Privacy policy for CORS Unblock — HeaderForge
CORS Unblock — HeaderForge by Sapir
HeaderForge Privacy Policy
Last updated: September 18, 2026
The short version
HeaderForge runs entirely in your browser. Your rules stay on your machine unless you turn on sync. We collect no browsing data, no analytics, and no telemetry of any kind.
What the extension stores
Your header rules (header names, values, URL patterns), profiles, settings and license status are stored locally in your browser using chrome.storage.local. They are never sent to us.
Match history (Pro). When you use "Test a URL" in the popup, the address you typed is kept in a list of your last 50 tests, without its query string, so you can see what matched. It stays in chrome.storage.local and you can clear it at any time in Settings.
Variables (Pro). Values you give to variables such as {{token}} are stored in chrome.storage.local on your computer. They are not synced unless you separately turn on syncing variable values, and exported rule files contain only the variable names.
Block and redirect rules are carried out by the browser itself. HeaderForge never fetches, reads or forwards the requests they affect.
Small counters. The number of free URL tests used this month and the days your rules were used (so we can ask once whether you'd like to leave a review) are kept on your computer and never sent.
Optional sync. If you switch on sync in Settings, your rules and profiles are also copied to chrome.storage.sync, which your browser's own sync carries to your other computers signed in to the same profile. That goes through the browser vendor's sync, not through us. Rules can contain secrets such as tokens, so sync is off until you turn it on.
The live request list (Pro)
HeaderForge Pro can show you, in the popup, the requests the tab you are looking at is making, and which of your own header rules touched each one. Because this is the one place where the extension observes network activity, here is exactly what it does.
Only while the popup is open. The popup opens a connection to the extension's background worker and names the one tab it is showing. Nothing is observed before that connection exists, and nothing is observed for any other tab.
Memory only. The list is held in the background worker's memory, at most 200 requests per tab. It is never written to chrome.storage, never synced to your other computers, and never sent over the network to us or anyone else.
Discarded when you close the popup. When the last popup watching a tab closes, everything recorded for that tab is deleted immediately.
What is kept per request: the host and path of the address, the method (GET, POST…), the kind of request (page, script, fetch…), the status code or error, the time, and for each of your rules that matched: the header name and a single true/false — did your change actually go out.
What is never kept: header values, cookies, anything from the query string (only whether there was one), request or response bodies, and page content.
Free users see the number of requests and a blurred placeholder. The per-request details are not sent to a free popup at all. The one thing a free popup does receive from this recording is the CORS notice described below.
The list is honest about what it can prove. Firefox reports request headers to the extension after your rule has changed them, so a row can truthfully say a header was sent. Firefox reports response headers before your rule changes them, so for a response-header rule the list only says the rule matched that response — it never claims the header was present, changed or removed.
The "blocked by CORS" notice (free)
While the popup is open on a tab, HeaderForge also keeps a much shorter list drawn from the same recording: the servers whose answers the browser will not let that page read. It is what the popup uses to say "api.example.com blocked a request from this page (CORS)" and to offer the one-click fix, which is free. It lives under the same rules as the list above — that one tab, the background worker's memory, only while the popup is open, dropped when the popup closes, never written to storage and never sent anywhere.
What is kept per server: its host name, the origin of the page that asked (for example http://localhost:3000), whether the failure was a rejected preflight, and the time. At most 20 servers per tab. No address path, no query string, no headers, no bodies.
If you close the notice, HeaderForge remembers a single "not on this tab" flag against that tab's id, for as long as the tab is open, so it does not ask again. That flag is the only thing about the notice that outlives the popup, and it too is memory only.
Limited Use
HeaderForge's handling of user data complies with the Mozilla Add-on Policies, including its Limited Use requirements. The data described above is used for one purpose only — showing you which of your own rules affected which request, on your own screen. It is never transferred off your device, never sold, never used for advertising or profiling, never used to train models, and never read by a human.
The only network request we ever make
If you choose to activate HeaderForge Pro, the extension sends your license key to Lemon Squeezy (our payment provider, lemonsqueezy.com) to verify it. That happens when you activate, and then at most once a day while Pro is on, so that Pro switches off if your subscription ends. If you never activate Pro, the extension never sends it. Your email address, if returned by Lemon Squeezy during validation, is stored locally to display your license status. The request goes to exactly one address, https://api.lemonsqueezy.com/v1/licenses/validate, and contains exactly one thing: your licence key. No page data, no identifiers, nothing about what you were doing.
The optional test on the welcome page
The welcome page has a button labelled "Send 3 test requests to httpbin.org". Only if you click it, the page sends three test requests to https://httpbin.org/anything, a public service that echoes back what it received. They exist to prove your test rule works, and they carry the test header X-HeaderForge-Test: hello and nothing else about you. Apart from these and the licence check, the extension makes no network requests. You can confirm this by searching the extension's source for fetch(: it appears in common.js for the licence check and in welcome.js for the test.
What we never do
No browsing history collection
No analytics or usage tracking
No advertising or third-party trackers
No remotely hosted code — every line ships in the extension package and is reviewed by the add-on store you installed it from
No sale or sharing of any data, ever
Permissions
HeaderForge requests access to all websites (<all_urls>) for one reason only: modifying HTTP headers requires the browser's network-layer permission on the sites you target. Header rules are applied locally by the browser itself; the extension does not read page content.
It also requests webRequest, which it uses in observe-only mode for the live request list and the CORS notice described above. Headers are still modified by declarativeNetRequest, not by this permission. Because HeaderForge already has access to all websites, adding it does not widen what the extension can reach, and the browser shows no additional permission warning.
Contact
Questions: sapirsoftware@gmail.com
The current version of this policy is always at https://sapirsoftware.github.io/headerforge-privacy.html