Privacy policy for API Sniffer - Endpoint Detector
API Sniffer - Endpoint Detector by Bahawal Ali
Privacy Policy
Last updated: July 26, 2025 · Applies to API Sniffer (browser extension) and its companion services
This Privacy Policy explains what data API Sniffer ("the Extension", "we", "us") collects, how it is used, and your choices regarding this data. This applies to both our free features (which run entirely within your browser) and our optional Hunter's Plan features (which utilize companion cloud services to enable collaboration and out-of-band testing).
In short: The core capture and testing tools run 100% locally. That data never leaves your device unless you explicitly export it. If you subscribe to the Hunter's Plan, specific features (such as team chat, the OOB catcher, the disposable mailbox, and license verification) require sending the data described below to our servers or our trusted service providers in order to function properly.
1. Data Processed Entirely on Your Device
The following information is stored exclusively in your browser's local extension storage. It is never transmitted to us or any third party unless you choose to export or copy it:
Captured HTTP/XHR/Fetch requests and responses.
Captured WebSocket and WebRTC traffic.
Secrets-scanner findings and JavaScript analysis results.
Repeater history, Automator run results, Target Scope rules, and custom header, blacklist, or regex configurations.
The BOLA/IDOR Hunter's saved request lists.
Extension preferences (such as theme and filters).
We do not have access to this data, nor is it sent to our service providers or any other external entities by the Extension itself.
- Data Collected for Account & Hunter's Plan Features
If you create an account or subscribe to the Hunter's Plan, we collect the following data strictly to operate the specific features they relate to:
Data Collected When Used For
Email address, hashed password, authentication identifier, and account ID. You create an account. Authentication (via Firebase Authentication) and license verification. Note that payments and subscription management are handled by our authorized reseller, Freemius.
Auth token and refresh token. You are logged in. Maintaining your session for Hunter's Plan features without requiring constant re-authentication.
Chat messages, username, team membership, and team invites (by email). You use Team Chat or World Chat. Delivering and displaying chat messages within the relevant channels.
Contents of any request sent to the OOB Interaction Catcher (method, headers, body, source IP address). Any request is made to your assigned OOB callback URL. Displaying the captured interaction to help you confirm blind vulnerabilities. Note: This can include data from systems you are testing (see Section 3).
Emails received at a claimed disposable mailbox alias (sender, subject, body). You claim an alias and it receives an email. Displaying received mail in your dashboard inbox.
Target URLs submitted to the Request Smuggling Detector or GraphQL Analyzer. You run a scan. Performing the scan and returning the results. This data is processed in-memory and is not stored long-term.
3. Third-Party Data Capture
The OOB Interaction Catcher and Disposable Mailbox are designed to record any incoming requests or emails directed to your assigned addresses. By design, this may include IP addresses, headers, and bodies of requests from systems you are testing, which could encompass third-party operational data. This functionality is core to how webhook and callback testing services operate. You are solely responsible for using these features only against systems you own or are explicitly authorized to test, and for handling any resulting data appropriately in accordance with our Terms of Use.
- Cookies Permission
The BOLA/IDOR Hunter's cookie-swap feature utilizes your browser's cookies API to temporarily read and overwrite a cookie for a domain you are actively testing. This allows requests to be sent with a substituted session value before restoring the original value. This process occurs entirely within your local browser's cookie store; your cookie values are never transmitted to our servers. - Debugger & Proxy Permissions
The JS Analyzer and Live Interceptor utilize Chrome's Debugger API to inspect and modify traffic on tabs you are actively debugging, specifically when you choose to pause a request. The Proxy Configuration feature interacts with the proxy API only if you explicitly configure a custom proxy. Both tools operate locally within your browser and do not transmit your browsing traffic to us. - Third-Party Service Providers
We partner with the following trusted service providers to operate the Hunter's Plan features. Each provider processes only the data necessary for its designated purpose:
Firebase (Google): Provides authentication services and infrastructure for real-time feature message delivery.
Supabase: Provides secure storage for OOB interaction logs and mailbox emails as described above.
Freemius: Serves as our authorized reseller, handling payments and subscription/license management. We share your account email with Freemius to verify an active Hunter's Plan subscription. Freemius's own privacy policy governs their handling of your data.
7. Data Sales
We do not sell or rent your personal data to third parties. Furthermore, we do not use your data for advertising, determining credit-worthiness, or lending purposes. Any data collected is used solely for the operational purposes stated within this policy.
- Data Retention
Account details, chat logs, OOB interaction logs, and mailbox data are retained for as long as your account remains active. You may request the deletion of your account and its associated cloud data at any time by contacting us (see Section 12). We will fulfill such requests within a reasonable timeframe, barring any legal obligations to retain certain information. - Your Choices & Rights
You may use all free features of the Extension without creating an account or sending any data to us.
The Hunter's Plan cloud features are strictly opt-in and activate only upon registration and usage.
You may request access to, export of, or deletion of your account data at any time.
Uninstalling the Extension immediately ceases all local data collection. - Children's Privacy
API Sniffer is a professional developer and security-testing tool. It is not directed at, nor intended for use by, individuals under the age of 13. We do not knowingly collect personal data from children. - Changes to This Policy
Should we make material changes to our data collection or usage practices, we will update this page accordingly. Where required, we will notify you directly (e.g., via an in-extension notice) before these changes take effect. - Contact Information
If you have questions about this policy or wish to make a request regarding your data, please contact us at:
Entity: Bahawal Ali
Email: bahawalofficial218@gmail.com
Phone: +923294675295
Website: store.bahawal.top/sniffer