Privacy policy for LLM Cliché Highlighter
LLM Cliché Highlighter by Haider Alwasiti
LLM Cliché Highlighter collects nothing, stores nothing, and sends nothing anywhere.
This is not a promise about intent. It is a property of what the add-on is allowed to do, and every claim below can be checked against the source at https://github.com/hwasiti/llm-cliche-highlighter-extension
WHAT IT DOES WITH YOUR DATA
Nothing leaves your browser. When you click the toolbar button, the add-on reads the text of the page in that one tab, finds phrases matching its built-in patterns, and wraps them in highlights in the page you are already looking at. The text is examined in memory and discarded when you close or reload the page.
There is no server, no account, and no analytics, telemetry, crash reporting or remote configuration of any kind.
WHAT IT NEVER COLLECTS
Personally identifying information: never collected.
Authentication or credential data: never collected.
Financial or payment information: never collected.
Health information: never collected.
Location: never collected.
Browsing history or activity: never collected.
Search terms: never collected.
Bookmarks: never collected.
Personal communications: never collected.
Website content: read in the active tab only, never transmitted and never retained.
WHY IT COULD NOT COLLECT DATA EVEN IF IT WANTED TO
The add-on requests two permissions and no host permissions at all:
- activeTab gives access to a single tab, only after you click the toolbar button, and only until you navigate away. The browser enforces this. Before your click it has no access to any page.
- scripting is what lets it inject its own two files into that tab.
It requests no network permission, so it cannot contact any server. It requests no storage permission, so it has nowhere to keep anything between clicks. The highlights live entirely in the page's own DOM, which is why reloading the page clears them.
This is declared formally in the manifest as data_collection_permissions: { required: ["none"] }.
CHECKING THIS YOURSELF
The add-on is open source under the Apache License 2.0 and small enough to audit in an afternoon. manifest.json lists every permission requested; background.js handles the toolbar click; content.js walks the page; core.js is the pattern engine and is pure text processing with no input or output. Search the source for fetch, XMLHttpRequest, sendBeacon or storage and you will find none of them.
CONTACT
wasiti14@gmail.com, or an issue on the project repository.
CHANGES
If a future version ever collects anything, this policy and the manifest declaration will be updated before that version is published, and the change will be called out in the release notes.