Last updated: August 14, 2026
WardenOne is a browser security extension that protects you against phishing, malware downloads, redirect chains, IP grabbers, trackers, token theft, bad certificates, and risky sites. This policy explains exactly what data WardenOne touches, where it stays, and the few cases where information leaves your device.
We wrote this to be honest about scope rather than reassuring. If anything here is unclear, contact us (see Contact below).
WardenOne saves the following in your browser’s local extension storage
(chrome.storage.local). This stays on your computer, is not synced to a cloud
account by WardenOne, and is not uploaded to us:
The opt-in Twitch local rewind feature makes short, high-bitrate clips of video and audio already playing in the current tab and keeps up to five minutes in volatile browser memory. The clips are used only for the in-player replay, are never uploaded or saved to disk by WardenOne, and are discarded when the channel, page, or tab closes. To control memory use, the oldest clips may be discarded before five minutes on unusually high- bitrate streams.
Deleting this data: Removing WardenOne from your browser deletes its local storage. You can also reset settings from the options page, and the “Forget this site” and “Clean browsing data” tools remove data on demand.
To keep ad/tracker/malware/phishing blocking current, WardenOne periodically downloads
public filter lists from their maintainers, for example EasyList, AdGuard filter
lists, Phishing.Army, the urlhaus/malware-filter list, and the OpenPhish public feed
(fetched from raw.githubusercontent.com). These are ordinary downloads of rule files —
your browsing history is not sent; the list host only sees the normal network request
(including your IP address, as with any website you load). No personal data is attached.
Pages routinely load scripts from other companies, and one of the commonest ways a trusted site starts attacking its visitors is that one of those scripts is quietly swapped. To notice that, WardenOne re-requests third-party scripts the page has already loaded, hashes them, and compares the hash with what it saw before.
The important detail for your privacy: every one of those requests goes to a host the page itself just used, so no company learns anything it did not already know from you loading the page. Scripts served by the site you are visiting are skipped entirely, nothing about the request is sent anywhere else, the hashing and comparison happen on your device, and only the hash is kept. Re-checks are rate-limited and capped per page, and allowlisted sites are skipped. Turn it off with Script drift guard in the popup.
This checks a website’s own public breach record — not your account, and not any password of yours. It tells you whether the site you are on has been breached in the past, so you can decide how much to trust it with.
Nothing is sent until you click. With Breach & site-history checks enabled, pressing
Check breach history in the popup sends the site’s registrable domain only — example.com,
never the full address, never the page path or query, never anything from the page itself — to
haveibeenpwned.com. Have I Been Pwned will also see your IP address, as it would for any
request your browser makes.
The reply is cached on your device for 12 hours, so revisiting a site does not re-send anything. That cache holds at most 120 domains; the oldest entries are dropped past that. Clearing WardenOne’s data removes it.
There is no password checking in WardenOne. Earlier versions of this policy described a
password k-anonymity lookup against api.pwnedpasswords.com. That feature was never reachable
in the shipped extension — no part of the interface offered it — and the unused code behind it
has been removed. If a password checker is ever added, it will be documented here before it
ships, not after.
A login form on a domain registered days ago is one of the strongest phishing signals
there is. If you switch this on, then when a page shows a password field WardenOne
sends that site’s registrable domain — example.com, never the full URL, never the page
contents, never what you type — to the public RDAP service at rdap.org, and uses
the registration date it returns to warn you before you sign in.
This is the one feature that tells an outside party something about where you browse, which is why it is off by default even though it needs no API key and costs nothing. rdap.org sees the domain and your IP address, as any site you load would. Answers are cached on your device (most recent 100 domains) so the same site is not looked up twice; requests for IP addresses and private or local hostnames are never sent at all. Turn it on or off with Login page age check in the popup.
WardenOne can optionally check a URL, domain, or file hash against third-party threat
services only if you enable that provider. All of these are off by default: Google
Safe Browsing (safebrowsing.googleapis.com), VirusTotal (www.virustotal.com), urlhaus
(urlhaus-api.abuse.ch), AbuseIPDB (api.abuseipdb.com), PhishTank
(checkurl.phishtank.com), and WhoisXML (www.whoisxmlapi.com,
domain-reputation.whoisxmlapi.com, threat-intelligence.whoisxmlapi.com).
Most of those require you to supply your own API key. OpenPhish is the exception: it is
used through its free public community feed, which needs no key, and it is fetched as a
whole list from raw.githubusercontent.com rather than by asking about your URL — so no
address of yours is sent to it. An earlier version of this policy said every provider
required a key, which was not true of OpenPhish. When you enable one, the specific URL/domain/hash
being evaluated is sent to that provider so it can return a verdict. Those providers are
independent data controllers with their own privacy policies; review theirs before
enabling. WardenOne sends nothing to them until you do.
That is the complete list. WardenOne contacts no other external endpoints, and there is no background telemetry, crash reporting, or usage analytics.
WardenOne requests broad browser permissions because on-device security requires them. None are used to collect data about you. A per-permission justification is published with the store listing; in summary:
declarativeNetRequest, webRequest,
webNavigation, scripting, activeTab, <all_urls>) — to block malicious requests
and detect redirect chains, grabbers, and unsafe navigations, on any site. Network
request observation is read-only.WardenOne does not collect or transmit: your browsing history, page contents, form data, keystrokes, credentials, cookies, location, or any personally identifiable information. There is no advertising, no data brokerage, and no third-party tracking introduced by WardenOne.
WardenOne’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Concretely, and in the same terms that policy uses:
WardenOne uses no Google account sign-in and requests no OAuth scopes. Google Safe Browsing is an optional, off-by-default lookup that a person enables with their own API key.
WardenOne is a general-audience security tool and is not directed at children under 13. It does not knowingly collect any personal information from anyone.
If this policy changes materially, we will update the date above and the version published with the store listing. Continued use after an update constitutes acceptance.
Questions or privacy requests: open an issue on the project’s issue tracker — https://github.com/iri-dev/WardenOne/issues/new/choose
The issue tracker is the support channel for WardenOne. It is public, so please do not post anything you would not want visible; if a privacy request needs private details, say so in the issue and we will arrange another route.
WardenOne is provided as a protective tool and does not guarantee detection of every threat. It supplements, and does not replace, safe browsing habits.