← Submission GuardPresented by Likelyr

PRIVACY POLICY / EFFECTIVE JULY 15, 2026

Your form is not our dataset.

Submission Guard is an open-source Chrome extension that gives web forms a private, searchable Sent folder. Its default path is local: no Likelyr account, analytics service, advertising system, or hosted Likelyr data service receives your form answers.

What the extension processes

To save drafts, check a submission, and create a record, the extension may process the website URL, hostname and page title; visible form labels and values; validation state; selected file name, size, type, fingerprint and locally extracted document text; and website confirmation text. Processing begins after you explicitly run Submission Guard on the active tab. If you then choose Always protect this page, automatic activation is registered only for that saved page path until you revoke it. Search, sign-in, and payment forms are excluded from activation.

The extension filters known high-risk categories using input type, autocomplete metadata, and field names or visible labels. It also excludes values matching recognizable private keys, cloud and GitHub tokens, database URLs, environment secrets, Social Security numbers, recovery codes, and payment-card numbers before drafts, receipts, exports, or email are created. These categories also include passwords, payment and bank details, security codes, government IDs, birth dates, medical fields, hidden fields, file-input values, and fields marked private. Websites and secrets vary, so these heuristics cannot guarantee that every sensitive answer is recognized. Users can disable field-value storage for label-only receipts or mark a field private with the documented data attribute.

Where data is stored

Drafts, settings, remembered-page rules, approved-file fingerprints, and submission records are stored in Chrome storage and IndexedDB on your device. Drafts expire according to your chosen retention period. Receipt history follows your chosen limit. Local screenshots are optional, off by default, and never included in an email-bridge request.

You can search, export, delete individual records, revoke remembered pages, or use Delete everything in the extension. That action unregisters remembered-page scripts, revokes optional website and local-bridge access, and clears extension-managed IndexedDB plus local and session storage. Removing the extension also removes extension-managed local storage under Chrome's normal behavior.

Optional email delivery

The dashboard is the canonical Sent folder and email delivery is off by default. A user may run the open-source bridge on the same computer, configure an SMTP account in its private local environment file, and grant Chrome access to that localhost origin. The extension stores the bridge endpoint, destination address, and generated bridge access token; it does not store the SMTP or IMAP password.

When enabled, the extension sends the bridge a filtered receipt containing the attempt status, date, website, URL, page title, eligible answers remaining after heuristic filtering, selected-file metadata, findings, and any confirmation detected before delivery. Screenshots are stripped before transmission. The bridge sends through the SMTP account the user configured. Optional IMAP settings can verify or create the exact outgoing Sent copy. The selected email provider processes the message under its terms; Likelyr does not receive it.

Sharing, sale, and tracking

Submission Guard contains no advertising SDK, behavioral analytics, tracking pixel, remote AI, or data broker integration. Likelyr does not sell form data, use it for advertising, build user profiles from it, or permit humans to read it. Data is shared only with the email infrastructure the user explicitly configures, as needed to deliver that requested feature, or when legally required.

Chrome permissions

  • storage keeps settings, drafts, approved fingerprints, and records on the device.
  • activeTab lets a user run a one-time check on the current page after a toolbar action.
  • scripting injects the packaged checker temporarily or registers it for one saved page path.
  • Optional website access is not granted at install. Chrome permissions are hostname-based, so Chrome names the current hostname after the user chooses Always protect this page; Submission Guard’s registered script is path-scoped and the user can revoke it from the popup or Settings.
  • Optional localhost access connects to an email bridge running on this device after a user-requested test.

Security

The extension's bridge path is localhost-only and uses a bearer token plus recipient allowlist. The open-source bridge includes request limits and receipt deduplication. SMTP and optional IMAP credentials remain in the bridge environment selected and controlled by the user.

Changes and contact

If data practices materially change, the extension will present an updated disclosure before the new processing is enabled, and this policy will be updated.

Privacy and security questions can be sent to wesley.schmiedeskamp@gmail.com. This is the public developer address listed with Submission Guard in the Chrome Web Store. Do not email form answers, authentication tokens, bridge credentials, screenshots containing private data, or other sensitive content.