1. Overview & Scope
This Privacy Policy describes how MetaShield Pro ("the Extension", "we", "our") handles information when you use our Chrome browser extension, website and related services. This policy is fully compliant with the Chrome Web Store Developer Program Policies, the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
If you do not agree with this policy, please do not install or use MetaShield Pro.
2. Information We Do NOT Collect Zero Data Collection
To be 100% transparent โ MetaShield Pro does NOT collect, store, transmit, sell or share any of the following:
- Personal identifiable information (name, email, phone, address)
- Full browsing history, search queries or visited URLs off-device
- Wallet addresses, seed phrases, private keys, signatures or transaction data
- Cookies, tracking pixels, fingerprinting or advertising identifiers
- IP addresses, geolocation, device or telemetry data
- Any data sent to external servers or third parties
Important: There is no backend server. There is no signup form. There is no "phone-home" code. If this were untrue, Chrome's Manifest V3 permission model would flag it during web store review.
3. Information Stored ONLY On Your Device Local Only
The following non-personal data is stored strictly on-device via Chrome's isolated chrome.storage.local API. This data never leaves your browser profile:
๐ก๏ธ Extension Settings
Your chosen preferences: toggle states, detection sensitivity, blacklist/whitelist choices you saved manually.
๐ Detection Logs
Most recent 200 threat-hit records (domain + risk score only, no URLs) shown on the popup dashboard.
๐ Aggregate Counters
Simple numeric counters for: sites scanned, threats blocked, safe sites visited. For dashboard display.
๐ค User Whitelist
Any domains you explicitly whitelist by clicking "I trust this site" in the warning modal. Only used by your browser.
All of the above can be wiped instantly by uninstalling the extension or using the clear-history button in the popup UI.
4. How Information Is Used
The tiny amount of local-only data above is used exclusively to operate the extension for you, and for no other purpose:
- Threat detection: Matching URLs you visit against an on-device database (70+ official whitelist domains + known scam domains + keyword patterns).
- UI display: Populating the dashboard counters, stats and detection history visible only to you inside the popup interface.
- Preferences persistence: Remembering toggles, threshold and your own whitelisted trusted domains across browser restarts.
๐ซ What we will NEVER do
- Sell or rent any data to advertisers, data brokers or third parties
- Combine extension data with any account or identity-graph service
- Use data for retargeting, profiling or cross-site advertising
- Force updates that change the privacy model without your knowledge and a visible in-app notification
5. Permissions Explained (Manifest V3 Transparency)
Chrome shows requested permissions during install. Here's exactly why each is needed โ no over-permissioning:
- <all_urls> host access โ Required so content script runs on every page you visit to detect phishing (attacks don't pre-register). URLs are only compared locally, never transmitted.
- storage โ Stores only the minimal settings/counters in chrome.storage.local (see Section 3).
- tabs & activeTab โ So popup can show the live status of the page you are currently viewing (risk score, verified badge).
- scripting โ Required to inject the warning modal overlay and verified-OK badge into pages. No remote code is ever injected โ everything ships with the extension package.
6. Third-Party Services & Subprocessors
MetaShield Pro uses these external vendors โ each provides a static, publicly-auditable library with no network calls:
๐ psl.min.js (Public Suffix List)
Open-source bundled library to correctly parse domains (e.g. distinguish .co.uk from .com). Runs locally.
๐ Chrome Web Store
Hosts the extension install. Google's privacy policy applies to the store itself; we receive zero user data from installs.
No analytics, crash-reporting SDKs or remote configuration tools are included. Period.
7. Terms of Service (Supplemental)
License & Use
MetaShield Pro is licensed to you for personal, non-commercial use. You may not reverse-engineer, redistribute or resell the extension.
Disclaimer of Warranties
The extension is provided "as-is" without warranty of any kind. While our detection engine blocks a wide range of attacks, no security tool is 100% perfect โ always verify URLs yourself before connecting wallets or approving transactions.
Limitation of Liability
To the maximum extent permitted by law, MetaShield Pro's creators and operators shall not be liable for any indirect, incidental, special, consequential or punitive damages, including lost profits, crypto, NFTs or data.
8. Your Data Rights (GDPR / CCPA)
Because we hold zero of your data on any server, most rights requests are instant and operated by you directly:
- Right of Access / Data Export โ Export your local settings from the popup (or: right click extension โ inspect background โ storage).
- Right to Erasure ("Right to be Forgotten") โ Right-click MetaShield โ "Remove from Chrome" โ all local data is deleted immediately and irreversibly.
- Opt-Out of โฆ anything โ Toggle the main switch off in the popup. All detection stops on the spot.
For any formal request (including designated-agent requests under CCPA), email us anytime. We will reply within 48 business hours to confirm we hold nothing on our systems to delete.
9. Children's Privacy
MetaShield Pro is general-audience software and is not directed at children under 13 (COPPA) or under 16 (GDPR). We do not knowingly solicit or store data from minors. If you believe we hold any, contact us immediately and we will confirm deletion.
10. Policy Updates
We may occasionally update this policy to reflect extension upgrades or legal changes. Material changes will be announced via a prominent in-app notification and by bumping the "Effective date" above. Your continued use after updates constitutes acceptance.
11. Questions & Contact
Privacy, security and compliance matter. If you have any question about this policy, want to report a security vulnerability, or need to submit a CCPA/GDPR access request โ our team responds in under 48h:
For scam-domain submissions use the contact form and we will add your report to the next extension update's blacklist database.