SiteExtract Privacy

SiteExtract has no servers. No account, no analytics, no telemetry, nothing uploaded.

Last updated: 27 September 2026

In short

SiteExtract is a browser extension that saves the page you are viewing as an editable starter project and downloads it to your device as a ZIP.

SiteExtract has no servers. There is no account, no login, no analytics and no telemetry. Nobody at Elevven11 Studio can see what you browse, what you extract, or what your projects contain.

When SiteExtract runs

Only when you ask it to: when you open it from the toolbar button or the keyboard shortcut and press Extract.

There is deliberately no content script in the extension manifest. Nothing of SiteExtract is loaded into a page until you press Extract on that page, and it is not present on any other page at all. There is no automatic mode.

Sites it does not read at all

SiteExtract never reads 522 well-known sites. There is no setting to turn this off. Two reasons:

  • Large platforms such as Google, YouTube and Amazon, because a copy of somebody else's platform is rarely a useful starter.
  • Pages that routinely hold personal information: webmail, cloud storage, banking, payment and similar sites.

The check runs in the popup and again in the extract tab, before the page reader is injected, so a blocked page is never read. It runs once more on the address the reader reports, in case the tab moved to another page in between, and a capture that fails it is discarded without being processed.

The list is curated and not exhaustive. There is no way to enumerate every bank in the world, and the settings page says so rather than implying otherwise. Sites people deploy their own work to, such as github.io, vercel.app and netlify.app, are never blocked.

What SiteExtract reads

When you press Extract, the page reader collects:

  • the page's address, its base address and its title;
  • in Snapshot mode, the page as it is rendered: its markup, including open and closed shadow roots, the image each element actually displays, lazy-loaded image sources, the pixels of any canvas it is allowed to read, and the current state of the page's form controls;
  • the text of the stylesheets the page can read itself, used only when the same file cannot be downloaded;
  • with design tokens switched on, the computed colours, font families, type sizes, spacing, border radii and shadows of up to 4,000 visible elements. Only how often each value occurs is kept.

In Source mode the rendered markup is not read. The original HTML is downloaded again from the page's address instead.

Signed-in pages and form fields

A snapshot saves the page as you see it. If you are signed in, the project contains what the signed-in page shows you.

Password fields, and fields the page marks for card numbers or one-time codes, are never written to the file. Their values are removed before the page leaves the tab.

Text in other fields is kept, because it is part of the page as shown, and so are values the page already wrote into its markup, such as hidden form fields. Clear anything you do not want saved before you extract.

Everything the reader collects goes into the project on your device and nowhere else.

The network

Building a project means downloading the files the page uses. When you press Extract, the extract tab requests the page's stylesheets, its images and fonts when those options are on, any video or other files it references, and in Source mode its HTML and scripts.

  • The requests go straight from your browser to the servers that host those files, as they did when the page loaded. There is no SiteExtract server in between.
  • Cookies are sent only to the page's own site, so the files of a signed-in page load as they did for you. Requests to any other domain carry no cookies.
  • Files on the blocked sites, and on private network addresses such as your router, are never requested, even when the page points at them. The check runs again if a request is redirected. A page served from a private address may still use its own files.
  • Each file is limited to 25 MB and 15 seconds, with one retry.
  • Nothing about the page, the project or you is uploaded. There is no endpoint to send anything to.

Access to other domains is not granted at install. SiteExtract asks for it the first time you extract, so files served from CDNs can be downloaded. Declining still works: those files keep their original addresses and are listed in the project report. Access can be withdrawn from the settings page at any time.

The advert at the foot of the popup comes from a list that ships inside the extension. Showing it makes no request and tells nobody the popup was opened.

What SiteExtract stores

In the extension's own localStorage, on your device, and nowhere else:

  • your extract defaults: mode, images, fonts and design tokens;
  • your settings: credit comment, badge, theme and promotions;
  • one number that rotates the house advert.

SiteExtract keeps no history of the sites you have extracted. There is no such list, and no setting to create one.

The project is held in memory in the extract tab until you close it. It is saved only where your browser saves downloads.

What goes into the project

The ZIP holds the page, its downloaded files, tokens.css, report.json and README.md. The report and the README record the page's address without its query string, which can carry session tokens, along with the time of the extract and any files that could not be downloaded.

SiteExtract can add three marks of its own, each labelled so it is easy to delete, and each switchable in settings:

  • an HTML comment at the top of index.html crediting SiteExtract, invisible on the page, on by default;
  • a small visible badge in the corner of the page, off by default;
  • a short section at the end of README.md, which follows the promotions setting.

No advert is ever placed inside the copied page.

What leaves your device

Nothing, unless you ask for it:

  • Extracting requests the page's files from the servers that host them, as described above.
  • The ZIP is saved by your browser like any other download. Where it goes next is up to you.
  • Links to the studio site, the help page, the privacy policy and the sibling extensions open in a new tab, with a tag naming the part of SiteExtract they came from. The tag identifies the extension, not you.

Permissions, and why

Permission Why
activeTab Reads the page you are on, at the moment you ask. Granted by your click and lapsing when you navigate away.
scripting Runs the page reader in the tab being extracted.
host permissions Optional and not granted at install. Requested on your first extract so files on other domains can be downloaded, and withdrawable from settings.

There is no storage permission. Settings live in the extension's own localStorage.

Children

SiteExtract is a developer tool with no accounts, no content and no communication features. It collects nothing from anyone, of any age.

Deleting your data

Everything SiteExtract holds is in one store on your device. "Reset SiteExtract" in the settings page empties it. Projects you have downloaded are ordinary files on your device and can be deleted like any other. There is nothing held anywhere else, so there is nothing else to request, export or delete.

Changes

If this policy changes, the date at the top changes with it, and the change will be described in the extension's release notes.

Contact

Questions about this policy go to elevven11studio@gmail.com, or message us on WhatsApp. Bug reports and feature requests are welcome through extension support.

This policy covers the SiteExtract extension only. The studio privacy policy covers this website and the enquiries you send through it.