Transparency
Permissions, and why
DummyDrop asks for as little as it can. This page lists every permission in version 1.1.0, why it is needed, and what it does not allow.
Permissions DummyDrop asks for
| Permission | Why it is needed | What it does not allow |
|---|---|---|
activeTab |
Gives DummyDrop temporary access to the tab you are on, but only after you click its toolbar icon or use its keyboard shortcut there. This is what lets it read the form fields on that page and fill the ones you ticked. | Access to any other tab, or to any page in the background. The browser ends the access when the tab moves to a different site or closes. |
scripting |
Runs DummyDrop's scanner and filler inside the tab (and its frames) that activeTab gave it.
DummyDrop declares no always-on content scripts.
|
Running anything on a page you have not opened DummyDrop on. |
storage |
Saves your settings, saved values, profiles, site rules, remembered field types and the position of the floating window in the browser's local extension storage, on your device. | Syncing to an account, or being read by websites. |
sidePanel |
Lets you keep DummyDrop open in the browser's docked side panel, an option you turn on yourself. | It gives no access to any website. |
Optional site access (*://*/*: http and https pages only) |
Not granted when you install. Asked for one site at a time, only when you press a button for it: Keep DummyDrop active on this site (the shield button), or Allow access for an iframe served by another site, such as an embedded payment form. | Anything you did not approve. The browser shows its own prompt for each site, and you can remove a site any time from Always-on sites in the settings or in the browser's extension settings. |
One more thing that is not a permission
The optional floating window shows DummyDrop's own page inside a frame on the page you opened it on. To allow
that, the extension declares that one page (floating.html) as a web-accessible resource for web
pages. It uses a per-session dynamic address, so websites cannot detect DummyDrop by probing for it, and it
exposes no data. It adds no permission and no install warning.
Permissions DummyDrop does not ask for
- Access to all websites at install. There is no host permission in the install list, only the optional per-site access above.
-
tabsandwebNavigation: DummyDrop cannot list your tabs or follow your browsing. It only sees the tab you clicked it on. history,bookmarks,cookiesanddownloads.webRequest: it cannot see or change your network traffic.clipboardRead,geolocation,notifications,identity.-
Network access of its own. DummyDrop's code makes no network requests, has no server and loads no remote code.
Its extension pages run under a strict Content-Security-Policy:
script-src 'self'; object-src 'self'.
Keyboard shortcuts are not permissions
The two keyboard shortcuts, Alt+Shift+F and Alt+Shift+G, are suggestions you can change at any time on
the browser's extension shortcuts page. Using either one on a page is what grants activeTab access to
that page.
The Privacy Policy explains what DummyDrop does with the information it handles, and How it works shows these permissions in action.