x402 Inspector Pro Privacy Policy
Plain-language summary: x402 Inspector Pro decodes challenge data locally in the browser. It does not automatically inspect browsing activity, transmit pasted challenge data, store challenge data, run analytics, sell data, or connect to a wallet.
1. Scope
This policy applies to the Chrome extension named x402 Inspector Pro — Challenge Decoder. The extension lets a user manually paste an x402 payment challenge header or JSON payload, view locally decoded fields, and generate a basic cURL request template.
2. Information handled by the extension
The extension may temporarily process information that the user deliberately pastes into its popup, including public x402 challenge fields such as payment amount, network, asset, payment destination, resource URL, scheme, and description. This may constitute website content and financial or payment information under Chrome Web Store disclosure categories.
The extension also processes an endpoint URL when the user enters one to generate a cURL template.
3. Local processing, storage, and transmission
- All decoding and template generation occurs locally inside the extension popup.
- Pasted challenge data and endpoint URLs are not sent to the developer or any external server.
- The extension does not retain pasted challenge data or endpoint URLs after the popup is closed.
- The extension does not request access to browsing history, website tabs, cookies, local storage, or host permissions.
4. Sensitive credentials
The extension is not designed to receive wallet seed phrases, private keys, passwords, authentication cookies, signed payment credentials, or card information. Users should never paste such information into the extension. The extension displays an in-product warning against entering credentials.
5. Optional Stripe checkout links
The extension contains user-initiated buttons that open external Stripe checkout pages for optional hosted gateway subscriptions. Stripe—not the extension—processes information entered on those checkout pages. The extension does not receive, read, or store card numbers, wallet credentials, billing addresses, or Stripe checkout form contents.
6. Analytics, advertising, and sharing
- No analytics or behavioral tracking is included.
- No personalized advertising is included.
- User data is not sold, rented, or transferred to data brokers.
- No developer employee or contractor can view pasted challenge data because it is not transmitted.
7. Chrome Web Store Limited Use compliance
The extension’s use of user-provided challenge information is limited to providing its disclosed challenge-decoding and request-template functions. Data is not used for advertising, profiling, creditworthiness, unrelated product development, or any purpose unrelated to the extension’s single purpose.
8. Security
The extension contains no remotely hosted executable code. Its JavaScript and HTML are packaged with the extension and reviewed through the Chrome Web Store submission process. External subscription pages are opened using HTTPS.
9. Data deletion
Because challenge inputs are not persistently stored, users can remove them immediately with the Clear button or by closing the popup. The extension has no developer-controlled database containing challenge inputs.
10. Children
The extension is a developer utility and is not directed to children under 13.
11. Changes to this policy
This policy may be updated when the extension’s functionality or data practices change. The effective date above will be revised when material changes are made.
12. Contact
Privacy questions may be submitted through the support contact displayed on the extension’s Chrome Web Store listing.