Privacy Policy: Watch Glyph
Watch Glyph is a Chrome extension that checks the hostname of the page you're viewing for mixed or look-alike writing scripts (a common homoglyph / IDN spoofing technique). This policy explains exactly what the extension does and does not do with your data.
What the extension accesses
-
The active tab's URL, specifically its hostname
(e.g.
example.com), every time a tab is activated or navigates. This is required to run the script/homoglyph check, to keep the toolbar icon in sync with the page you're on, and to show a one-time system notification if a tab's domain looks unsafe, so you find out without needing to open the popup. - Nothing else. The extension never reads page content, DOM, form fields, cookies, or browsing history, and it has no access to any page beyond the URL bar.
What is stored, and where
The extension stores two small settings locally on your device, using
Chrome's storage.local API (never storage.sync,
so this data does not travel with your Google account or leave your
device):
- Your chosen interface language (English, Croatian, German, or French).
- The list of hostnames you've marked "trusted" via the extension's popup.
Separately, the extension keeps a small in-memory note per open tab of which domain it last notified you about, purely so it doesn't repeat the same notification on every page reload. This is never written to disk and is lost the moment the tab closes or the browser restarts.
What is never collected
No analytics, telemetry, crash reporting, or usage tracking of any kind. No personal information, account details, or identifiers are collected.
Network activity
None. Watch Glyph makes zero network requests. Punycode decoding, Unicode script classification, and the confusable-letter and known-brand comparisons run entirely inside your browser using data files bundled with the extension itself. Nothing you browse is ever sent anywhere, to us or to any third party.
Sharing
Since nothing is collected or transmitted, nothing is ever shared, sold, or disclosed to third parties.
Data retention and deletion
Stored data (language choice, trusted-domain list) lives only in the extension's local storage on your device. You can clear it at any time by removing a domain from the trusted list in the popup, or delete everything by uninstalling the extension.
Why the extension asks for these permissions
-
tabs: to read the active tab's URL (address only, not content) so it can be analyzed, and to detect navigation/tab switches so the toolbar icon and notifications update automatically without you needing to click anything. -
storage: to remember your language choice and trusted-domain list locally between browser sessions. -
notifications: to show a system notification when a tab's domain looks unsafe. No content is included beyond the domain name itself and the same warning text shown in the popup.
Children's privacy
Watch Glyph is not directed at children and does not knowingly collect data from anyone, regardless of age, because it does not collect data at all.
Changes to this policy
Any future changes to this policy will be posted here with an updated "Last updated" date.