Last updated: August 21, 2026
"Capture to Faraday" ("the extension") is a browser extension that lets you capture manual pentest findings — with an optional screenshot — directly into your own self-hosted Faraday instance, without leaving the page you are testing.
This document explains what data the extension touches, where it is stored, and who it is shared with.
| Data | Why it's collected | Where it's stored | Shared with |
|---|---|---|---|
Faraday server URL (baseUrl) |
So the extension knows which Faraday instance to talk to | chrome.storage.local (your device only) |
Nowhere — used only to build requests to your own server |
| Faraday API token | To authenticate requests on your behalf | chrome.storage.local (your device only) |
Sent only to your own Faraday server, as an Authorization header |
| Faraday username, last verified date | Cosmetic ("Connected as …") and to confirm the token is still valid | chrome.storage.local (your device only) |
Not shared |
| Last used workspace name | Convenience — pre-fills the workspace selector next time | chrome.storage.local (your device only) |
Not shared |
| Active tab's URL, title, and a screenshot of the visible page | To let you attach page context and visual evidence to a finding | Kept only in memory while the extension popup is open; discarded when you close it without submitting | Sent to your own Faraday server only if you click Submit |
| Finding text you type (title, description, severity, CWE, tags, etc.) | This is the content of the vulnerability report you're creating | Kept only in memory while the popup is open | Sent to your own Faraday server only if you click Submit |
The extension never reads or stores your browsing history, cookies, or the content of any page other than the one active tab you are actively working on when you open the popup.
All network requests the extension makes go to the Faraday server URL that you entered in the extension's Options page — nowhere else. The extension has no backend of its own, no analytics SDK, and no crash-reporting service. There is no telemetry of any kind.
Once you submit a finding, the report (and screenshot, if included) is stored on your Faraday server, subject to that server's own retention and access policies — the same as if you had entered it directly through the Faraday web UI.
activeTab — lets the extension read the URL/title of the tab you're on and capture a screenshot of it, only when you actively open the extension popup. It cannot access other tabs or run in the background without your interaction.storage — lets the extension save your connection settings (server URL, token) locally so you don't have to re-enter them every time.chrome://extensions.The extension does not request broad access to all websites, browsing history, cookies, or any permission beyond what's listed above.
The extension does not integrate with, or send data to, any third-party service (no analytics, no advertising networks, no crash reporting, no cloud sync). The only external endpoint it ever contacts is the Faraday server address you provide.
This extension is a professional security-testing tool and is not directed at children. It does not knowingly collect data from children.
If this policy changes, the "Last updated" date above will be revised and the new version published at the same location. Material changes will also be noted in the extension's changelog.
For questions about this privacy policy or the extension's data handling, contact: dgiannico@faradaysec.com