Skip to content
PayloadPigeon
PlaygroundHelpLegal & contact
Product/Help

KIRAVS D.O.O. / Montenegro

Data & Security

How PayloadPigeon handles traffic, local saved data, permissions, exports and reports.

Product informationUpdated: September 27, 2026PayloadPigeon 0.5.0
Local encrypted library

Password protection applies to saved work, not every temporary value.

Real network effects

Send, Ready and enabled Rules can affect a server or tested page.

Protection limits

Local library encryption does not protect plaintext exports or data already sent to a server or page.

On this page

  1. 1. What this page covers
  2. 2. Data and recipients
  3. 3. Permissions
  4. 4. Capture and library lifecycle
  5. 5. Password, recovery and protection boundaries
  6. 6. Credential modes
  7. 7. Exports and sharing
  8. 8. WebSocket and page boundary
  9. 9. Playground data notice
  10. 10. Report a vulnerability

1. What this page covers

This page explains what data PayloadPigeon processes, how the local library is protected, and what happens when you send requests, export files or affirmatively opt in to aggregate usage telemetry. The extension, optional telemetry, website, learning Playground, and support enquiries involve different data flows. See the Privacy Policy for details.

2. Data and recipients

DataWhere / recipientControl
Temporary TrafficExtension session storageStart, Stop, Clear and the documented Capture lifecycle
Saved libraryEncrypted local extension storage; some technical metadata remains openLocal password, recovery key, Lock and deletion
Website analyticsCloudflare Web Analytics via Automatic setupAggregate website usage and performance only; no advertising or session replay; separate from extension telemetry
Optional extension usage telemetryCloudflare Workers Analytics EngineOff by default; affirmative opt-in; aggregate allowlisted counters only
Backend Send, Ready and enabled RulesUser-selected server or tested pageReal network or page effects; review the active Test or Rule
Downloaded filesUser-selected device and later recipientsReadable JSON/Markdown or a package with a separate file password
PlaygroundPayloadPigeon demo service and its infrastructureSample data only; page controls and Backend Send can reach its endpoint
Website / supportHosting and email providersSeparate Privacy Policy and contact choices

3. Permissions

PermissionPurpose and activationHow it stops
debuggerSupported Capture and modification for the selected tabUse Stop for Capture; disable or uninstall the extension to stop its use
sidePanel / tabsWorkspace UI and selected-tab contextClosing the panel does not revoke tabs access; disable or uninstall the extension to stop its use
storageTemporary state and saved workUse the matching Clear, delete or Lock control; uninstall removes extension access
unlimitedStorageRequired capacity beyond Chrome’s standard local quota behaviorUsed by the installed extension; disable or uninstall it to stop use. Disk space and product limits remain finite
Optional HTTP/HTTPS host accessSelected Backend HTTP destinationRevoke the optional site access in Chrome; it is separate from required permissions

4. Capture and library lifecycle

ActionCapture / runtime TrafficSaved library
Start capture this tabStarts selected-tab CaptureDoes not create or unlock the library
StopEnds active CaptureDoes not Lock or delete saved data
Clear TrafficClears the applicable temporary listDoes not delete Tests/Results
Last panel closesEnds Capture after up to 1 s reconnection graceDoes not equal Lock or revoke tabs access
Top-level origin changesEnds the accepted Capture scopeSaved library remains
LockEnds supported work and clears relevant temporary values, the unlock key and draftsKeeps the encrypted library
Chrome restart / extension reload, update or disableRequires unlock after the session key is lostEncrypted library remains

5. Password, recovery and protection boundaries

Masking hides a value on screen; redaction removes or replaces it in a particular representation; encryption protects saved content with key material. They are not interchangeable. Saved collections use AES-256-GCM before local persistence. In the unlocked state plaintext and key material exist in memory/session storage. Protection does not guarantee physical erasure or defend a compromised OS, browser profile or privileged extension context.

6. Credential modes

ModeWhat it doesLimit
Current sessionUses an eligible recent captured header from the same contextStops on missing, ambiguous or mismatched context; no promise for arbitrary body/query credentials
Don't sendOmits the selected headerDoes not remove cookies or every form of authentication
Test valueStores and sends the chosen literalCan be a real secret despite its name; use synthetic values

Cookie, Set-Cookie and Proxy-Authorization are not ordinary editable Test values. Heuristic warnings and evidence sanitisation are separate controls.

7. Exports and sharing

FormatProtectionContents / limits
Standard JSON bundleReadable plaintextSelected Plan content; optional history/evidence; not runtime, Advanced Rules or settings
Protected packageSeparate file passwordRecipient previews and explicitly imports into their own protected library
Markdown ResultReadable plaintext reportNot an import format; may include selected saved evidence

The author’s local password/recovery key is never shared as the file password. Import is Protect/Unlock → Choose file → file password if protected → preview/review → explicit Import. Import never starts Capture, Send, Ready or Current Check.

8. WebSocket and page boundary

Supported control is limited to compatible page text/JSON sockets. Early sockets may require reload/new connection; Worker, binary and ambiguous sockets can be observe-only. Network verified is not a business-success verdict, and Related server message is not simply the next incoming frame. The tested page receives messages intended for it but must not receive unrelated extension data. No exploit details are published here.

9. Playground data notice

Requests and messages that you direct to the Playground endpoint are processed by the PayloadPigeon demo service. This includes the page controls and a Backend Send aimed at that endpoint. Application code keeps values only for the request or WebSocket connection and does not write them to a database, KV, files or analytics. See Privacy Policy § Playground for infrastructure handling and the details confirmed for publication.

10. Report a vulnerability

Report a suspected vulnerability privately to security@payloadpigeon.com. Include the PayloadPigeon and Chrome versions, concise reproduction steps, the expected and observed impact, and sample data from a system you own or are authorised to test.

Do not include live credentials or third-party data, and do not use denial of service, social engineering or systems without permission. A bounty, fixed response time or remediation deadline is not promised.

All documents →
PayloadPigeon

A product of KIRAVS D.O.O.
Registered in Montenegro.

Product

How it worksPlaygroundUsing PayloadPigeonWatch the videoSupport

Legal & company

Data & SecurityPrivacy PolicyTerms & LicenceAccess, cancellation & refundsContact & company detailsReport a vulnerability
© 2026 KIRAVS D.O.O. · PayloadPigeonFree Early Access · No paid subscription