WebInspect Privacy
WebInspect has no servers. No account, no analytics, no telemetry, nothing uploaded.
Last updated: 26 September 2026
In short
WebInspect is a browser extension that inspects the page you are looking at and reports its technology, SEO, accessibility, performance, mobile readiness and technical configuration.
WebInspect has no servers. There is no account, no login, no analytics and no telemetry. Nobody at Elevven11 Studio can see what you browse, what you inspect, or what WebInspect finds.
When WebInspect runs
By default, only when you ask it to: when you click the toolbar button, use the keyboard shortcut, or choose WebInspect from the right-click menu.
There is deliberately no content script in the extension manifest. Nothing of WebInspect is loaded into a page until you ask for a report on that page, and it is not present on any other page at all.
Automatic inspection is an option you can turn on. It reads each page as it finishes loading so that a score can appear on the toolbar, and it needs permission to access the pages you visit, which Chrome will ask you about separately. It is off until you turn it on, and the permission can be withdrawn from the settings page at any time.
Sites it does not read at all
WebInspect skips 522 well-known sites unless you turn that off in settings. Two reasons, and the second is the one that matters here:
- Large platforms such as Google, Facebook, YouTube and Amazon, because a report on them is not actionable.
- Pages that routinely hold personal information: AI assistant chats, webmail, cloud storage, password managers, banking, payment, health, insurance and government sites.
The check runs before the page reader is injected, so a skipped page is never read, rather than read and then discarded. Nothing is collected from it, not even a count.
The list is curated and not exhaustive. There is no way to enumerate every bank in the world, and the settings page says so rather than implying otherwise. Whatever the list covers, the guarantees in the rest of this policy apply to every page: no page text, no field values, no browsing history.
What WebInspect reads
To inspect a page, it reads:
- the page's address, from the browser rather than from the page, and its title, language and encoding;
- its meta tags, canonical link, language alternate links and structured data;
- its heading outline: the level and the text of each heading;
- its images: source, alt attribute, format, intrinsic and displayed size, loading attribute;
- its links: destination, kind, accessible name, rel and target;
- the structure of its forms: field types, whether each field has a label, where the form submits to. Never the values;
- its script and stylesheet elements, including integrity and loading attributes;
- the resource timeline the page already exposes to itself: what was loaded, from where, how large it was where the server discloses that, and how long it took, and the paint and layout-shift timings the browser has already recorded for it;
- computed colours of text elements, to calculate contrast ratios;
- measured geometry, to find horizontal overflow, fixed widths and small touch targets;
- the names of cookies the page can see, because those are among the strongest signals of which platform a site runs on. Never their values;
- a sample of CSS class names, to recognise CSS frameworks;
- whether a fixed list of well-known JavaScript variable names exists on the page. Only whether they exist, never what they contain.
Page text is counted, not collected. The word, character and paragraph counts are computed in the page and only the numbers leave it. The text itself is never stored, never sent and never cached.
What WebInspect never reads
- The values of any form field. No password, no card number, no search term, no message. Nothing in the codebase will accept one.
- Cookie values, tokens or credentials of any kind.
- The contents of the pages you visit. Only counts, structure and short fragments used as evidence, such as a heading's text or an image's file name.
What WebInspect stores
On your device, in chrome.storage.local, and nowhere else:
- your settings, including which sections run and your size thresholds;
- a cache of the last few reports, keyed by page address, which expires after five minutes and holds at most twelve entries.
That cache is what makes reopening the popup on the same page instant. It holds counts, findings and the short evidence fragments already shown in the report. It is not a browsing history: it holds the last few pages you inspected, expires in minutes, and can be cleared from the settings page.
WebInspect keeps no history of the sites you have inspected. There is no such list, and no setting to create one.
An image address travels through chrome.storage.session when you use "Inspect this
image" from the right-click menu, so the popup knows which image you meant. That store lives in
memory for the life of the browser session, is never written to disk, and the entry is deleted the
moment the popup reads it.
"Open printable report" hands the report to its tab the same way. The tab deletes the entry as soon as it reads it and keeps its own copy only until the tab is closed.
The network
One feature uses the network: the link checker.
- It is off by default.
- Turning it on requires a permission you grant explicitly.
- It only runs when you press "Check links".
- It sends a request to each link on the page to see whether it answers. The sites being checked will see those requests, as they would see a visitor.
- No cookies or credentials are sent, and nothing about the page is uploaded.
Nothing else in WebInspect makes a network request. There is no endpoint to send anything to.
What leaves your device
Nothing, unless you ask for it:
- Export, copy and the printable report build a file, a clipboard entry or a page in your browser. Where it goes next is up to you.
- Link checking sends requests to the sites a page links to, as described above.
Report exports contain the scores, the findings, the evidence behind them, the technologies detected and the page's own metadata. They do not contain a copy of the page.
Permissions, and why
| Permission | Why |
|---|---|
activeTab |
Reads the page you are on, at the moment you ask. Granted by your click and lapsing when you navigate away. |
scripting |
Runs the page reader in the tab being inspected. |
storage |
Keeps your settings and the short-lived report cache, on this device. |
contextMenus |
Adds the right-click entries for a page and an image. |
| host permissions | Optional and not granted at install. Requested only for automatic inspection or link checking, and withdrawable from settings. |
Children
WebInspect is a developer tool with no accounts, no content and no communication features. It collects nothing from anyone, of any age.
Deleting your data
Everything WebInspect holds is in one store on your device. "Reset WebInspect" in the settings page empties it. There is nothing held anywhere else, so there is nothing else to request, export or delete.
Changes
If this policy changes, the date at the top changes with it, and the change will be described in the extension's release notes.
Contact
Questions about this policy go to elevven11studio@gmail.com, or message us on WhatsApp. Bug reports and feature requests are welcome on the support page.
This policy covers the WebInspect extension only. The studio privacy policy covers this website and the enquiries you send through it.