Legal

Privacy Policy

Last updated: 2026-07-11

Zevr Guard (hereafter "the Service") is a Chrome extension provided by Zevr (hereafter "we" or "us"). This Privacy Policy explains what information the Service handles, how it is used, and under what conditions it may be transmitted.

1. Information we handle

  • Approximate location. When the side panel opens its world map, the Service asks our own endpoint (feedback.zevrhq.com/v1/whereami) once per session for the coarse, country-level location Cloudflare had already resolved from the connection, in order to render your own "You are here" pin. No third party is involved and the request carries no data about you or the sites you browse.
  • Destination-domain information of your browser traffic. The Service reads these via the Chrome declarativeNetRequest and webRequest APIs to classify, visualise, and optionally block them. This information never leaves your browser.
  • Your settings and local statistics. Block-category toggles, custom blocklist, custom allowlist, and per-page counters are stored in chrome.storage.local.

2. What we do not handle

  • We do not receive, record, or transmit the URLs you visit.
  • We do not operate analytics, telemetry, or A/B testing.
  • We do not sell or share your information with third parties.

3. Outbound requests the extension makes

  • Threat-database fetch to https://zevrhq.com/feed/v1/ (our own CDN). The request is a fixed URL and contains no information about your browsing. It runs at most once per day.
  • Approximate location to feedback.zevrhq.com/v1/whereami (our own endpoint). Used to place a single pin on the map. It is a plain GET carrying nothing: the answer is the coarse location Cloudflare had already resolved from the connection. No third party is involved, the result is cached after the first call, and nothing is stored on our side.
  • Phishing report (optional, user-initiated) to feedback.zevrhq.com (our own endpoint). Sent only when you explicitly click "Report as phishing", and containing only the reported domain name, the detection context (e.g. which brand it imitates) and your UI language. It never includes the page you were on, your IP-derived location, or any identifier. Reports are reviewed by hand; approved domains join the public threat database.
  • False-positive report (optional, user-initiated) to feedback.zevrhq.com (our own endpoint). Sent only when you explicitly click "This is a safe site — report the mistake" on a warning page. It carries the domain you are disputing, which threat list named it, when that list was built, and the extension version. Everything in it describes the domain and the list entry; nothing describes you, your language, or the rest of your browsing. Reports are reviewed by hand before anything is removed from the threat database.

4. Retention

All data stored by the Service lives inside chrome.storage.local on your device. Uninstalling the extension removes everything. We do not retain copies elsewhere because we never receive the data in the first place.

5. Open source

The Service is released as open source under GPL-3.0. Every claim on this page can be verified against the source code: github.com/krystasis/zevr-guard.

6. Security contact

For security-sensitive reports, please follow the process described in SECURITY.md. General questions can be sent to krystasis12@gmail.com.

7. Changes to this policy

We may update this Privacy Policy to reflect changes to the Service. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be announced via the project release notes.