Privacy Policy
Website Reputation Checker (“the extension,” “we,” “us”) gives you an AI-generated assessment of how trustworthy the website you're viewing is likely to be, powered by Google's Gemini model. This policy explains the one piece of browsing data we need to do that, how we protect it, and the choices you have. We're available for Chrome, Microsoft Edge, Firefox, and Safari, and this policy applies to every version.
The extension and service are intended only for users in the United States. We don't offer them to users in the European Economic Area, the United Kingdom, or Switzerland. If you install the extension from outside the United States, your data is still processed in the United States and you use it at your own discretion.
To assess a site, the extension sends its bare hostname — the domain only, such as
example.com — to our servers. That's all. We never send the full URL, the path, query strings,
fragments, page content, form inputs, cookies, or anything that identifies you. The hostname on its own tells us
which site to evaluate and nothing about you personally.
The extension checks a site automatically when you open it, so the color-coded toolbar icon is ready as you browse. Two things keep this to a minimum: well-known sites on a built-in trusted list are recognized on your device and never sent anywhere, and a site you've seen recently is served from a local cache instead of being sent again.
The assessment is produced by Google's Gemini model (gemini-2.5-flash), which we
access through Google Cloud's Vertex AI. We send Vertex AI only the bare hostname, and it
returns a rating. Google acts as our processor under the Google Cloud Data Processing Addendum.
To judge new and lesser-known sites accurately — including scam sites too recent to appear in a model's training data — the assessment uses Google Search grounding, which checks the hostname against current web information.
Separately, if Google's automated systems flag a request as suspicious, Google may log it for up to 90 days to investigate abuse of its services. This applies only to flagged requests and is never used to train its models.
To enforce request limits and prevent abuse, our servers process your IP address with each request. We do
not store it in raw form: it is immediately converted to an irreversible hash using
HMAC-SHA256 with a secret salt held only by us, and the original address is discarded. We also
configure the platform's automatic request logs — which would otherwise record your IP — to drop it at the point
of collection, so it isn't retained there either. The hash lets us count requests from a source without keeping
the address.
To avoid re-checking the same site, the extension keeps a brief cache of recent results on your device — about one hour — in your browser's local storage, keyed by hostname. Nothing in this cache is sent to us, and you can clear it any time from the extension's options page, which also shows a short privacy summary. There is no account and nothing else to configure.
On our server (Google Cloud) we keep two things, neither tied to your identity or IP:
We never use your data for advertising, personalized profiling, credit or lending decisions, or to train models — ours or Google's.
Two simple bases:
We keep data only as long as needed, and never tied to your identity:
HMAC-SHA256 hash is automatically deleted after about
2 hours; the raw IP is never stored.We do not build long-term profiles tied to you.
We transmit all data over encrypted connections (HTTPS/TLS), send only the bare hostname, and store IP data only as a keyed hash so we never hold raw addresses at rest. Our AI processing runs on Google Cloud, which maintains enterprise-grade security and compliance certifications. We restrict access to our systems and review our practices regularly. No system is perfectly secure, but we protect your data with measures appropriate to its sensitivity.
The service is operated from, and intended for, the United States. Our servers and our AI processing (Google
Cloud Vertex AI) run in the United States (region us-central1), pinned at the project level, and any
data described here is processed there. Requests to Google's AI are made from our server using a service account,
so Google receives only the hostname — not your IP or identity. We don't offer the extension to users in the
EEA, UK, or Switzerland; if you install it from outside the United States, your data is still processed in the
United States.
Depending on your state, you may have the right to know what personal information we collect, to request its deletion or correction, and to opt out of its sale or sharing. We do not sell or share your personal information as defined under the CCPA/CPRA, and we won't discriminate against you for exercising any right.
Because we store IP data only as a one-way hash, and we don't tie hostnames to your identity, we usually cannot link the data we hold back to you as an individual. We aren't required to collect extra information solely to identify you — so for some requests we may be unable to locate data relating to you, or may need more detail from you to act.
Email privacy@inkme.blue and we'll respond within the time the law requires. We may need to verify your request first.
The extension is not directed to children, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us data, contact us and we'll delete it.
We distribute through the Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons (AMO), and the Apple App Store (as a Safari extension), and we follow each store's data rules.
Our use of data collected through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the data only to provide the extension's single purpose — assessing website trustworthiness — and never transfer it except as that policy permits (for example, to a service provider like Google Cloud that processes it to deliver the feature, for security, or to comply with law). The same limited-use principles apply to our Microsoft Edge listing.
We declare the data this extension transmits in its manifest, so Firefox shows you that disclosure and asks for your consent when you install. Sending the site hostname to generate an assessment is part of the extension's primary function, and you can withdraw consent by uninstalling.
Our App Privacy information on the App Store lists the data this extension handles. We declare the site hostname under “Browsing History,” used for app functionality and not linked to your identity, consistent with this policy and our App Store privacy labels.
We may update this policy as the extension evolves or the law changes. We'll revise the “Last updated” date and, for material changes, give a more prominent notice. Continued use after an update means you accept the revised policy.
Questions about this policy or your data? Email us at privacy@inkme.blue, or write to us at:
InkMeBlue LLC
522 W Riverside Ave Ste N
Spokane, WA 99201-0581
United States
InkMeBlue LLC is the data controller responsible for your information.