Statable GDPR Checker Privacy Policy

Last updated: July 30, 2026

This privacy policy explains how the Statable GDPR Checker browser extension ("the extension") handles information. Statable GDPR Checker is an auditing tool published by Key Arg B.V. for Chrome. We are committed to the same privacy-first approach as our analytics service: all processing described below happens locally in your browser, the extension makes no network requests of its own, and the information it reads never leaves your device.

This is a separate extension from the Statable Debugger, which has its own policy. The two read different things: the Debugger inspects Statable's own script, while the GDPR Checker observes what a page loads from third parties. If you use both, each policy applies to its own extension.

1. Who We Are

Statable GDPR Checker is developed and published by Key Arg B.V., a company registered in the Netherlands. Key Arg B.V. is the controller responsible for the extension, and this policy is governed by the laws of the Netherlands. You can contact us at scanner@statable.com. Full company contact details are available in our main Privacy Policy.

2. Single Purpose

Statable GDPR Checker has one purpose: it measures what a website loads before the visitor answers its cookie banner, and reports which third parties received data, which cookies were stored, and what can be done about it. It is a measurement tool. It reports what a page did; whether that is lawful depends on context the extension cannot see, and nothing it shows is legal advice.

3. Scope Of This Policy

This policy covers the browser extension only. Our website and analytics service are covered by our main Privacy Policy. Using the extension requires no Statable account, and the extension is not connected to any account you may hold with us.

4. Information The Extension Reads

The extension observes the http and https pages you visit while it is enabled. That observation is the measurement: there is no way to report which third parties a page contacted without watching the page contact them. Everything it reads is processed locally on your device and shown only in the panel. Because the extension observes pages you browse, the requests they make and the cookies they set, our Chrome Web Store privacy disclosure declares "Website content", "Web history" and "User activity"; this section describes exactly what that means in practice.

For each page you load, the extension reads:

  • the network requests the page makes: the URL, the request method and the timestamp of each request, which is what identifies the third parties involved and when they were contacted;
  • two request headers only: whether a Cookie header accompanied a request, and whether a Referer header did — the first distinguishes a request carrying an identifier from a cookieless one, the second shows whether the third party learned which page you were on. The header values themselves are not retained;
  • response headers, specifically Set-Cookie and its attributes (Max-Age, Expires, SameSite, Secure, HttpOnly), plus the headers that identify a CDN or bot-protection layer — a persistent cross-site cookie and a load balancer's session cookie are different findings and can only be told apart by their attributes;
  • cookies present for the page, read through the browser's cookie API: name, domain, path and expiry. The extension never writes, edits or deletes a cookie;
  • navigation events for the tab, which mark the moment the page began loading — the point from which "before consent" is counted;
  • a sample of the page's HTML, matched locally against the signature list to find consent banners and tracking snippets that are present in the markup. The sample is compared and discarded; it is not stored, and no part of it leaves the browser; and
  • the fact that you first interacted with the page — a click, key press or touch. Only the timestamp is recorded, because that moment is the boundary the whole measurement depends on: it is when consent could first have been given. What you clicked, typed or entered is not read.

When you open the panel, the extension additionally reads the id and URL of the active tab, so a measurement is attributed to the site it actually came from, and can reload that tab when you ask it to.

5. How Each Type Of Information Is Used

Every item in section 4 is used for one thing: producing the reading you see in the panel. Request URLs are matched against the signature list to name the vendor; timestamps decide whether something happened before or after your first interaction; cookie attributes decide whether a cookie is a cross-site identifier or infrastructure; the HTML sample finds banners and snippets the network cannot reveal.

None of it is used to profile you, and none of it is used to build a record of the sites you visit. There is no such record: the extension keeps a measurement in memory for the tab it belongs to and nothing beyond it.

6. Information We Do Not Collect

The extension does not read or collect:

  • the contents of forms, or what you type — only that an interaction occurred, and when;
  • credentials, passwords, payment details or anything you enter on a page;
  • your browsing history as a history — it observes the page currently open and keeps nothing after that tab is gone;
  • the values of cookies, which are irrelevant to the measurement; only names, domains and attributes are read; and
  • any identifier of you or your device. The extension creates no user id, installation id or device fingerprint.

7. Sharing And Disclosure

Nothing is shared, because nothing is transmitted. The extension makes no network requests of its own — not to Statable, not to any third party, not for analytics, error reporting or updates to its signature list, which ships inside the package. No human at Key Arg B.V. or anywhere else can access what the extension reads, because it is never sent anywhere. We sell nothing to anyone, for the simple reason that we hold nothing to sell.

8. Limited Use

Our use of information from the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. The information described in section 4 is used solely to provide the measurement shown in the panel. It is not transferred, not sold, not used for advertising, creditworthiness or lending purposes, and not used to train any model.

9. Data Retention

A measurement lives in the browser's memory for as long as its tab does. Navigating to another page starts a new measurement and discards the previous one; closing the tab, or restarting the browser, discards it entirely. The extension writes nothing to disk: it uses no extension storage, no cookies of its own and no local database. There is no server to delete anything from, and therefore no deletion request to make.

10. Data Security

The strongest security property of this extension is what it does not do: it never transmits data over the network, so there is no data in transit to protect. All processing takes place inside your browser on your own device, and the information is discarded as described in section 9.

11. Incognito Access

The extension can ask for permission to run in incognito windows, which Chrome disables by default and which you grant explicitly. It asks for one reason: a site you have already accepted cookies on may not show its banner again, which makes the reading unreliable. An incognito window carries none of that history. Everything in this policy applies identically there — nothing is transmitted, and nothing survives the window closing.

12. Remote Code

The extension does not download or execute remote code. It is built on Manifest V3, and all of its code — including the signature list that identifies trackers — is bundled into the extension package reviewed by the Chrome Web Store.

13. Changes To This Policy

If we change what the extension reads, how that information is used, or any other data practice described here, we will update this policy, revise the "Last updated" date above, and proactively notify users of material changes through the extension's Chrome Web Store listing before the new practices take effect.

14. Contact Us

If you have questions about this policy or the extension's data practices, contact us at scanner@statable.com. General enquiries can go to support@statable.com. Full company contact details, including our postal address, are available in our main Privacy Policy.