Last updated: 2026-08-15

VeriSilo Companion Privacy Policy

This policy covers the VeriSilo Companion browser extension for Chrome and Edge and, where stated, its optional connection to the separately installed VeriSilo desktop application. VeriSilo Companion is an inspection tool: it observes browser signals on pages you explicitly scan and explains them. It does not sell data, shows no advertising, and operates without a VeriSilo server.

Data in the website demo

The website demo uses simulated identities and evidence. Created and edited data stays in page memory and resets on reload. It does not connect to the desktop app, read local files, or probe your IP or DNS. Do not enter real passphrases or proxy credentials.

Your motion preference is saved in this browser and shared with the demo window. The site includes no analytics or advertising scripts; pages and static assets are delivered by the website host. The policy below covers the browser extension.

What the extension reads

Nothing is read automatically. Only after you open the side panel on a page and click Scan does the extension read browser-visible signals from that one tab: user agent and platform, language, screen and timezone, hardware concurrency, and summary digests of Canvas, WebGL, WebGPU, audio, fonts, media devices, WebRTC, iframes, and Workers.

The extension never reads cookie values, page text, form input, passwords, localStorage/IndexedDB contents, or browsing history.

Where data is stored

The current scan report is kept in chrome.storage.session and disappears with the browser session. A redacted history of at most 20 reports is kept locally in chrome.storage.local for up to 30 days; nothing is saved from incognito/InPrivate tabs. Both stores are restricted to trusted extension contexts and are never synced to any cloud account. You can inspect and clear the local history from the panel at any time.

Exported JSON/HTML reports redact high-sensitivity signal values by default and are generated only when you explicitly export.

Network checks

A network check never runs automatically. After you grant the optional site access and confirm the action, the extension contacts ipwho.is (exit IP, geolocation, ASN), Cloudflare 1.1.1.1, and Google Public DNS with a fixed example.com DoH query for comparison. If ipwho.is is unavailable, one of the fallback exit-IP services api.ipify.org or api.ip.sb is contacted instead. Those providers receive your request IP address. The result is stored in session storage and can be cleared from the panel. The comparison is not presented as DNS leak detection.

Connection to the VeriSilo desktop app

If you have separately installed the VeriSilo desktop application, the extension may use Native Messaging to read a short-lived, redacted runtime status and to submit the network result you just triggered. The desktop stores a bounded local history in its encrypted Vault until you clear it or delete the Silo. The extension never sends cookies, page storage, credentials, browsing history, the full observation report, or Vault secrets through this bridge. The companion remains fully functional without the desktop app.

What is never done

The extension does not transmit browsing activity, authentication information, cookies, or reports to VeriSilo servers because none exist. It does not sell, share, or use data for advertising. It contains no remote code. The only external navigation is the VeriSilo project page, opened only when you click the corresponding button.

Your controls

Everything the extension does is user-triggered. Optional website access and optional privacy controls are requested only when you invoke the related feature, and can be revoked in the browser's extension settings. Session results and local history can be cleared from the panel. Uninstalling the extension removes its storage.

Changes and contact

This policy is versioned with the extension. Material changes will be described in the extension changelog. For questions, open an issue in the VeriSilo repository.

VeriSilo repository