Skip to content

Browser Extensions Privacy Policy

How Sukesh Das's Chrome extensions, including Undersite, handle data: what each one reads, what it sends and what it never collects.

Last updated: 4 October 2026

This policy covers the browser extensions I publish on the Chrome Web Store as Sukesh Das. The first part sets out the rules every one of my extensions follows. After that, each extension has its own section explaining exactly what it does with data. For this website itself, see the main Privacy Policy.

Extensions covered by this policy

ExtensionWhat it doesData it collects
UndersiteShows what a website is built with, how its SEO is set up and where it is hostedNone
BlockwiseFinds Squarespace block and section IDs and suggests ready-made CSS snippetsNone

Rules that apply to all my extensions

  • No selling of data. I never sell, rent or trade user data, to anyone, for any reason.
  • Single purpose. Any data an extension handles is used only for that extension’s stated purpose, never for advertising, profiling or anything unrelated.
  • No credit or lending use. User data is never used to decide creditworthiness or for lending.
  • Fewest permissions possible. Each extension asks only for the permissions it needs. Wherever I can, broader access is optional and requested only when you turn on the feature that needs it.
  • No remote code. All code ships inside the extension package. Nothing is downloaded and run later.
  • Chrome Web Store policy. The use and transfer of user data by my extensions complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

If an extension ever needs to collect personal data, its section below will say exactly what, why, where it goes and how long it is kept, and the extension’s listing will show the same before you install it.

Undersite

Undersite is a free extension that shows what a website is built with, how its SEO is set up and where it is hosted. It collects no user data. It has no servers, no accounts, no analytics, no telemetry and no ads, and I never receive anything from your use of it.

What happens when you scan a page

Undersite only runs when you click its icon on a tab. During a scan it:

  1. Reads structural information from the current page inside your browser: meta tags, script and stylesheet URLs, element class names and a limited sample of the page markup. It does not read cookies, form inputs, passwords or anything you typed.
  2. Checks a fixed list of well-known JavaScript variable names (such as Shopify or jQuery) to see whether they exist on the page.
  3. Makes one request to the page’s own address to read its response headers, and reads the site’s public robots.txt, llms.txt and sitemap files from the same site. These requests go only to the site you are scanning and are sent without cookies or credentials.
  4. Looks up the site’s public DNS records, as described below.

All of the analysis happens locally on your device.

DNS lookups

To identify hosting, DNS and email providers, Undersite queries Cloudflare’s public DNS-over-HTTPS resolver at cloudflare-dns.com. The only thing sent is the hostname of the site you chose to scan (for example example.com). No identifiers, cookies or credentials go with the request. If your network blocks this service, Undersite still works and leaves out the DNS section.

Optional features that contact other services

Two features contact a service other than the DNS resolver. Both are opt-in and never run on their own, and Chrome asks for their permission only the first time you use them.

  • Find sites on this IP asks HackerTarget (api.hackertarget.com) which other domains share the server’s IP address. Only that server IP address is sent.
  • Check plugins for updates asks the official WordPress directory API (api.wordpress.org) for the latest versions of the plugins, theme and core detected on a WordPress site. Only public plugin and theme slugs are sent (for example elementor).

If you never press these buttons, Undersite never contacts these services. You can revoke either permission at any time at chrome://extensions.

Storage

Scan results are cached in Chrome’s session storage so going back to a scanned tab is instant. Session storage is held in memory, is never synced and is cleared when the browser closes. Nothing is written to persistent storage or sent to any server.

Permissions

PermissionWhy it is needed
sidePanelShows the results panel
activeTabGives access to the one tab you clicked the icon on, only after you click
scriptingRuns the read-only collector in that tab
storageThe session-only results cache described above
Optional: access to all sitesOff by default. Lets tabs scan automatically without clicking the icon each time. It changes nothing about what is read or stored.
Optional: access to api.hackertarget.comOff by default. Used only by “Find sites on this IP”.
Optional: access to api.wordpress.orgOff by default. Used only by “Check plugins for updates”.

Blockwise

Blockwise is a free extension that finds the IDs of blocks and sections on Squarespace sites and suggests CSS snippets from my Squarespace snippet library. It collects no user data. It has no accounts, no analytics, no telemetry and no ads.

What happens when you use it

  1. Blockwise only runs on a tab after you click its icon (or press its shortcut). It reads the page structure inside your browser, such as block and section IDs and class names, to work out what you clicked. It does not read cookies, form inputs, passwords or anything you typed.
  2. To show the snippet list, it requests the list of snippet titles from sukeshdas.com. When you preview, copy or add a snippet, it requests that one snippet’s CSS (and, for a few widgets, plain HTML). No information about you or the page you are on is sent with these requests: no page address, no IDs from the page, no cookies. On first use, the extension receives a random install code from sukeshdas.com and sends it with these requests so abuse can be limited. The code is not linked to you, your browser profile or any account.
  3. Previews are applied only in your own browser tab. Nothing is changed on the website itself until you paste the code into Squarespace yourself.

Blockwise never downloads or runs JavaScript. Snippet HTML is cleaned before it is shown (scripts, event handlers and script links are removed). Like any website, sukeshdas.com receives the standard request details your browser sends, such as your IP address, which my host uses briefly to stop abuse (for example, limiting how many snippets can be requested per hour). It is not used for anything else.

Storage

Blockwise keeps the snippet list, the snippets you added for a site (up to five at a time) and your panel height in Chrome’s extension storage on your device. Loaded snippet code is kept in session storage, which is cleared when the browser closes. None of this is synced or sent anywhere. Removing the extension deletes it.

Permissions

PermissionWhy it is needed
activeTabGives access to the one tab you clicked the icon on, only after you click
scriptingOpens the Blockwise panel in that tab (and inside the Squarespace editor preview)
storageThe on-device storage described above
alarmsRefreshes the snippet list every 30 minutes so new snippets appear
Access to sukeshdas.comLoads the snippet list and snippet code from my library

Children

My extensions are not aimed at children, and none of them knowingly collects personal data from anyone under 16.

Changes to this policy

When I publish a new extension or change what an existing one does with data, I update this page and the date at the top before that version is released.

Contact

Questions about any of my extensions or this policy? Email [email protected] or use the contact form.

Booking new projects

Have a project in mind?

Send a short brief. I reply by email with next steps.

Sukesh Das

Usually replies within 4 hours9 AM to 11 PM, Bangladesh time