// permission registry

Browser permissions are trust commitments.

This registry explains what each EXFILTR product expects to request, why it is required, what is not accessed, and whether data leaves the device.

Current registry.

These pages describe planned v1 permission posture. Final Chrome Web Store copy must match actual implementation before submission.

Internal prototype built

TabRest

Local-first browser session memory. Expected permissions focus on saving and restoring tab/session state.

  • Data leaves device: no in current v1 direction.
  • Cloud behavior: none in v1.
  • Release status: pre-release.
Scoped

Refine

User-triggered readability workflow. Expected permissions focus on active-tab access and local preferences.

  • Data leaves device: no by default in current v1 direction.
  • Cloud behavior: none in v1.
  • Release status: pre-release.

Every product must explain the trust surface.

Permission copy is part of launch readiness. If a permission cannot be explained plainly, the scope is not ready.

Requested

What permissions are requested?

The registry names each browser permission before public release and ties it to a concrete user-facing workflow.

Reason

Why is each permission required?

Permissions must be justified in plain language, not hidden behind technical ambiguity.

Not accessed

What is explicitly not touched?

Products should state what they do not read, collect, process, sync, or monitor.

Data behavior

Does data leave the device?

Local-first behavior is preferred. Any cloud behavior must be specific, user-beneficial, and reflected in privacy copy.