Chrome Extension
Privacy
Policy
What Prospect Audit does
Prospect Audit is a Chrome extension that scans the website you are currently viewing and shows you which web services the site owner might need. It is a tool for freelance web developers and small agencies.
What is stored locally on your device
All data stays on your device. Nothing is sent to any server operated by us.
Saved leads
The audit results you choose to save, including the site URL, detected technologies, opportunities, contact details found on the page, and any pitch text you generate. Stored in chrome.storage.local.
Sender profile
Your name, business name, tagline, and optional portfolio URL, used to sign generated pitches. Stored in chrome.storage.local.
License state
If you activate a Pro license, the license key, instance ID, activation date, and last validation date are stored in chrome.storage.local.
Daily scan counter
A count of distinct hostnames scanned today, used to enforce the free-tier daily limit. Resets at midnight local time. Stored in chrome.storage.local.
WordPress version cache
The latest WordPress core version fetched from WordPress.org, cached for 24 hours to avoid repeated requests. Stored in chrome.storage.local.
Network requests the extension makes
The extension makes the following outbound requests. No audit results or personal data are included in any of these requests.
1.
Same-origin requests to the site being audited
When the extension scans a page, it makes one additional GET request to the same URL to read response headers (server software, CDN, PHP version). The response body is discarded immediately. When the scanned site is WordPress, the extension may also fetch the site's own REST API root (/wp-json/) to detect installed plugins, and may fetch the site's contact page to look for email addresses and phone numbers. These requests go to the site you are auditing, not to us.
2.
WordPress version check
A GET request to https://api.wordpress.org/core/version-check/1.7/ to retrieve the latest WordPress release version. Made at most once per 24 hours. No user data is sent.
3.
License check (Pro users only)
When you activate, validate, or deactivate a Pro license, the extension sends your license key and instance ID to https://api.lemonsqueezy.com/. This request is made only from a user gesture or when revalidation is due (at most once every 7 days). The license key is never logged or shown in error messages.
What is NOT collected
No browsing history
No audit results sent to any server
No analytics or telemetry of any kind
No remote code loaded or executed
How to delete your data
Leads and settings
Open the Leads page and delete individual leads, or remove the extension entirely to clear all stored data.
License
Use the Deactivate button on the Settings page before removing the extension.
All local data
Removing the extension from Chrome deletes all chrome.storage.local data associated with it.