1. Scope and separate data flows
This notice covers the PayloadPigeon Chrome extension, this marketing website and its self-hosted video, support or security correspondence sent to KIRAVS D.O.O., and the separate HTTP/WebSocket Playground when it is publicly enabled. They do not all have the same recipients or purposes.
KIRAVS D.O.O., registered in Montenegro, operates the site and correspondence channels and, when enabled, the Playground. Registered address: CETINJSKI PUT LAMELLA 5/17 STAN 4 PODGORICA. Privacy contact: privacy@payloadpigeon.com. If you test for an organisation, that organisation remains responsible for its authority and data choices.
2. Extension data and local protection
Runtime Traffic
After Start capture this tab, supported selected-tab traffic can include URLs, headers, bodies, timing and text/JSON WebSocket messages, including sensitive data.
Runtime Traffic and the session unlock key are held temporarily in trusted chrome.storage.session and follow the documented Capture and session lifecycle.
Encrypted saved library
Saved Tests, Plans, Results, snapshots, evidence, notes and Advanced Rules.
Encrypted before chrome.storage.local using the local password-protected library. Open technical metadata and allowlisted settings/entitlements remain outside that encrypted content. While unlocked, data and the key exist in memory/session storage.
A password is created at the first durable action. A separate recovery key can unlock the existing library and allow a password change; it is not a file backup or email recovery. Losing both after Lock means KIRAVS cannot restore the local library. One-off Capture/Traffic/Modify actions do not require library setup.
3. Capture, permissions and real network actions
Capture starts only with Start capture this tab for the selected ordinary HTTP/HTTPS tab and supported related targets. Opening the panel or switching tabs does not start Capture for a new tab. Stop, a top-level origin change and closing the last controlling panel end Capture under the accepted lifecycle; the last panel allows up to one second for reconnection. Stop, Clear Traffic and closing a panel are not Lock.
Required permissions are debugger, sidePanel, storage, tabs and unlimitedStorage. Backend Send may request optional HTTP/HTTPS host access for a destination the user has reviewed. Plain HTTP can be used for local or development endpoints; HTTPS is recommended whenever data is sensitive. A granted destination can remain in Chrome until revoked.
Anonymous telemetry uses a distinct optional host grant. Only after affirmative opt-in, the extension may request access specifically to https://payloadpigeon.com/* and send accepted batches to /api/telemetry. That grant does not give telemetry captured Traffic: telemetry never receives request or response bodies, headers, cookies, credentials, WebSocket payloads, Test names, Result notes or evidence, or other user-entered content. It does not request broad https://*/* access for telemetry.
unlimitedStorage removes Chrome’s standard local-storage quota behavior, but does not create infinite disk, expand storage.session or remove product limits.
The extension does not automatically upload captured traffic or the saved library to a PayloadPigeon cloud service. Testing can send requests or messages to the chosen server and deliver modified responses to the tested page. Backend HTTP Send does not follow redirects automatically. Export creates a file on the device; subsequent sharing is controlled by the user.
4. Credentials, saved values, evidence and exports
Supported backend HTTP credential headers use one of three modes: Current session selects an eligible recent captured value from the same context and stops if none is unambiguous; Don't send excludes that specific header, not all authentication; Test value stores and sends the literal chosen by the user. Cookies are handled separately. Cookie, Set-Cookie and Proxy-Authorization are not ordinary editable Test values.
Potentially sensitive URL, body and message fields receive heuristic review. Keep saves applicable values in the encrypted Test; Remove changes the copy; Cancel does not save. A warning is not proof of a live credential, and automatic detection cannot find every secret. Result evidence is sanitised separately; keeping Test configuration does not include raw evidence.
Full evidence is the full available body after supported sanitisation, not raw network bytes. Selected JSON and labelled legacy excerpts are different. Standard JSON bundles and Markdown are readable files. A protected package uses a separate file password, never the author’s local library password or recovery key. Disabling evidence does not remove configured payload from a Test or snapshot. Bundles exclude runtime capture, Advanced Rules and settings/entitlements and are not complete backups.
5. Optional anonymous usage analytics
Anonymous usage analytics is optional and starts only after affirmative opt-in in the extension. An upload contains the extension version, Chrome major version, aggregation period and aggregate counts from a fixed feature allowlist. It is used only to understand and improve PayloadPigeon.
Telemetry does not contain URLs or domains; request or response bodies; headers, cookies or credentials; WebSocket messages; captured traffic; page titles or tab IDs; Test or Test Plan names; Result notes or evidence; user-entered strings; email addresses or phone numbers; an IP supplied by the extension; or an account, user, persistent installation or device identifier. Unknown fields are rejected rather than stored.
Cloudflare processes the HTTPS request to deliver and protect the endpoint and may technically process ordinary network metadata such as a source IP. The Worker may use that signal for infrastructure rate limiting, but does not intentionally write it to the PayloadPigeon telemetry dataset or custom logs. The dataset stores only accepted aggregate counters and the limited version/context fields described above, using a server-side timestamp, for up to 3 months. There is no separate long-term raw-event archive.
6. Website and ordinary hosting
The repository serves self-hosted scripts, styles, images and video and does not manually embed an analytics beacon, advertising pixel, third-party player, external font or tracking-cookie code. Playground controls are not a support form, but selecting their send controls transmits the entered sample fields to the demo service.
- Website host / CDN
- Cloudflare Workers
- Hosting regions
- Cloudflare global network. Workers execute by default in a data center close to where the request is received; no regional execution restriction is configured.
- Website log data
- PayloadPigeon does not enable Cloudflare Workers Logs/Observability and does not intentionally store request or response bodies in application logs. Cloudflare may process limited network, routing, security, and traffic metadata as part of operating and protecting the service.
- Log retention / backups
- No custom PayloadPigeon application-log retention period is configured because Workers Logs/Observability is disabled. Cloudflare may retain service and network metadata according to its applicable service and privacy policies.
- Email provider
- Proton Mail
- Email processing regions
- Proton Mail stores mailbox data on servers located in Switzerland, Germany, or Norway. Encrypted offline backups may be retained for up to 30 days.
Cloudflare Web Analytics is described separately below. Its automatic edge injection does not change the separate hosting and security processing described here, including possible processing of ordinary network metadata such as a source IP. Ordinary requests to APIs you choose outside Playground are not proxied through KIRAVS hosting by default.
7. Website analytics
Cloudflare Web Analytics is enabled for visits to payloadpigeon.com through Cloudflare Automatic setup. Cloudflare injects the integration at the edge; PayloadPigeon does not manually embed a script or keep a Web Analytics site token in this repository. Its purpose is aggregate website usage and performance analytics.
Website analytics may provide aggregate metrics such as visits, page views, page paths, referring sites, approximate country, device, browser and operating-system information, and web-performance metrics. PayloadPigeon does not use Google Analytics, advertising analytics or session replay, and does not create a custom visitor identifier for this integration.
This website analytics flow concerns visits to payloadpigeon.com and is separate from the Chrome extension’s optional anonymous usage telemetry. Extension telemetry requires affirmative opt-in, sends accepted batches to /api/telemetry, and stores only allowlisted numeric feature counters in Cloudflare Workers Analytics Engine; it never receives captured Traffic or user content. Cloudflare infrastructure and network processing remain subject to the separate disclosures above, and applicable notice or consent requirements can depend on jurisdiction.
8. Playground demo service
The Playground is a separate learning page backed by an HTTP/WebSocket demo service. Requests and messages you send there are processed by KIRAVS’s service on the listed infrastructure. The Playground does not automatically access your PayloadPigeon library, local password or recovery key. Use sample data only.
- Target runtime
- Cloudflare Workers
- Processing regions
- Cloudflare global network. Workers execute by default in a data center close to where the request is received; no regional execution restriction is configured.
- Infrastructure log data
- PayloadPigeon does not enable Cloudflare Workers Logs/Observability and does not intentionally store request or response bodies in application logs. Cloudflare may process limited network, routing, security, and traffic metadata as part of operating and protecting the service.
- Log retention
- No custom PayloadPigeon application-log retention period is configured because Workers Logs/Observability is disabled. Cloudflare may retain service and network metadata according to its applicable service and privacy policies.
Application code keeps Playground request fields only for the request or socket connection and does not write them to KV, D1, files, the usage telemetry dataset or a database. It may use a coarse network signal for production abuse controls. The infrastructure provider may process security, access or invocation information under the confirmed account configuration.
9. Support and reasons for processing
When you contact us, we receive your email address, message and any files you choose to send, together with ordinary email metadata. Provide only the information needed to explain the issue. Do not send live tokens, passwords, payment-card details or unredacted customer traffic. We do not automatically access your browser or local Results.
Where the GDPR or a similar framework applies, the relevant basis depends on the activity: responding to a request about the product or our service relationship; legitimate interests in answering other enquiries, maintaining website security and investigating faults; compliance with a legal obligation; or consent for a genuinely optional purpose. These grounds are not a blanket authorisation to reuse your data for unrelated purposes.
Support and attachment retention: Support correspondence is retained for up to 12 months after the last communication, unless longer retention is required to resolve an ongoing issue or comply with legal obligations. Deleted mailbox data may remain in encrypted Proton backups for up to 30 additional days.
Submitting material for support authorises us to examine that specific material for the enquiry, not to publish it or use it for advertising. We do not sell inspected traffic or use it for personalised advertising or credit decisions. This website does not make automated decisions about you with legal or similarly significant effects.
10. Retention, deletion and recovery
Clear Traffic removes the applicable temporary list; deleting Tests, Plans, Results or evidence uses the corresponding extension control. Lock ends supported runtime work and clears relevant session/cache/draft data without deleting the encrypted library or reversing server actions and file uploads already started. Clearing ordinary Chrome browsing history is not presented as deleting extension storage.
Encrypted saved items remain until removed or the extension/profile storage is deleted. Uninstall can remove local extension storage; export first if needed. A recovery key opens an existing library but cannot restore a deleted profile. Exported and recipient copies are separate and are not recalled by local deletion. Physical erasure from memory, SSD or backups is not guaranteed.
The optional aggregate telemetry dataset follows its stated retention of up to 3 months. Playground application data is not persisted by this code. Provider logs and support records follow the separately confirmed periods above: Support correspondence is retained for up to 12 months after the last communication, unless longer retention is required to resolve an ongoing issue or comply with legal obligations. Deleted mailbox data may remain in encrypted Proton backups for up to 30 additional days.
11. Location and international transfers
KIRAVS is established in Montenegro. Local extension traffic is not automatically transferred to us because of that location. Website and support records may be processed in the regions listed above.
International processing and applicable safeguards: Yes. Cloudflare operates a global network and may process service and traffic metadata internationally. Proton Mail stores mailbox data in Switzerland, Germany, or Norway. Messages exchanged with external email providers are also transmitted to those providers according to the destination selected by the sender or recipient.
Where a cross-border transfer rule applies, the relevant provider arrangement and transfer mechanism must be in place. This notice does not claim an EU adequacy decision for Montenegro or that all providers store data exclusively in the EU.
For EU/EEA privacy enquiries, contact KIRAVS at privacy@payloadpigeon.com.
The Playground uses Cloudflare Workers on Cloudflare’s global network, with no regional execution restriction configured. Optional telemetry is delivered to Cloudflare Workers and accepted aggregate counters are stored in Cloudflare Workers Analytics Engine. Cloudflare Web Analytics is a separate website flow enabled through Automatic setup. These provider facts do not by themselves assert a particular legal transfer mechanism.
12. Your privacy rights
Depending on the applicable law and circumstances, you may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent for processing based on consent. Withdrawal does not affect earlier lawful processing. We respond within the applicable statutory time limits and may request only the verification reasonably needed for your request.
Send requests to privacy@payloadpigeon.com. We can act on data we actually hold, not on local browser files we have never received.
You may also contact the Montenegrin Agency for Personal Data Protection and Free Access to Information (AZLP) or the supervisory authority available to you under applicable law. Where EU/EEA rights apply, the EDPB directory lists the national authorities. Mandatory local privacy rights are not limited by this notice.
We can act on Playground, website or correspondence data we actually hold, subject to verified provider controls; we cannot remotely decrypt or delete a library that remains only in the browser. Anonymous extension telemetry has no persistent installation or user identifier that would let us isolate one person’s contribution.
13. Chrome Web Store Limited Use
PayloadPigeon’s use and transfer of data obtained through Google APIs complies with the Chrome Web Store User Data Policy and its Limited Use requirements.
Accessed browsing and traffic data is limited to the disclosed testing purpose. We do not sell it or transfer it for personalised advertising. Human access to material you send for support is limited to the authorised enquiry or another permitted legal or security purpose. See the Chrome Web Store Limited Use policy.
Optional usage telemetry is limited to the aggregate counters described above and is not used for advertising, eligibility, credit decisions or sale. Captured traffic and Google API user data are not included in that telemetry dataset.
14. Free access, changes and contact
There is no paid checkout, subscription billing, account service or automatic cloud library sync in this edition. The Playground flow occurs only through its described controls. Optional aggregate usage telemetry occurs only after affirmative opt-in and is not hidden Capture telemetry.
We will update this page for changed practices and provide required notice for material changes. A new date does not itself provide consent. Privacy contact: privacy@payloadpigeon.com.