Effective date: July 30, 2026 Last updated: July 30, 2026

JSON Toolbox by JSONBuddy lets users pretty-print JSON, minify JSON, and apply JSON Patch operations. The selected JSON is sent over HTTPS to the JSONBuddy Web API only after the user requests one of these operations.

We do not sell JSON content, use it for advertising, or use it to track browsing activity.

1. Scope

This policy applies to the JSON Toolbox by JSONBuddy Chrome extension.

2. Information processed

JSON content

The extension processes JSON only when the user loads it from the active tab, pastes it, or selects a local .json file. For JSON Patch, the request contains both the patch operation array and the input document. The exact serialized request is limited to 10 KiB (10,240 UTF-8 bytes). The extension does not read pages in the background.

Connection metadata

Standard server access logs may record operational metadata such as IP address, timestamp, endpoint, user agent, and response status. Request bodies containing JSON content are not included in standard access logs.

3. How information is used

JSON content is used only to return the requested formatted, minified, or patched result. Connection metadata may be used to operate, secure, and troubleshoot the service and prevent abuse. It is not used to build advertising profiles or track browsing history.

4. Storage and retention

  • Submitted JSON: Processed for the request and not as application data or intentionally written to application logs.
  • JSON results: Stored by the extension only in Chrome session storage and cleared with the browser session. Downloaded files are controlled by the user.
  • Consent preference: A boolean recording acceptance of the disclosure is stored locally in the Chrome profile. It contains no JSON content.
  • Server access logs: only as reasonably necessary for security, abuse prevention, troubleshooting, and reliable operation.

5. Sharing and disclosure

JSON content is transmitted only to the JSONBuddy Web API and infrastructure providers operating that service on our behalf. It is not sold, licensed, provided to advertising networks, or shared for unrelated purposes. Information may be disclosed if required by law or necessary to protect the security and integrity of the service.

6. Chrome permissions

activeTab
Lets the user request JSON from the active tab.
scripting
Reads JSON text from that tab only after the user selects the command.
storage
Stores results for the browser session and remembers the consent preference.
api.json-buddy.com
Sends the selected JSON to the chosen Web API endpoint over HTTPS.

7. Security

JSON content is transmitted using HTTPS. Results are rendered as plain text, not executable HTML. The extension does not load remotely hosted executable code and does not collect or store API keys.

8. User choice, integrations, and local processing

The extension asks for consent before sending the first request. You can avoid transmission by not running a tool or by removing the extension.

Need automation or local processing?

Use the JSONBuddy Web API for supported remote operations, or the JSONBuddy CLI to keep processing on your computer.

9. Chrome Web Store Limited Use

Information received through Chrome APIs is used only to provide the extension features described here. Our use of that information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

10. Changes to this policy

If the extension's data practices change, this policy and the extension disclosure will be updated before those changes take effect. The revision date above identifies the latest version.

11. Contact

Questions can be sent to contact@xml-buddy.com.