JSHarvest processes the JavaScript resources of pages you visit entirely on your own device. Captured data is stored in the browser's session storage and is cleared when the browser closes. Your settings, optional capture snapshots and your AI API key (if you provide one) are stored in local storage on your device.
JSHarvest transmits no data by default. It contains no analytics, tracking or telemetry, and the developer receives no data whatsoever. There is no account, no sign-in and no server operated by the developer.
Two optional features contact other servers, and both are off by default:
1) Deep Scan downloads JavaScript files from the website you are currently inspecting in order to analyse them as text. Nothing is sent to any third party, and downloaded code is never executed. Requests are made without cookies.
2) AI analysis requires you to supply your own third-party API key (Anthropic, OpenAI, Google Gemini, Groq or OpenRouter). When enabled and used, a summary of the collected inventory — totals, third-party host names, bundle filenames, and findings whose secret values are already masked — is sent to the provider you selected, billed to your own account. Raw secret values are never stored by JSHarvest and are therefore never transmitted. With the "Redact context" option enabled by default, file paths and raw endpoint values are withheld as well. Data sent to a provider is subject to that provider's own privacy policy.
Your API key is stored only in your browser's local storage. It is never synced and is sent only to the provider it belongs to.
JSHarvest does not read browser history, bookmarks, passwords or cookies, does not profile users, and does not sell data. Uninstalling the extension removes all stored data.