JSON Toolbox by JSONBuddy lets users pretty-print JSON, minify JSON, and apply JSON Patch operations. The selected JSON is sent over HTTPS to the JSONBuddy Web API only after the user requests one of these operations.
We do not sell JSON content, use it for advertising, or use it to track browsing activity.
1. Scope
This policy applies to the JSON Toolbox by JSONBuddy Chrome extension.
2. Information processed
JSON content
The extension processes JSON only when the user loads it from the active tab, pastes it, or selects a local .json file. For JSON Patch, the request contains both the patch operation array and the input document. The exact serialized request is limited to 10 KiB (10,240 UTF-8 bytes). The extension does not read pages in the background.
Connection metadata
Standard server access logs may record operational metadata such as IP address, timestamp, endpoint, user agent, and response status. Request bodies containing JSON content are not included in standard access logs.
3. How information is used
JSON content is used only to return the requested formatted, minified, or patched result. Connection metadata may be used to operate, secure, and troubleshoot the service and prevent abuse. It is not used to build advertising profiles or track browsing history.
4. Storage and retention
- Submitted JSON: Processed for the request and not as application data or intentionally written to application logs.
- JSON results: Stored by the extension only in Chrome session storage and cleared with the browser session. Downloaded files are controlled by the user.
- Consent preference: A boolean recording acceptance of the disclosure is stored locally in the Chrome profile. It contains no JSON content.
- Server access logs: only as reasonably necessary for security, abuse prevention, troubleshooting, and reliable operation.
5. Sharing and disclosure
JSON content is transmitted only to the JSONBuddy Web API and infrastructure providers operating that service on our behalf. It is not sold, licensed, provided to advertising networks, or shared for unrelated purposes. Information may be disclosed if required by law or necessary to protect the security and integrity of the service.
6. Chrome permissions
activeTab- Lets the user request JSON from the active tab.
scripting- Reads JSON text from that tab only after the user selects the command.
storage- Stores results for the browser session and remembers the consent preference.
api.json-buddy.com- Sends the selected JSON to the chosen Web API endpoint over HTTPS.
7. Security
JSON content is transmitted using HTTPS. Results are rendered as plain text, not executable HTML. The extension does not load remotely hosted executable code and does not collect or store API keys.
8. User choice, integrations, and local processing
The extension asks for consent before sending the first request. You can avoid transmission by not running a tool or by removing the extension.
Use the JSONBuddy Web API for supported remote operations, or the JSONBuddy CLI to keep processing on your computer.
9. Chrome Web Store Limited Use
Information received through Chrome APIs is used only to provide the extension features described here. Our use of that information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
10. Changes to this policy
If the extension's data practices change, this policy and the extension disclosure will be updated before those changes take effect. The revision date above identifies the latest version.
11. Contact
Questions can be sent to contact@xml-buddy.com.