Privacy policy for ScopeBrief
ScopeBrief by riodrwn
Privacy Policy
Effective date: September 27, 2026
Purpose
ScopeBrief is developed by riodrwn. It captures selected bug bounty program scopes and rules from HackerOne, Bugcrowd, YesWeHack, and Intigriti so you can review and download Markdown or JSON briefs. This policy covers ScopeBrief 1.0.0 and this project website.
Information handled
When you click Capture program, the extension reads supported program content and records program names, page titles, source URLs, links, capture timestamps, asset identifiers, scope status, and policy text. This is limited to the program you capture; ScopeBrief does not monitor your general browsing history, clicks, keystrokes, or mouse activity.
Information inside program text
Program text can contain names, usernames, contact email addresses, or testing credentials. ScopeBrief does not automatically redact these. Such information may be retained in local captures and downloaded files. The extension does not directly read browser cookies, saved passwords, or authentication tokens. It does not separately collect health records, payment details, personal messages, or your geographic location.
How information is used
Captured information is used only to generate, preview, save, and export the briefs you request. ScopeBrief does not send captures to an AI service. If you later upload an export to an AI agent or another service, that action is under your control and subject to that service’s privacy practices.
Local storage and retention
Captures are stored in chrome.storage.local or the equivalent Firefox extension storage, not browser cloud sync. They remain until you delete them, clear extension data, or uninstall the extension. Delete local data removes the selected program’s stored captures. Raw captures can contain sections omitted from the displayed brief. Downloads remain on your device until you delete them separately. No application-level encryption is added to local captures or exports; protect your browser profile and downloaded files.
Network requests
On HackerOne, capture may request the program’s official CSV over HTTPS from HackerOne using the browser’s existing same-origin session. HackerOne receives ordinary request information, such as your IP address and applicable session cookies, under its own privacy policy. ScopeBrief does not read those cookies directly or send captured content to a developer-operated server. External websites you open from links have their own privacy practices.
Sharing and analytics
The developer does not receive captured program data through the extension. ScopeBrief contains no advertising, analytics, telemetry, or remote executable code. The developer does not sell captured data, use it for advertising, or use it to determine creditworthiness or for lending. Exporting creates local files; it does not automatically share them with a third party.
Permissions
activeTab provides temporary access to the program tab when you invoke the extension. scripting runs packaged extraction scripts on that tab after Capture program is clicked. storage retains program captures locally. ScopeBrief does not request clipboard or browser-history permissions.
Chrome Web Store Limited Use
ScopeBrief’s use of information received through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information is used only for the stated user-facing purpose and is not sold or used for unrelated purposes.
This website and support
This static website is hosted on GitHub Pages. ScopeBrief adds no analytics or tracking scripts. GitHub may process request information, including IP addresses, to operate its hosting service under the GitHub Privacy Statement. If you voluntarily open a GitHub issue or contact the developer, information you provide will be used to address your request. GitHub issues are public; do not include private program details or credentials.
Changes and contact
Updates to this policy will be published here with a revised effective date. For privacy questions, contact riodrwn through the project’s GitHub Issues page. Do not post sensitive information publicly.