Skip to content
Loupewire
  • Guides
  • Support
Add to Chrome

Privacy Policy

Effective date: 2026-09-20

In short

  • The extension processes everything on your device. Captured requests, headers, cookies and bodies stay in the tracker window and are never sent anywhere.
  • The extension makes no network requests of its own. No telemetry, no analytics, no crash reporting, no account.
  • This website, the pages you are reading now, uses Google Analytics to count visits. The extension does not.

This policy covers two separate things: the Loupewire browser extension and the website at loupewire.github.io. They behave differently, so each has its own section. "We" means the people who publish Loupewire under the loupewire organization on GitHub.

1. The extension

1.1 What the extension handles

Loupewire records the HTTP requests the browser makes while its tracker window is open: URLs, methods, status codes, request and response headers, cookies, request bodies, timing and redirects. This data routinely contains secrets such as session cookies and authorization tokens. That is why the extension is built the way it is:

  • Captured traffic lives in the memory of the tracker window and nowhere else. It is discarded when the window closes. It is never written to disk unless you export it yourself, and it is never transmitted.
  • Masking happens on your device. Values matching your mask patterns, and a built-in preset covering the usual secret-bearing headers and cookies, are hidden on screen and in every export. Masking is a display and export transform; the extension does not store masked or unmasked copies.
  • Exports are files you create. A HAR or JSON export, or a copied request, is produced on your device and handed to you. Where it goes after that is up to you.

1.2 What the extension stores

Only your own configuration, in the browser's local extension storage on your device: track, skip, block and mask patterns, header rules, and settings such as theme and window preference. Nothing derived from observed traffic is stored: no history, no recently matched examples, no autocomplete built from captures. Uninstalling the extension removes this storage.

1.3 Network requests

The extension makes no network requests of its own. It observes requests that pages make; it does not originate any. There is no telemetry, no analytics, no crash reporting, no update check beyond the browser's own extension updates, no cloud sync, no AI service, and no account.

1.4 Permissions and why each one is needed

Permission Why the extension asks for it
webRequest Observes request and response metadata (URL, method, headers, status, timing, redirects, request body) so the tracker window can list and display them. Listeners are non-blocking and registered only while the tracker window is open.
declarativeNetRequest Applies your header rules and block patterns as session rules. Rules exist only while the tracker window is open and are removed when it closes.
storage Saves your patterns, header rules and settings in local extension storage. Captured traffic is never stored.
Host access to all sites (<all_urls>) Traffic from any site you visit must be observable for the tracker to show every tab in one window, and header rules must apply to whichever host you target. No content script is injected into any page.

The extension injects nothing into websites. Every surface it has (the tracker window and the options page) is a page of the extension itself.

1.5 Retention

Captured traffic: for as long as the tracker window is open, subject to a per-session ceiling after which the oldest records are dropped. Configuration: until you change it or uninstall the extension. We hold nothing on our side, because nothing reaches us.

2. This website

2.1 Google Analytics

This website uses Google Analytics 4 to count visits, see which pages are read and which install button is clicked. Google Analytics sets cookies in your browser and records your approximate location, device and browser, the pages you visit and how you arrived. It runs on the website only; the extension never loads it.

Google's handling of this data is described in Google's privacy policy. You can stop it with a content blocker, by disabling cookies for this site, or with the Google Analytics opt-out browser add-on.

2.2 Embedded video

The home page contains an intro video hosted on YouTube. The page shows a static poster image and loads YouTube's player only when you click it, through YouTube's privacy-enhanced embed, which does not use cookies to personalize what it shows you. Once you click, Google's privacy policy applies to the player.

2.3 Hosting

This website is served by GitHub Pages. GitHub may log the IP address of visitors for security purposes, as described in that page. Apart from Google Analytics and the video player, the website loads no third-party script, font or resource.

2.4 Support and bug reports

Support happens in public, in the loupewire-support repository on GitHub. Anything you post there, including files you attach, is public and governed by GitHub's privacy statement. Please mask or remove secrets before attaching an export; the extension's masked export exists for exactly that.

3. Children

Loupewire is a developer tool and is not directed at children under 13. We do not knowingly collect information from children; since the extension collects nothing at all, there is nothing to collect.

4. Your rights

If you are in the European Economic Area, the United Kingdom, California or another region with data protection rights, you have rights to access, correct, delete and object to the processing of personal data about you. For the extension there is nothing to exercise them on, because we hold no data. For the website, the only data is what Google Analytics collects; the controls in section 2.1 stop that collection, and you can ask us about it through the contact below.

5. Changes to this policy

When the extension's behaviour changes in a way this policy describes, for example if a paid tier adds a license check, this policy is updated in the same release and the effective date at the top changes. Material changes are also noted in the release notes on the store listing.

6. Contact

Questions about this policy: open an issue in loupewire-support, or start a thread in its Discussions.

Loupewire

HTTP request inspector, header editor and masked HAR export for Chrome, Edge & Chromium browsers

Everything the extension captures stays on your device. No account, no telemetry.

Product

  • Guides
  • Support

Legal

  • Privacy Policy
  • Terms

Community

  • GitHub
  • Report a bug

© 2026 Loupewire. For Chrome, Edge & Chromium browsers.