Privacy policy for SEO Page Inspector — On-page SEO Audit
SEO Page Inspector — On-page SEO Audit by Vlad
Privacy policy for SEO Page Inspector — On-page SEO Audit
Last updated: 24 September 2026 (hreflang check added)
SEO Inspector ("the extension") is a browser tool that analyzes the on-page SEO of the web page you are currently viewing. This policy explains exactly what it reads, what it stores, and the few cases in which it contacts a server.
The extension has no backend, no analytics, no tracking and no user accounts. It never sends your browsing data to the developer. Page analysis runs entirely inside your browser. Some optional checks that you start yourself do make network requests — those are listed in full below, because they are the only cases in which any data leaves your browser.
- The active tab’s content — only when you open the popup on that tab. It reads the page’s HTML (meta tags, headings, links, images, structured data, visible text) and performance timings to build the report. This stays in the popup’s memory and is discarded when the popup closes.
- Every page you open — only if you switch on “Show the issue count on the icon as soon as a page loads” in the settings, which asks for access to all sites first. The same reading is then done when the page finishes loading, to put the number of critical issues on the toolbar icon. The result is the number and nothing else: it is not stored, not kept between pages and never sent anywhere. Switch the setting off (or withdraw site access in
about:addons) and this stops immediately. It is off until you turn it on.
The extension makes no network request until you take an action that requires one, except for a few same-origin checks on the site you are already viewing when the popup opens:
robots.txt, llms.txt and llms-full.txt at the site root, and a HEAD request for the page path (without its query string) to read the X-Robots-Tag header. The popup also displays the page’s own favicon, social preview image and image thumbnails, which your browser fetches from wherever the page hosts them, without a referrer. Nothing is ever sent to the developer: the only contact with the developer’s site is that installing the extension, or updating to a new feature version, opens its page on savko.dev in a new tab — an ordinary page visit that carries no data from the extension.
- llms.txt detection, X-Robots-Tag header, robots.txt rules — goes to: The site you are viewing (same origin). Sent: A request for /llms.txt, /llms-full.txt, /robots.txt and the page’s own URL. When: Automatically, when the report is built.
- Link checker — goes to: The domains the page links to. Sent: An HTTP status request per link. When: Only when you press “Check HTTP status”.
- Image checker — goes to: The hosts serving the page’s images. Sent: An HTTP request per image. When: Only when you press “Check images”.
- Response headers — goes to: The site you are viewing. Sent: A request for the page URL. When: Only when you press “Fetch response headers”.
- Sitemap validator — goes to: The site you are viewing. Sent: A request for sitemap.xml, its sub-sitemaps and the URLs listed in them. When: Only when you press “Validate sitemap”.
- Issue count on page load (off by default) — goes to: The site you are viewing (same origin). Sent: A request for /robots.txt and a HEAD request for the page path, to see whether the page is blocked or set to noindex. When: Only while the setting is on, once per page you open.
- Hreflang — “Check alternates” — goes to: The alternate addresses the page itself declares. Sent: A request for each alternate (at most 25), to read whether it links back. When: Only when you press “Check alternates”.
- Right-click menu — “Sitemap” — goes to: The site you are viewing (same origin). Sent: A request for /robots.txt, to find the sitemap it declares. When: Only when you pick that item.
- Right-click menu — “Check link status” — goes to: The address the link points to. Sent: An HTTP status request for that one link (links to other sites only if you have granted optional site access). When: Only when you pick that item.
- Domain tab — registration data — goes to: rdap.org (third party). Sent: Only the registrable domain name of the page you are viewing (for example example.com). Never for IP addresses, intranet hosts or reserved names — no lookup is made for those. When: Only when you open the Domain tab.
- Domain tab — DNS records — goes to: dns.google (third party, DNS-over-HTTPS). Sent: Only the registrable domain name of the page you are viewing (same exclusions as above). When: Only when you open the Domain tab.
The two third-party services above receive a domain name and nothing else — no URL path, no page content, no identifier of you.
rdap.org is a bootstrap service: it redirects the query to the registry responsible for that top-level domain, which therefore also sees the domain name. They are subject to their own privacy policies: rdap.org (https://about.rdap.org/) and Google Public DNS (https://developers.google.com/speed/public-dns/privacy). If you never open the Domain tab, neither is ever contacted.Several right-click menu items (Rich Results Test, PageSpeed Insights, Schema Markup Validator, Google
site: and phrase searches, Archive.org) simply open that service in a new tab, with the page or link address — or, for the search items, the text you selected — in the address of that tab. That is an ordinary page visit you start yourself, subject to that service’s own privacy policy; the extension sends nothing on its own.Nothing the extension stores is sent to the developer or to any third party. The only copy that can leave your device is your settings, carried by Firefox Sync:
-
localStorage — your settings: theme, interface language, the tab the popup opens on, whether on-page highlighting is switched on, whether the icon shows the issue count as soon as a page loads, and whether the right-click menu is shown and which of its items.-
storage.sync — a copy of the same settings, so Firefox can carry them to your other computers when Firefox Sync is on. They hold no page data.-
storage.local — the last version you ran (so the “what’s new” page opens only once per update), and, when you generate a report, the report’s HTML, kept only long enough to hand it to the report tab that opens; the report tab deletes it, and the next popup open deletes it too in case that tab never ran.No browsing history, no page content and no personal data is persisted.
No data is shared with the developer or sold to anyone. The extension does not use or transfer user data for any purpose unrelated to its single purpose (on-page SEO analysis), does not use it to determine creditworthiness or for lending purposes, and contains no advertising or analytics code.
activeTabandscripting— to read the current page and highlight its headings and problem images on it. Highlighting switches on when you open the popup; switch it off once and the choice is remembered for the pages you open later. The highlight only adds temporary styling to the page and is removed with the toggle.storage— for the values listed under “Data storage”.contextMenus— to add the SEO Inspector submenu to the right-click menu. It can be switched off, or trimmed item by item, in the popup’s settings.- Optional host access (
<all_urls>) — requested only when you first use the link checker, image checker, response headers or sitemap validator, because those need to reach arbitrary domains, or when you switch on the issue count that appears as a page loads. Declining it simply disables those features.
Questions about this policy: svryxod@gmail.com (mailto:svryxod@gmail.com)