BackPing Privacy Reporter 的隐私政策
BackPing Privacy Reporter 作者: Pierre Di Marco
Privacy policy of the BackPing Privacy Reporter extension for Firefox
This is the part of the BackPing.net privacy policy that concerns the extension. The full policy, which also covers
the website and its optional accounts, is at https://www.backping.net/privacy.
Controller. Pierre Di Marco, Im Flürchen 22, 54309 Newel, Germany. Contact: https://www.backping.net/contact.
BackPing.net is a private, non-commercial project.
In short. The extension analyses the page you are on entirely inside your browser and works without sending
anything. It makes no network requests of its own except the two you ask for: Share sends an anonymized report of
the current site to BackPing.net, and Look up fetches the site's community grade and sends only its hostname.
Firefox asks for your permission the first time you use each. The information it reads is used for nothing but
showing you the analysis: it is not sold, not used for advertising, creditworthiness or lending purposes, and not
passed to anyone except as described here.
What the extension reads on your device. To analyse the page you are on, the extension reads the following
inside your browser, on your device only:
- the addresses of the network requests your open tabs make (hostnames, request types and timing), and the
response headers of the main document; - the cookies your browser has stored for the site you are visiting and for the third-party sites it contacts,
including their values, which are shown in the popup; - the keys and the length, not the content, of localStorage and sessionStorage items (a preview of the values is
shown in the popup only), and the names of IndexedDB databases, caches and service workers; - the calls the page makes to fingerprinting-capable browser APIs, such as reading pixels back from a canvas, and
which script made them; - whether a cookie banner is visible, and the times of your own clicks and key presses on the page. They are used
only to tell whether you answered the banner and are never sent anywhere.
This information is kept per tab in the browser's session storage (storage.session), which lives in memory only and
is deleted when the tab or the browser is closed. The only things the extension may keep permanently (storage.local)
are a developer setting with the address of the report server and a small number recording which version of its
data practices you have acknowledged, so that it can tell you once when what it sends or keeps changes. We never
see any of this unless you press Share or Look up.
The extension changes nothing on your device unless you ask it to. Delete cookie removes the selected cookie or
cookies after a second, confirming click. Test a first visit deletes the cookies the current page receives and the
page's stored data, then reloads the page so that its cookie banner appears again; this signs you out of that site.
Export JSON writes a file to your device that contains the analysis without cookie values or storage contents.
The extension needs the permissions cookies, webRequest, storage and scripting and access to all websites, because
it has to observe whatever site you open. It loads no remote code and does not block or modify anything.
Reports sent from the extension. Sending a report is voluntary: nothing leaves your browser unless you press
Share, and you do not have to provide any data to use the extension. Before it sends a report, the extension
fetches a proof-of-work challenge from BackPing.net and solves it (a fraction of a second of computation); the
challenge contains nothing about you. Both requests carry your IP address, like any request to any server, and the
language the extension is displayed in, so that the server answers in that language. Neither is stored with the
report. A report contains:
- the hostname of the page (never a path, query string or title), its registrable domain, and whether the page was
loaded over HTTPS; - the number of requests the page made and how many of them were insecure (mixed content);
- the third-party sites the page contacted, with request counts and the company and category the extension knows
for them; - the names, attributes (Secure, HttpOnly, SameSite, partitioned) and lifetimes of the site's own cookies and of
partitioned cookies, never their values. Parts of cookie and storage-key names that may be identifiers (long
numbers, hexadecimal strings, UUIDs, codes mixing letters and digits) are replaced with [ID]. Unpartitioned
third-party cookies, which reflect your own browsing rather than the site, are never sent; - the fingerprinting techniques observed, with the origin and script path (no query string) of the scripts that
used them; - the status and value of seven security headers (Strict-Transport-Security, Content-Security-Policy,
Referrer-Policy, Permissions-Policy, X-Content-Type-Options, X-Frame-Options and Cross-Origin-Opener-Policy),
with nonces redacted; - the consent manager detected on the page;
- how many items the page keeps in local storage, session storage, IndexedDB, Cache Storage and service workers,
and the names (not the contents) of storage keys that match known trackers; - whether a cookie banner was shown, and whether trackers and cookies came before it was answered, as yes/no flags
without any timings; - the page load time, rounded to 10 ms;
- the version of the extension.
The server treats every submission as untrusted: it re-applies this anonymisation and computes the score itself. It
records the exact time it received the report; public pages show report times by day only. To count each network
once per site, each stored report carries a reporter tag, a 16-bit number computed with a secret key from your
network (IPv4 address or IPv6 /64 block) and the reported site; it cannot be traced back to your IP address or used
to link your reports of different sites. The server also counts, per site and month, the number of networks per
country that reported it, using a geolocation database kept on the server itself; the country is not stored with
your report. For abuse protection the server keeps request counters per network in memory only, for at most one
hour, and writes no IP addresses to its database or logs.
A report describes a website, not you: it contains no name, no address, no IP address and no identifier of you or
your browser. Because the reporter tag and the time of receipt could, combined with knowledge of what you visited
and when, make it possible to single a report out, we nevertheless treat stored reports as pseudonymous personal
data. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest, which we share with the public, is transparent
information about the tracking behaviour of websites. Reports are deleted 24 months after they were received;
database backups are kept for 14 days. Reports are never linked to a BackPing.net account.
Looking up a site. When you press Look up, the extension asks BackPing.net for the published grade of the site
you are on. The request contains that site's hostname, the language the extension is displayed in and, like any
request, your IP address. The server answers from the public data shown on the website and stores nothing about the
request; your network is only counted in memory to limit the number of lookups. Legal basis: Art. 6(1)(f) GDPR.
Firefox's data-collection permission. The extension declares the hostname it sends as browsing activity and
the report as website content, both as optional data collection, so installing it shares nothing. Firefox asks
the first time you press Look up (browsing activity) or Send report (both), and nothing is sent unless you
allow it. You can withdraw the permission at any time in Firefox's add-ons manager (about:addons); the extension
then sends nothing until you allow it again. There you can also turn off the extension's access to websites; it
then observes nothing and says so in its popup. Firefox's Total Cookie Protection keeps the cookies that third
parties set on a page in a separate jar for that site; the extension shows these partitioned cookies with the
site's own and, when you share, sends their names and attributes, never their values.
Hosting. BackPing.net runs on a server rented from Hetzner Online GmbH in Germany, which processes data on our
behalf under a data processing agreement (Art. 28 GDPR). The web server keeps standard access logs (IP address,
time, requested address, status, browser type) for 14 days.
Your rights. You have the rights of access, rectification, erasure, restriction, data portability where it
applies, and objection (Art. 15 to 21 GDPR), and the right to complain to a supervisory authority (Art. 77 GDPR);
the one responsible for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Rheinland-Pfalz, Mainz. Because we cannot tell which report came from which person, please tell us which site you
reported and roughly when (Art. 11(2) GDPR); we will then look for the report and delete it. Contact:
https://www.backping.net/contact.
Changes. After an update that changes what the extension sends or keeps, the extension shows a notice with a
link to the updated policy until you acknowledge it. This text follows version 3.0 of the BackPing.net privacy
policy, last updated 29 September 2026.