Scope
This policy covers the Form Rescue Chrome extension and its public product and support pages on ExtensionCrate.
Data handled
On websites where you grant access, Form Rescue can handle:
- Text and supported form-control values you enter.
- Page context needed to identify a draft: page title, origin, sanitized URL or route, field type, label, name, placeholder, structural fingerprint, frame identity, and timestamps.
- Local settings such as website access, exclusions, retention limits, capture preferences, and optional vault configuration.
- Local operational diagnostics such as field types, status, and error codes.
Depending on what you type, draft content may contain personal, health, financial, communication, location, or other user-generated information. Form Rescue does not send that information to ExtensionCrate or any third party.
How data is used
Form Rescue uses local information only to recognize supported fields on an approved website, save meaningful versions, confirm a successful write, find and preview matching drafts, restore after your action, and enforce your settings.
It is not used for advertising, profiling, analytics, credit decisions, or an unrelated purpose.
Sensitive-field protection
Form Rescue does not intentionally capture password, hidden, or file inputs; current or new passwords; one-time verification codes; payment-card fields; authentication tokens; private keys; recovery phrases; card numbers; or equivalent secrets.
Government identifiers, banking identifiers, dates of birth, medical or patient identifiers, and safe fields on sensitive page routes are paused by default. You may explicitly allow these private fields for one website. Hard-blocked secrets remain excluded.
Storage and retention
Drafts are stored in local IndexedDB. Settings and vault configuration are stored in chrome.storage.local. An unlocked vault key is kept only in chrome.storage.session.
The default retention is 30 days, with an 8 MB limit, up to 250 page drafts, 100,000 characters per field, and five versions per field. Available limits can be changed in Settings. Cleanup removes the oldest unpinned drafts first.
The optional encrypted vault uses AES-GCM. Its key is derived with PBKDF2-SHA-256 (250,000 iterations) from a password Form Rescue does not store or recover. Exported JSON backups are readable plaintext even when the vault is enabled.
Website access
Website access is optional. Site-by-site access is the default. You can instead grant access to regular HTTP and HTTPS websites through Chrome's permission prompt. Form Rescue injects its capture layer only after Chrome confirms access for the relevant origin.
Stored URLs redact query parameters whose names indicate tokens, credentials, codes, keys, or secrets. Non-routing fragments are removed. Ordinary route parameters can remain when needed to identify the correct step.
Security
All executable extension code is included in the installed package. The extension does not load remote code. Recovery previews render as plain text, and imported rich content is sanitized. No control can guarantee a device, profile, or backup file will never be compromised; protect your device and exported files.
Your controls
- Choose site-by-site or all-regular-sites access, pause a website, add exclusions, or revoke access in Chrome.
- Opt in or out of private-field capture for one website.
- Change retention and storage limits.
- Enable, lock, or disable the optional encrypted vault.
- Export, import, pin, restore, or delete drafts.
- Clear all extension data in Settings or remove the extension through Chrome.
Children
Form Rescue is a general productivity tool and is not directed to children under 13. ExtensionCrate does not knowingly collect children's data through the extension because the extension does not transmit user data to us.
Changes
This policy may change when the extension's behavior or applicable requirements change. The effective date will be updated for material revisions.
Contact
Questions or privacy requests can be sent to support@extensioncrate.com.