Privacy
Fusebox privacy policy
Last updated August 8, 2026. Fusebox is a local-first website analysis extension. We do not sell browsing history, page content, or report data, and we do not use the brochure site for targeted advertising. This policy explains the exceptions: the specific external lookups, optional cloud AI, checkout, and license services described below.
The short version
The extension reads the active tab to produce a report. Page inspection and deterministic verdicts run locally, while a standard scan also sends the site's domain, hostname, or resolved IP address to the lookup services listed below; those lookups never receive the page's HTML. Two opt-in flows are different: cloud AI, where prompts and selected report context leave the browser, and a diagnostic session, where redacted page content is shared with Fusebox support until the session ends. Use local or on-device AI and leave diagnostics off when that matters.
What the extension can access
Fusebox runs on HTTP and HTTPS tabs so it can inspect the page you choose to analyze. The following information is collected by the extension and processed locally unless this policy says otherwise:
- The active tab URL, hostname, title, DOM, page HTML, headings, links, forms, images, scripts, stylesheets, Open Graph metadata, Twitter card metadata, and JSON-LD.
- Technology, tracker, SEO, origin, hosting, history, and security-header reports derived from the active tab or public lookups.
- Network requests and console entries available to the extension's debugging tools.
- Report results, deterministic verdicts, prompts, conversations, preferences, feature flags, API keys, and license state in browser memory or browser storage.
Fusebox does not upload the active tab's HTML or browsing history to a Fusebox server as part of the deterministic report. The debugging tools can expose request URLs, response details, and console data from the active tab; treat those tools as potentially sensitive. The one flow that does send page content to a Fusebox server is a diagnostic session you join yourself, described below.
External services
These are the services Fusebox can contact. A service is contacted only for the purpose and in the circumstances shown. The providers operate independently and their own policies govern information they receive, including ordinary network metadata such as an IP address and user agent.
| Service | Purpose | Data sent | When |
|---|---|---|---|
Google Public DNS (dns.google) Google Public DNS privacy | Resolve A, AAAA, MX, TXT, NS, CNAME, and SOA records, and resolve a hostname before an IP report. | The target domain and the requested DNS record type. | When a DNS or IP report runs. |
RDAP.org RDAP.org privacy considerations | Retrieve domain registration data such as registrar, registration dates, status, and name servers. | The target domain. | When a WHOIS/domain report runs. |
IPinfo (ipinfo.io) IPinfo privacy policy | Provide IP, ASN, network-owner, and location context for the inspected hostname. | The resolved IP address and, if supplied by the user, an IPinfo token. | When the IP/hosting report runs. |
ipwho.is ipwho.is privacy policy | Provide key-free IP, network-owner, and location context when IPinfo returns nothing usable. | The resolved IP address of the inspected site. | Only when the IP report falls back from IPinfo. |
RIPEstat RIPE NCC privacy statement | Provide an ASN fallback when IPinfo does not return ASN data. | The resolved IP address. | Only when the IP report needs an ASN fallback. |
Team Cymru IP-to-ASN (queried over Google Public DNS) Team Cymru privacy policy | Corroborate the network owner and ASN for the inspected site's IP address. | The inspected site's resolved IP address, encoded in a DNS TXT query name answered by Team Cymru's name servers. | When the IP report enriches or corroborates ASN data. |
Internet Archive Wayback Machine Internet Archive privacy information | Retrieve historical capture dates, counts, and snapshot URLs for a domain. | The target domain. | When the history report runs. |
crt.sh (Sectigo certificate transparency search) Sectigo privacy policy | Retrieve certificate history, issuers, and subject alternative names published in public certificate transparency logs. | The target domain, as a wildcard certificate search query. | When the TLS/certificate report runs. |
urlscan.io urlscan.io privacy policy | Retrieve the most recent public scan records and malicious/benign verdicts for the domain. | The target domain and, if supplied by the user, a urlscan.io API key. | When the urlscan report runs. |
MDN HTTP Observatory (Mozilla) Mozilla privacy notice | Grade the target site's security headers. | The target hostname. Mozilla runs the scan from its own infrastructure, so the inspected site receives a request from Mozilla rather than from the user. | When the security-header grade report runs. |
Cloudflare security DNS and Quad9 Cloudflare and Quad9 privacy policies | Check whether independent blocking DNS resolvers refuse to resolve the domain, as a threat-consensus signal. | The target domain. | When the threat report runs. |
URLhaus (abuse.ch) abuse.ch privacy policy | Check the host against known malware-distribution URLs. | The target hostname and the user's URLhaus Auth-Key. | Only when the user has configured a URLhaus Auth-Key. Without a key the reputation report reports 'not configured' and no request is made. |
Fusebox license service (Cloudflare Workers and D1) Cloudflare privacy policy | Run checkout orchestration, issue and validate licenses, and support restore/manage flows. | For validation: license key, installation ID, and extension version. For purchase: email, checkout/license records, a short campaign source code, and an optional buyer-selected source answer. Cloudflare may also receive standard request and security metadata. Settings exposes an advanced license Worker URL; if the user replaces the Fusebox default, validation data is sent to that configured endpoint instead. | When a user buys, activates, restores, or validates a Fusebox license. |
Fusebox brochure page counter (Cloudflare Workers and D1) Cloudflare privacy policy | Measure an aggregate daily count of brochure page routes and bounded launch-channel codes at the edge. | A UTC day, normalized page path, and bounded campaign code. The counter does not store query strings, referrers, cookies, IP addresses, or visitor identifiers. | For brochure GET/HEAD page requests when the page counter is configured. |
Fusebox self-hosted Rybbit analytics (ry.fusebox.dev) Rybbit privacy information | Measure brochure page traffic, visitor journeys, acquisition sources, device categories, approximate location, and outbound-link use. | The brochure hostname, path, full query string, page title, referrer, language, screen dimensions, and outbound-link destination, text, and target when an outbound link is clicked. The service also receives the request IP address and user agent; Rybbit uses them to derive device/browser/OS and approximate location and to generate a pseudonymous visitor identifier. The deployed tracker creates a random rybbit-visitor-id in local storage, although the current production configuration does not include that value in page-view requests. | The client script loads on fusebox.dev and www.fusebox.dev page views except /admin paths. The current public configuration enables page views, SPA navigation, query parameters, and outbound-link tracking; session replay, error tracking, web vitals, button/copy/form tracking, and feature flags are off. |
Fusebox community observations (Cloudflare Workers and D1) Cloudflare privacy policy | Accept an explicit, opt-in contribution of minimized aggregate technology, hosting, tracker, security, and risk signals. | Registrable domain, observation date, extension version, normalized signal IDs, optional security grade, and the inspected site's resolved IP address. The contribution also carries a stable contributor ID derived from the local installation ID by a one-way hash, and the service records the contributor's IP address at the edge. That attribution exists so abusive contributions can be traced, removed, and blocked; it is not joined to license records and is not used to build a browsing profile. No page HTML, full URL, source, cookies, prompts, or raw network data. Community calls reuse the advanced license Worker URL, so replacing that default sends this data to the configured endpoint instead of Fusebox. | Only after the user enables community sharing and presses the contribution action for a report. |
Fusebox diagnostic sessions (Cloudflare Workers) Cloudflare privacy policy | Share a short-lived, redacted diagnostic snapshot with Fusebox support or QA to reproduce a problem. | While a session is active the extension uploads, roughly every five seconds, redacted page HTML (capped per document), the report set and verdict, DOM metadata, console entries, network request summaries, the page domain and its URL with query string and fragment removed, the extension version, and a one-way hash of the installation ID. Redaction removes values that look like credentials, tokens, cookies, and API keys, and strips query strings from URLs, but it is pattern-based and cannot guarantee that every secret rendered into a page is caught. The advanced diagnostic Worker URL is user-editable (and defaults to localhost in the development configuration), so these snapshots go to the exact endpoint shown in Settings. | Only after the user reviews the Worker URL and enters a six-digit pairing code under Settings, Advanced, Admin diagnostics. The panel shows a persistent sharing indicator, the expiry time, and a stop control, and the session expires on its own. |
Stripe Checkout Stripe privacy policy | Process a payment and provide payment status and receipt information to the license service. | Email, payment, and billing details entered into Stripe's hosted checkout. Fusebox does not receive full payment-card numbers. | When a purchase is completed through Fusebox checkout. |
OpenAI API OpenAI business/API privacy information | Optional cloud AI for chat and narrative analysis when the user supplies an OpenAI API key. | The user's prompts and conversation, the current URL/domain, and any report or active-tab context included in the AI request. | Only when the user selects OpenAI cloud AI. |
Vercel AI Gateway Vercel privacy notice | Optional gateway for cloud AI models when the user supplies a Vercel AI Gateway key. | The user's prompts and conversation, the current URL/domain, and any report or active-tab context included in the AI request. The gateway may route the request to the selected model provider. | Only when the user selects Vercel AI Gateway cloud AI. |
Ollama Ollama privacy policy | Optional local AI endpoint for chat and narrative analysis when the user selects Ollama. | The user's prompts and conversation, the current URL/domain, and any report or active-tab context included in the AI request. | Only when the user enables BYO-key AI mode and selects Ollama. |
LM Studio LM Studio privacy policy | Optional local AI endpoint for chat and narrative analysis when the user selects LM Studio. | The user's prompts and conversation, the current URL/domain, and any report or active-tab context included in the AI request. | Only when the user enables BYO-key AI mode and selects LM Studio. |
Chrome Prompt API / Chrome model delivery Chrome Prompt API documentation | Optional on-device AI and availability or download of the browser-managed model. | Fusebox sends prompts and selected context to the browser's on-device model. Chrome may download model assets after the user consents; Fusebox does not send the report to its own server in this mode. | Only when the user enables on-device AI and Chrome makes the Prompt API available. |
AI modes
Deterministic snapshot
Runs in the extension from the evidence already collected. It does not require a hosted LLM.
Chrome on-device Prompt API
Runs on the device after the user consents to model availability or download. Fusebox does not send the report to its own server in this mode. Chrome may fetch model assets under Google's browser policies.
OpenAI or Vercel cloud AI
Requires a user-supplied key. The provider can receive the user's prompts, conversation, current URL/domain, and the report, page, network, or console context selected by the AI request. Review the provider's policy before sending confidential information.
Ollama or LM Studio
Sends requests to the local endpoint configured by the user, usually on localhost. Fusebox does not route these prompts through its servers; the local provider's own behavior is outside Fusebox's control.
What we retain
Browser storage
Preferences and AI settings are stored in the browser's local storage. Chat conversations are also stored locally so they survive reopening the extension. License state, the generated installation ID, and any advanced license or diagnostic Worker URL are stored in Chrome extension storage. The brochure may retain one short campaign code in session storage so a later checkout can identify a launch channel; it is cleared with the browser session. The brochure analytics script also creates a random rybbit-visitor-id in local storage. The current production configuration does not send that local value in page-view requests, but clearing fusebox.dev site data removes it. Fusebox does not receive your OpenAI, Vercel, IPinfo, Ollama, or LM Studio keys as part of extension storage.
Fusebox license records
The license service stores the email associated with a purchase, a license key, plan/status dates, checkout-session references, Stripe customer references where provided, a short launch-channel code, and an optional buyer-selected source answer. The installation ID and extension version are used to sign a validation response; they are not used to build a browsing profile.
Support messages
If you email support@fusebox.dev, we receive the information you choose to include, such as your email address, receipt, license key, screenshots, and a website URL. Please remove secrets or sensitive page content before sending a report.
Community contribution queue
If you enable community sharing and contribute a report while the service is unavailable, the minimized observation waits in extension storage for a later retry. The queue contains no page HTML, full URL, source, cookies, prompts, or raw network data. An accepted contribution may also return an anonymous, domain-scoped access pass so the extension can read bounded aggregate community results; the pass is stored locally and is not an account or contributor profile.
Community contribution records
A contribution is stored with the registrable domain, the observation date, the signal IDs, the inspected site's resolved IP address, a contributor ID derived from your installation ID by a one-way hash, and the IP address the contribution arrived from. Those last three exist so we can trace, remove, and block abusive contributions; they are not joined to license or checkout records and are not used to build a browsing profile. If you never enable community sharing, no such record is created.
Diagnostic session snapshots
If you join a diagnostic session with a pairing code, the redacted snapshots are held with the session record on the Fusebox Worker so support can review them. The session itself expires automatically. Ask support to delete a session's snapshots and we will.
Brochure analytics records
Fusebox stores the brochure analytics described below in its self-hosted Rybbit instance. No fixed production retention period is promised. Email support to ask about the current retention setting or to request deletion; we may need request details to locate pseudonymous records.
Local data can be removed by clearing the extension's stored data or by using the extension's own clear/delete controls where available. Fusebox retains purchase and license records for as long as reasonably needed to provide the product, prevent fraud, handle support, keep accounting records, and comply with law. External providers set their own retention periods; their policies are linked above.
Optional community sharing
Community sharing is off by default. If you enable it in the extension and press the contribution action, Fusebox sends a minimized observation containing the registrable domain, date, extension version, normalized technology/origin/hosting/tracker IDs, risk finding IDs, an optional security grade, and the inspected site's resolved IP address. The Worker stores aggregate counts, a per-domain/per-day receipt to avoid duplicate inflation, and a hashed short-lived access grant. It does not receive page HTML, full URLs, source previews, cookies, prompts, conversations, or raw network/console data through this feature.
Each contribution is also attributed. It carries a contributor ID derived from your installation ID by a one-way hash, and the service records the IP address the contribution arrived from. Both are stored with the contribution and are used to trace, remove, and block abusive contributions — a community dataset anyone can write to needs a way to undo a bad actor. They are not joined to your license or checkout records, are not used to build a browsing profile, and are never sold. Authorized administrators may inspect raw contribution attribution when investigating abuse and may purge or ban the contributor. The contributor ID is stable across your contributions by design; it cannot be reversed to your installation ID, and if you never enable community sharing it is never sent.
Community requests use the same Worker URL shown in the advanced license settings. The default is the Fusebox Worker. If you replace that URL, the contribution and aggregate-read requests described here go to the endpoint you configured instead; review it before enabling sharing.
Contributions are community signals, not proof that a website is safe, unsafe, malicious, or legitimate. You can leave the feature disabled and continue using local reports. Community reads are limited to aggregate data for the contributed domain, with a short-lived pass and bounded download quota to reduce scraping.
Diagnostic sessions
Diagnostic sharing is off by default and cannot start on its own. It begins only when you review the diagnostic Worker URL and enter a six-digit pairing code under Settings, Advanced, Admin diagnostics — a code we give you while helping with a specific problem. The Worker URL is user-editable and defaults to localhost in the development configuration, so snapshots go to the exact endpoint shown there. While the session is active the extension uploads a redacted snapshot roughly every five seconds: redacted page HTML with a size cap, the report set and verdict, DOM metadata, console entries, network request summaries, the page domain, the page URL with its query string and fragment removed, the extension version, and a one-way hash of your installation ID.
This is the most sensitive thing Fusebox can send, so it is worth being precise about the limits. Redaction removes values that look like credentials, tokens, cookies, and API keys and strips query strings from URLs, but it matches patterns rather than understanding the page, so it cannot guarantee that every secret rendered into a page body is caught. Do not join a session while a page shows information you would not send us. The side panel keeps a visible sharing indicator and the session's expiry time on screen the whole time, you can press Stop sharing at any point, and the session ends by itself when it expires.
Cookies, analytics, and sale of data
The brochure does not use advertising cookies. It has two separate first-party analytics paths. The Cloudflare Worker stores only an aggregate daily page-route count and a bounded campaign code such as hn or ext-paywall; that counter does not store query strings, referrers, cookies, IP addresses, or visitor identifiers. The site also loads a self-hosted Rybbit script from ry.fusebox.dev. Its current production configuration sends the hostname, path, full query string, page title, referrer, language, screen dimensions, and, after an outbound-link click, the link destination, text, and target. The service receives the request IP address and user agent and uses them to derive device/browser/OS, approximate location, sessions, and a pseudonymous visitor identifier. Session replay, error tracking, web vitals, button/copy/form tracking, and feature flags are currently disabled. Admin paths are skipped. Cloudflare may also process standard request, performance, and security metadata. Fusebox does not sell or rent browsing history, page content, report results, prompts, API keys, or analytics profiles.
Your choices and privacy requests
You can choose local, on-device, cloud, or off AI modes; omit the optional IPinfo, urlscan.io, and URLhaus keys; leave community sharing and diagnostic sessions off; and avoid sending sensitive page content to cloud AI. Review the advanced license and diagnostic Worker URLs before using them; replacing a default changes who receives the disclosed validation, community, or diagnostic data. Standard scans still contact the listed public lookup providers. To stop brochure analytics, block requests to ry.fusebox.dev; clearing fusebox.dev site data removes the tracker's local identifier. You can also ask us to delete associated self-hosted analytics records, although we may need request details to locate pseudonymous records. Fusebox-controlled remote endpoints use HTTPS. Advanced license and diagnostic URLs are used as entered; use HTTPS for any remote endpoint and reserve plain HTTP for a local service on your own computer. Depending on where you live, you may also have rights to access, correct, delete, or restrict the use of personal information. Email support@fusebox.devwith a privacy request. We may need to verify the request and may retain information required by law or legitimate security needs.
Changes and contact
We may update this policy when the product or its integrations change. The date at the top will change when we publish an update. Questions about this policy can be sent to support@fusebox.dev.