Privacy Policy for Tiger WebProxy

Effective Date: September 28, 2026

Tiger WebProxy is a Chrome extension for authorized security testing. It helps users monitor, intercept, edit, and replay HTTP/HTTPS traffic from Chrome tabs or URL scope selected by the user.

1. Data the Extension Can Access

To provide its core functionality, Tiger WebProxy can access:

Captured traffic may contain authentication information, form data, user-provided content, personal communications, or other sensitive website content. Tiger WebProxy uses this data only for the inspection workflow requested by the user and not for advertising, analytics, or profiling.

Cookie access is used only to make browser session traffic visible inside the local Monitor and Repeater workflow. Tiger WebProxy does not use cookies for tracking, analytics, account identification, advertising, or cross-site profiling.

2. Data Storage

Traffic history and Repeater data are held in extension memory by default. When the user explicitly selects SAVE, Tiger WebProxy creates a bounded session archive, stores the latest archive in Chrome extension-local storage, and downloads the same archive as a .json file. Importing a .json file also makes that archive the latest local archive.

Session archives can contain URLs, headers, bodies, authentication information, form data, or other sensitive content captured from the user's scope. Monitor type selections, Scope URL patterns, and Notes are stored in extension-local storage. Current Scope tab identifiers and active Web Proxy, Intercept, and Scope toggle states use Chrome session storage and are cleared when the browser session ends.

Users can clear traffic with CLS, delete individual packets and Notes pages, replace the latest local archive, clear extension data in Chrome, or uninstall the extension. Downloaded .json files are outside extension storage and must be deleted or protected by the user.

Tiger WebProxy has no telemetry, analytics, advertising, account, or remote server upload feature.

3. Data Sharing and Transfer

Tiger WebProxy does not sell user data or automatically upload captured traffic, browsing data, notes, or testing data to the developer or analytics services. Captured data is processed locally in the user's browser. The developer does not receive captured data.

When the user forwards an edited request or selects Send in Repeater, the browser sends that request, including applicable headers, cookies, and body data, to the destination selected by the user. Users should verify the destination and contents before sending sensitive information.

Data is not used for personalized advertising, credit decisions, or sale to data brokers. Use is limited to the extension's single purpose and the Chrome Web Store Limited Use requirements.

4. Permissions

Cookie headers come from request-correlated debugger events. Missing values are not reconstructed from stored cookies or matched by URL. The extension does not request the cookies or webRequest permissions. Cookie data is not uploaded to the developer; user-directed requests may send applicable cookies to their destination as described above.

5. User Responsibility

Capture operates while Web Proxy is enabled. Scope tabs and URL patterns let users restrict capture. If no Scope tabs or URL patterns are configured, capture is not restricted by Scope.

Tiger WebProxy is intended only for systems, applications, and accounts that the user owns or is authorized to test. Users should protect exported files and avoid monitoring unrelated tabs or websites containing sensitive third-party data.

6. Changes

This Privacy Policy may be updated from time to time. Updates will be reflected on this page.

7. Contact

Questions about this Privacy Policy can be sent to soovwv@gmail.com.