WebProof Privacy Policy

Last updated: 8 September 2026

WebProof is a browser extension that lets you prove facts from websites you are logged in to (for example your Spotify top artist or your Discord profile), revealing only the fields you approve. This policy explains what it does and does not do with your data.

What leaves your device

Only the specific fields you approve on the reveal screen before each proof, together with the fact that a verified connection to that website took place. Nothing else from the page, and none of your login details, ever leave your browser in readable form.

The approved fields are sent to our verification service to produce a signed credential. That credential contains only those fields, the source website and endpoint, a timestamp, and the verification method.

What stays on your device

Why the extension asks for broad website access

Chrome shows a warning that WebProof can "read and change all your data on all websites". This permission is used solely to capture the request headers of the verification window the extension itself opens, on whichever site a proof targets. It is not used to read or monitor your other browsing.

What we collect

We do not use analytics, advertising, or tracking of any kind. We do not build user profiles. The verification service processes the fields you approve only to issue your credential and does not retain them for any other purpose.

Third parties

Proofs run against the websites you choose to prove from; your normal relationship and terms with those sites apply. Credentials are issued and verified by our own service. We do not sell or share your data.

The technology

WebProof is built on the open-source TLSNotary protocol. A verifier we operate witnesses your encrypted connection cryptographically; it can confirm the data genuinely came from the website but cannot read your login or the parts of the page you did not reveal.

Contact

Questions about this policy: howardcastiaux@gmail.com.