Privacy Policy
Last updated: August 22, 2026
This policy explains how the Is This Link Safe Chrome extension and the website at
https://islinksafe.com handle information. Contact
[email protected] with questions or
privacy requests.
Important disclosure: automatic URL checks
islinksafe.com over
HTTPS so it can display a safety icon and warn about suspicious or dangerous pages. The transmitted URL
can include its domain, path, and query parameters. Its client-side fragment (the part after
#) is removed before the remote check.
The extension also sends a URL when you paste it into the popup or explicitly choose the context-menu check. Do not place passwords, access tokens, or other secrets in URLs.
Information handled
- Checked URLs and domains: the URL without its client-side fragment is processed for a verdict. The domain and verdict may be stored in the threat database. Stored Safe records do not replace a fresh authoritative threat check.
- Technical request information: the connecting IP address is used temporarily for rate limiting and abuse prevention. New usage metrics store a keyed pseudonymous identifier instead of the raw address, plus endpoint, status, latency, and time. Limited connection information may appear in infrastructure error logs.
- Website server IP: the checked site's public IP may be resolved and used as a threat signal. It is not necessarily the user's IP.
- Optional feedback: an incorrect-result report stores the reported URL, verdict, source, and submission time.
- Local extension settings: recent results are cached in Chrome for about 20 minutes; warning suppression lasts about 24 hours; rating-prompt preferences remain until extension data is cleared.
We do not provide user accounts, collect payment information, sell personal information, or use browsing activity for advertising, credit decisions, or unrelated profiling.
How information is used
- Return Safe, Suspicious, Dangerous, or Unknown results and show automatic warnings.
- Detect phishing, malware-listed URLs, typosquatting, and risky hosting infrastructure.
- Prevent abuse, enforce service limits, investigate feedback, and improve reliability.
Service providers
- Google Web Risk receives the checked URL and returns threat-list matches.
- AbuseIPDB may receive the checked website's resolved public IP.
- Sentry receives application errors and limited performance telemetry. Error context is configured to avoid intentionally sending full checked URLs or raw user-IP analytics.
- Google Forms powers the optional website and uninstall feedback forms; information entered there is also governed by Google's terms.
- Chrome Web Store provides aggregated page-view, install, and user statistics rather than individual browsing histories.
Retention
Browser cache and warning-suppression data use the periods above. Domain verdicts, pseudonymous operational metrics, and submitted incorrect-result feedback are currently retained until no longer needed or manually deleted. You may request deletion of feedback associated with a URL. External providers apply their own retention schedules. We intend to replace manual server retention with documented automatic deletion periods and will update this policy when those controls are deployed.
Security and limitations
Checks are transmitted over HTTPS, backend services are isolated on a private service network, and secrets are supplied through deployment configuration. No method is completely secure, and the extension provides a risk signal rather than a guarantee that a site is harmless.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browsing activity is used only to provide or improve the prominently disclosed link-safety features. It is not used for personalized advertising or transferred for unrelated purposes.
Your choices
You can stop automatic checks by disabling or uninstalling the extension and clear local data through Chrome's extension controls. To request information or deletion, email the address above and identify the relevant URL without including unnecessary secrets.
Children and changes
The service is not directed to children under 13, and we do not knowingly collect account or profile information from children. We may update this policy as the extension, providers, or retention practices change; the current update date will remain visible here.