Google Chrome Web Store Developer Program Compliance Notice:
PaloQA ("we", "our", or "us") is dedicated to protecting user privacy and ensuring full transparency regarding data collection, handling, storage, and sharing. This Privacy Policy applies to the PaloQA Chrome Extension ("Extension") and our platform website (https://paloqa.palosite.com, operated in partnership with https://palosite.com).
1. Executive Summary & Core Principles
Local-First Sandbox Architecture: PaloQA processes and stores all recorded tests, scripts, visual regression baselines, and API logs 100% locally inside your Chrome browser sandbox (chrome.storage.local and IndexedDB).
No Central Analytics or Trackers: We do NOT run tracking scripts, Google Analytics SDKs, or third-party telemetry inside the extension.
No Data Monetization: We NEVER sell, rent, trade, or monetize any user data, network traffic, website content, or keystrokes to any third party under any circumstances.
2. Categories of Data Processed, Purpose, and Handling
A. User Activity Data (Keystrokes, Clicks, Hover Events)
Data Collected: Clicks, typing actions, scroll position, and form field interactions.
How It Is Collected: Captured temporarily only when you explicitly click "Record Flow".
Purpose & Usage: To assemble reproducible, automated end-to-end browser test plans.
Sensitive Inputs Exclusion: Password fields and sensitive input fields are automatically redacted at capture time. Passwords are never logged or stored on disk.
Sharing: Processed locally and NEVER shared with external third parties.
B. Website Content & DOM Data (HTML Elements, Text Nodes, Screenshots)
Data Collected: Visible text nodes, DOM element selectors, CSS class names, and webpage viewport screenshots.
Purpose & Usage: To execute test steps, locate interactive elements during playback, assert expected page states, and generate visual regression diff reports.
Sharing: Saved locally in browser storage. When using optional AI Test Plan Generation or AI Self-Healing features, DOM element maps and screenshots are sent to third-party AI LLM providers as detailed in Section 4.
C. Network Traffic & API Metadata (XHR / Fetch Interception)
Data Collected: HTTP request/response methods, headers, status codes, query parameters, latency durations, and JSON payload bodies.
How It Is Collected: Intercepted strictly via Chrome's secure Developer Tools Protocol (chrome.debugger API) during active audit sessions.
Purpose & Usage: To validate live API contract schema drifts against OpenAPI/Swagger specifications and Postman Collections.
Sharing: Processed 100% locally. API traffic and authentication headers are NEVER transmitted to external analytics servers or third-party databases.
D. User Settings & API Credentials
Data Collected: User preferences, target test URLs, execution concurrency limits, and user-provided LLM API Keys (Google Gemini API Key, Anthropic API Key, NVIDIA NIM API Key).
Storage & Handling: API keys and preferences are stored exclusively inside Chrome's secure, sandboxed storage (chrome.storage.local). They are encrypted by browser security and never stored on any remote cloud server maintained by PaloQA.
3. Data Storage, Security, and Retention
Storage Mechanism: All saved test plans, recordings, visual baselines, and configuration templates are stored locally on your device within Chrome's isolated Extension Storage Sandbox (chrome.storage.local) and browser IndexedDB.
Data Retention: Data remains stored locally on your device for as long as you use the Extension.
How Users Can Delete Their Data:
Click "Reset Data" inside the PaloQA Extension Settings screen.
Clear extension data via chrome://extensions > PaloQA > Storage > Clear Data.
Uninstalling the PaloQA Chrome Extension instantly and permanently purges 100% of stored local data and databases from your computer.
4. Disclosure of Data Sharing & Third-Party Service Providers
PaloQA operates on a strict zero-third-party advertising disclosure policy. All third-party data sharing is limited exclusively to user-initiated AI features as described below:
Third-Party Provider
Data Shared
Purpose of Sharing
Provider Privacy Policy
Google Gemini API (generativelanguage.googleapis.com)
Natural language test description, DOM element map, viewport screenshot (base64)
Generating structured test plan JSON & locating broken element selectors via AI
No Authentication Tokens Shared: Bearer tokens, cookies, session headers, and passwords are automatically stripped before sending DOM context to AI providers.
Direct Browser-to-API Calls: Requests travel directly from your local browser to the official provider endpoint over HTTPS. PaloQA operates zero intermediary proxy servers.
No Ad Networks or Data Brokers: User data is NEVER shared with advertising networks, data brokers, data resellers, or credit reporting agencies.
5. Children's Privacy Compliance (COPPA & GDPR)
PaloQA is a professional software developer and QA engineering tool. Our services are not directed at, intended for, or designed to attract children under 13 years of age. We do not knowingly collect, store, or solicit personal data from children under 13.
6. Compliance with Chrome Web Store User Data Policies
PaloQA strictly adheres to the Chrome Web Store Developer Program Policies, including Limited Use requirements:
We only request permissions necessary to deliver user-requested features (activeTab, storage, sidePanel, tabs, debugger, scripting).
We do not use or transfer user data for personalized, targeted, or behavioral advertising.
We do not allow human agents to read user data unless required for security investigations or legally compelled.
7. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect new features or legal requirements. Any updates will be published with an updated "Last Updated" date at the top of this policy document and made accessible at https://paloqa.palosite.com/privacy.html.
8. Contact Information & Support
If you have any questions, concerns, or requests regarding this Privacy Policy or your data privacy, please contact us: