new version published at the same location. Material changes will also be noted in the extension's changelog.

9. Contact

For questions about this privacy policy or the extension's data handling, contact: dgiannico@faradaysec.com