This Privacy Policy explains how the NetKrypton Protect browser extension ("the Extension") handles data when you install and use it. It is issued by the extension's developer and applies specifically to the Extension — not to the NetKrypton.com web portal or any other WebOrbiton Team product, which are covered by their own policies.
The administrator of personal data in connection with the Extension is:
Igor Oprządek
Bągart 14A, Poland
E-mail: privacy[at]weborbiton.com
No Data Protection Officer has been appointed.
NetKrypton Protect is a free browser extension developed by the WebOrbiton Team that blocks malware domains, trackers, advertising hosts, and malicious scripts through network-level request blocking and on-device page analysis.
The Extension is built around a local-first principle: settings, statistics, and page
analysis are processed and stored exclusively on your device, using the browser's
chrome.storage.local and standard DOM APIs. This data is never
transmitted to us except where explicitly described in Section 6.
Uninstalling the Extension removes all locally stored settings and statistics, since the browser deletes the associated storage automatically.
Configuration data (local only) — protection toggles, theme and appearance preferences, and per-site exceptions you configure. Stored on-device.
Protection statistics (local only) — counts of blocked items per category (malware, trackers, ads, scripts), tracked per browser tab and per domain, shown in the popup and settings dashboard. Stored on-device and never transmitted to us.
Page content analysis (in-browser only) — the Extension inspects the structure of pages you visit (script, iframe, image, and link elements) to detect and block known tracking/advertising hosts and malicious script patterns (e.g. cryptojacking, keyloggers, payment skimmers, obfuscated code). This analysis runs entirely inside your browser; page content is not sent to us.
Blocklist requests — see Section 6 for the technical network requests the Extension performs.
The Extension does not collect passwords, payment details, form contents, or any data that identifies you personally.
Each browser permission requested by the Extension is used strictly for the technical purpose below.
| Permission | Purpose |
|---|---|
| storage | Local storage of settings and statistics on your device |
| tabs / activeTab | Read the domain of the active tab to show protection status and apply per-site exceptions |
| scripting | Inject the content-analysis script that inspects page structure |
| declarativeNetRequest(WithHostAccess) | Block network requests to known malware, tracker, and ad hosts at the network layer, without us reading request contents |
| alarms | Schedule the periodic (24-hour) blocklist refresh |
| webNavigation | Detect navigations so blocked domains redirect to the warning page correctly |
| host_permissions (<all_urls>) | Allow protection to function across all websites you visit |
The Extension makes two categories of outbound network requests, both technical in nature:
Blocklist updates. Approximately once every 24 hours (or when you manually refresh), the Extension downloads an updated malware domain list from list.netkrypton.com, infrastructure operated by us. This is a standard file download; no personal or account data is attached to the request beyond the technical metadata inherent to any HTTP request (e.g. your IP address, as with any web request).
Script analysis (optional, off by default). If you enable the Script Analysis feature, the Extension may fetch the content of an external script file referenced by a page you visit, in order to evaluate it locally against malicious-code heuristics. The fetch is performed to obtain the script's technical content only — it does not include your browsing history, account information, or any personal identifier.
No search queries, form data, or page content you generate is ever transmitted to us.
Because processing is local-first, the Extension has a single technical sub-processor:
WebOrbiton-operated infrastructure serving the malware blocklist file. Receives standard HTTP request metadata only; no personal data is intentionally collected or stored in connection with these requests.
Important: NetKrypton Protect does not sell, share, or transfer user data to any third party for advertising, profiling, or commercial purposes.
When the Extension blocks a navigation to a malicious domain, it shows a local warning page. The blocked domain is passed only through the page's own URL parameters inside your browser — it is not sent to us or logged remotely.
| Data | Retention |
|---|---|
| Settings & site exceptions | Stored locally until changed, reset, or the Extension is uninstalled |
| Protection statistics | Stored locally until cleared by you or the Extension is uninstalled |
| Blocklist cache | Stored locally, refreshed approximately every 24 hours |
| Page content analysis | Not retained — evaluated in-memory during the browsing session |
Since the Extension does not transmit personal data to our servers, most GDPR rights are exercised directly by you, on-device, through:
For any other questions regarding data processing, or to lodge a complaint with the supervisory authority (PUODO – Polish Personal Data Protection Office), contact us at privacy[at]weborbiton.com.
The Extension does not knowingly collect personal data from anyone, including children, since it does not require an account and processes data locally. The Extension is not directed at children and includes no age-specific features.
The Extension does not use profiling or automated decision-making affecting users (Art. 22 GDPR). Blocking decisions are made locally against static rule sets and heuristics, not against any profile of the user.
Since the Extension does not transmit personal data to our servers, no routine international transfer of personal data occurs in connection with its use. The blocklist infrastructure described in Section 8 is operated within the WebOrbiton Team's standard hosting setup.
We reserve the right to update this Privacy Policy. The version number and effective date at the top of this document will be updated accordingly. Material changes will be communicated through the Extension's release notes or the About section of its settings.