Verifiable, not just claimed.
Every privacy tool says “100% local”. This page is the receipts: exactly what Auto Blur reads, what it sends (almost nothing), why it asks for each permission, and — because honesty is the product — what blurring can not protect you from.
Network behavior — the complete list
The extension makes exactly one kind of network request, and only if you are a paying customer: an occasional call to autoblurai.com/api/restore to refresh your license code before it expires. It carries your signed license code and nothing else — no page content, no URLs, no settings. The code contains your purchase email, and the server receives ordinary connection metadata.
An extension without an activated code makes zero network requests. Ever. You can verify this yourself: inspect the extension service worker in browser developer tools. You can also inspect the packaged scripts; the bundled regex engine is reproducible from the supplied source and dependency lockfile.
Local detection and stored settings
- The content of any page you visit — all detection runs in your browser.
- Detected page content is not sent to our servers.
- Custom rules, site policies and settings use local or browser sync storage. Your browser provider handles sync when enabled.
- Revealed-item exceptions store SHA-256 hashes, short hints and scope information locally. Predictable values can be guessed; hashes are not encryption. Manual selected-text rules and backups can contain the selected text.
- Usage data: there is no analytics library, no telemetry, no error reporting, no usage tracking. License tokens contain the purchase email.
Every permission, and why
Auto Blur asks for the minimum Chrome allows for what it does:
storage— save your settings and rules locally (and sync them via your browser’s own sync, if enabled).idle— power the “blur when I step away” trigger.contextMenus— the right-click “Blur selection” item.activeTab— user-invoked controls on the current tab.tabs— route automation and shortcuts across tabs.alarms— license refresh and screen-share session cleanup.host access— content scripts must run on the pages you want blurred; that’s what a blur extension is. Content scripts run on supported web pages and frames, including background tabs.
Not requested: browsing-history permission, webRequest, cookies, downloads, nativeMessaging — none requested.
Licensing that respects privacy
Pro codes are Ed25519-signed tokens verified inside the extension against a bundled public key — activation works offline until the code expires. There is no account, no login, no server round-trip for each page scan. Periodic refresh requires a connection. The trade-off we accept openly: if you refund or cancel, your current code keeps working until its built-in expiry, because we have no remote kill switch into your browser — and we prefer it that way.
Honest limits — read this before trusting any blur tool
- Blur is visual, not redaction. The text stays in the page’s code: selectable, copyable, visible to screen readers and scrapers. Auto Blur protects against human eyes on your screen — shares, demos, shoulder surfing — not against software inspecting the page.
- Heavy blur beats light blur. Very low blur on short strings can in principle be reconstructed from a high-resolution screenshot. Keep intensity at the default or higher for anything that matters.
- Some corners of the web are unreachable by any extension: closed shadow DOM, certain sandboxed iframes, and non-web apps (native Zoom windows, Figma canvas). We document these instead of pretending.
- Screen-share detection sees browser-based shares (Meet, browser Zoom, Loom’s web capture). A share started from a native app is invisible to a browser extension — turn blur on manually before those.
Reporting a vulnerability
Found something? Email achleshavarshney@gmail.com with “security” in the subject. We respond within 48 hours, fix confirmed issues with priority over all other work, and will credit you in the changelog if you’d like.