Last updated: 4 October 2026
This policy covers the browser extensions I publish on the Chrome Web Store as Sukesh Das. The first part sets out the rules every one of my extensions follows. After that, each extension has its own section explaining exactly what it does with data. For this website itself, see the main Privacy Policy.
Extensions covered by this policy
| Extension | What it does | Data it collects |
|---|---|---|
| Undersite | Shows what a website is built with, how its SEO is set up and where it is hosted | None |
| Blockwise | Finds Squarespace block and section IDs and suggests ready-made CSS snippets | None |
Rules that apply to all my extensions
- No selling of data. I never sell, rent or trade user data, to anyone, for any reason.
- Single purpose. Any data an extension handles is used only for that extension’s stated purpose, never for advertising, profiling or anything unrelated.
- No credit or lending use. User data is never used to decide creditworthiness or for lending.
- Fewest permissions possible. Each extension asks only for the permissions it needs. Wherever I can, broader access is optional and requested only when you turn on the feature that needs it.
- No remote code. All code ships inside the extension package. Nothing is downloaded and run later.
- Chrome Web Store policy. The use and transfer of user data by my extensions complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
If an extension ever needs to collect personal data, its section below will say exactly what, why, where it goes and how long it is kept, and the extension’s listing will show the same before you install it.
Undersite
Undersite is a free extension that shows what a website is built with, how its SEO is set up and where it is hosted. It collects no user data. It has no servers, no accounts, no analytics, no telemetry and no ads, and I never receive anything from your use of it.
What happens when you scan a page
Undersite only runs when you click its icon on a tab. During a scan it:
- Reads structural information from the current page inside your browser: meta tags, script and stylesheet URLs, element class names and a limited sample of the page markup. It does not read cookies, form inputs, passwords or anything you typed.
- Checks a fixed list of well-known JavaScript variable names (such as
ShopifyorjQuery) to see whether they exist on the page. - Makes one request to the page’s own address to read its response headers, and reads the site’s public
robots.txt,llms.txtand sitemap files from the same site. These requests go only to the site you are scanning and are sent without cookies or credentials. - Looks up the site’s public DNS records, as described below.
All of the analysis happens locally on your device.
DNS lookups
To identify hosting, DNS and email providers, Undersite queries Cloudflare’s public DNS-over-HTTPS resolver at cloudflare-dns.com. The only thing sent is the hostname of the site you chose to scan (for example example.com). No identifiers, cookies or credentials go with the request. If your network blocks this service, Undersite still works and leaves out the DNS section.
Optional features that contact other services
Two features contact a service other than the DNS resolver. Both are opt-in and never run on their own, and Chrome asks for their permission only the first time you use them.
- Find sites on this IP asks HackerTarget (
api.hackertarget.com) which other domains share the server’s IP address. Only that server IP address is sent. - Check plugins for updates asks the official WordPress directory API (
api.wordpress.org) for the latest versions of the plugins, theme and core detected on a WordPress site. Only public plugin and theme slugs are sent (for exampleelementor).
If you never press these buttons, Undersite never contacts these services. You can revoke either permission at any time at chrome://extensions.
Storage
Scan results are cached in Chrome’s session storage so going back to a scanned tab is instant. Session storage is held in memory, is never synced and is cleared when the browser closes. Nothing is written to persistent storage or sent to any server.
Permissions
| Permission | Why it is needed |
|---|---|
sidePanel | Shows the results panel |
activeTab | Gives access to the one tab you clicked the icon on, only after you click |
scripting | Runs the read-only collector in that tab |
storage | The session-only results cache described above |
| Optional: access to all sites | Off by default. Lets tabs scan automatically without clicking the icon each time. It changes nothing about what is read or stored. |
Optional: access to api.hackertarget.com | Off by default. Used only by “Find sites on this IP”. |
Optional: access to api.wordpress.org | Off by default. Used only by “Check plugins for updates”. |
Blockwise
Blockwise is a free extension that finds the IDs of blocks and sections on Squarespace sites and suggests CSS snippets from my Squarespace snippet library. It collects no user data. It has no accounts, no analytics, no telemetry and no ads.
What happens when you use it
- Blockwise only runs on a tab after you click its icon (or press its shortcut). It reads the page structure inside your browser, such as block and section IDs and class names, to work out what you clicked. It does not read cookies, form inputs, passwords or anything you typed.
- To show the snippet list, it requests the list of snippet titles from
sukeshdas.com. When you preview, copy or add a snippet, it requests that one snippet’s CSS (and, for a few widgets, plain HTML). No information about you or the page you are on is sent with these requests: no page address, no IDs from the page, no cookies. On first use, the extension receives a random install code from sukeshdas.com and sends it with these requests so abuse can be limited. The code is not linked to you, your browser profile or any account. - Previews are applied only in your own browser tab. Nothing is changed on the website itself until you paste the code into Squarespace yourself.
Blockwise never downloads or runs JavaScript. Snippet HTML is cleaned before it is shown (scripts, event handlers and script links are removed). Like any website, sukeshdas.com receives the standard request details your browser sends, such as your IP address, which my host uses briefly to stop abuse (for example, limiting how many snippets can be requested per hour). It is not used for anything else.
Storage
Blockwise keeps the snippet list, the snippets you added for a site (up to five at a time) and your panel height in Chrome’s extension storage on your device. Loaded snippet code is kept in session storage, which is cleared when the browser closes. None of this is synced or sent anywhere. Removing the extension deletes it.
Permissions
| Permission | Why it is needed |
|---|---|
activeTab | Gives access to the one tab you clicked the icon on, only after you click |
scripting | Opens the Blockwise panel in that tab (and inside the Squarespace editor preview) |
storage | The on-device storage described above |
alarms | Refreshes the snippet list every 30 minutes so new snippets appear |
Access to sukeshdas.com | Loads the snippet list and snippet code from my library |
Children
My extensions are not aimed at children, and none of them knowingly collects personal data from anyone under 16.
Changes to this policy
When I publish a new extension or change what an existing one does with data, I update this page and the date at the top before that version is released.
Contact
Questions about any of my extensions or this policy? Email [email protected] or use the contact form.

