Privacy Policy for JSON Toolbox by JSONBuddy

Effective date: July 30, 2026  |  Last updated: July 30, 2026

JSON Toolbox by JSONBuddy lets users pretty-print JSON, minify JSON and apply JSON Patch operations. The selected JSON is sent over HTTPS to the JSONBuddy Web API only after the user requests one of these operations.

We do not sell JSON content, use it for advertising or use it to track browsing activity.

1. Scope

This policy applies to the JSON Toolbox by JSONBuddy Chrome extension. It explains what information the extension and JSONBuddy Web API process, why it is needed, how it is retained and what choices users have.

2. Information processed

JSON content

The extension processes JSON only when the user loads it from the active tab, pastes it or selects a local .json file.

For JSON Patch, the request contains both the patch operation array and input document. The exact serialized request is limited to 10 KiB (10,240 UTF-8 bytes). The extension does not read pages in the background.

Connection metadata

Standard server access logs may record operational metadata such as IP address, timestamp, endpoint, user agent and response status. Request bodies containing JSON content are not included in standard access logs.

3. How information is used

JSON content is used only to return the requested formatted, minified or patched JSON result.

Connection metadata may be used to operate, secure and troubleshoot the service and prevent abuse. It is not used to build advertising profiles or track browsing history.

4. Storage and retention

  • Submitted JSON: Processed for the request and not retained as application data or intentionally written to application logs.
  • JSON results: Stored by the extension only in Chrome session storage and cleared with the browser session. Downloaded files are controlled by the user.
  • Consent preference: A boolean recording acceptance of the disclosure is stored locally in the Chrome profile. It contains no JSON content.
  • Server access logs: Retained only as reasonably necessary for security, abuse prevention, troubleshooting and reliable operation.

5. Sharing and disclosure

JSON content is transmitted only to the JSONBuddy Web API and infrastructure providers operating that service on our behalf. It is not sold, licensed, provided to advertising networks or shared for unrelated purposes.

Information may be disclosed if required by law or necessary to protect the security and integrity of the service.

6. Chrome permissions

  • activeTab: Lets the user request JSON from the active tab.
  • scripting: Reads JSON text from that tab only after the user selects the command.
  • storage: Stores results for the browser session and remembers the consent preference.
  • api.json-buddy.com: Sends the selected JSON to the chosen Web API endpoint over HTTPS.

7. Security

JSON content is transmitted using HTTPS. Results are rendered as plain text, not executable HTML. The extension does not load remotely hosted executable code and does not collect or store API keys.

8. User choice, integrations and local processing

The extension asks for consent before sending the first request. Users can avoid transmission by not running a tool or by removing the extension.

Need larger integrations or completely local processing? Explore the JSONBuddy Web API for authenticated automation, or use the JSONBuddy CLI to keep processing on your computer.

9. Chrome Web Store Limited Use

Information received through Chrome APIs is used only to provide the extension features described here. Our use of that information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

10. Changes to this policy

If the extension's data practices change, this policy and the extension disclosure will be updated before those changes take effect. The revision date above identifies the latest version.

11. Contact

Questions can be sent to contact@xml-buddy.com.