Skip to content
Vanta Security
Privacy Policy Terms of Service

Privacy Policy

Last updated: June 8, 2026

Contents

  1. 1. Overview
  2. 2. Information We Do NOT Collect
  3. 3. How URL Checking Works
  4. 4. Local Script Analysis
  5. 5. Session Storage
  6. 6. Permissions We Request
  7. 7. Third-Party Services
  8. 8. Children's Privacy
  9. 9. Changes to This Policy
  10. 10. Contact

The short version: Vanta Security does not collect, store, or sell your personal data. URLs you visit are sent only to Google's Safe Browsing API for threat checking and are not retained by us.

1. Overview

This Privacy Policy describes how the Vanta Security browser extension ("the Extension", "we", "us") handles information when you use it. We are committed to protecting your privacy and being transparent about our practices.

2. Information We Do NOT Collect

The Extension does not collect, transmit to our servers, or store any of the following:

  • Your browsing history
  • Your personal identity or account information
  • Passwords or form data
  • Cookies or browser storage from other sites
  • Crash reports or telemetry

3. How URL Checking Works

When you navigate to a website, the Extension sends the URL to the Google Safe Browsing API (v4) to check whether it appears on Google's databases of suspected phishing, malware, and unwanted software sites.

This request is routed through a privacy proxy hosted on Vercel (a cloud platform) before being forwarded to Google's servers. The proxy does not log URLs or store any request data - it exists solely to keep the API key off the client device. Google's handling of this data is governed by the Google Privacy Policy.

Google works to provide the most accurate and up-to-date information about unsafe web resources. However, Google cannot guarantee that its information is comprehensive and error-free: some risky sites may not be identified, and some safe sites may be identified in error.

4. Local Script Analysis

The Extension also scans inline JavaScript on pages you visit for patterns associated with payment redirect attacks. This analysis happens entirely on your device -no script content is sent to any server.

5. Session Storage

If you choose "Proceed anyway" on a warning page, the Extension stores that URL in your browser's session storage so it is not blocked again during the same browser session. This data is stored locally in your browser and is automatically cleared when you close Chrome. It is never transmitted anywhere.

6. Permissions We Request

The Extension requests the following Chrome permissions and why:

  • webNavigation -to detect when you navigate to a new page so URLs can be checked.
  • tabs -to redirect the current tab to the warning page when a threat is detected.
  • storage -to store your session bypass list locally in your browser.
  • scripting -to inject the script scanner into pages you visit.
  • Host permissions (https://*/, http://*/) -required to run the content script on all web pages and to contact the Safe Browsing API.

7. Third-Party Services

The Extension uses the following third-party services:

  • Google Safe Browsing API - URLs are forwarded to Google's servers for threat checking under Google's Privacy Policy and the Safe Browsing Terms of Service.
  • Vercel - the API proxy is hosted on Vercel's infrastructure. URLs pass through Vercel's network in transit to Google but are not logged or retained. Vercel's privacy practices are described in the Vercel Privacy Policy.

8. Children's Privacy

The Extension is not directed at children under the age of 13 and does not knowingly collect any information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected by the "Last updated" date at the top of this page. Continued use of the Extension after changes constitutes your acceptance of the revised policy.

10. Contact

If you have any questions about this Privacy Policy, please open an issue on our GitHub repository or contact us at the email address listed on the Chrome Web Store listing.

Vanta Security

Legal

Privacy Policy Terms of Service
© 2026 Vanta Security. All rights reserved. Made by Andrew Cappelli ← Back to home