Sync encryption:
- AES-256-GCM encryption for all sync channels (browser sync, gist,
custom URL, folder sync, sync codes)
- Password with optional TOTP (RFC 6238) second factor
- Configurable auth TTL: session, 30/90/180/365 days, or never
- CryptoKey cached in IndexedDB — auth only needed when cache expires
AND new data exists (lastModified check runs before auth prompt)
- WebAuthn (biometric/PIN) as low-friction re-authentication gate
- Full options UI for setup, password change, and inline auth prompt
Smart reveal:
- Track which substitute values were actually sent outbound per session
- Reveal mode only replaces values that were genuinely substituted,
preventing false positives (e.g. AI using the word "user" won't be
replaced with a real username that maps to "user")
https://claude.ai/code/session_01SWSwDfMVij53bCTNSCLMwn
GitHub Gist sync:
- pushToGist(token): pushes all settings to a private Gist; creates a
new Gist on first use and stores the Gist ID in local storage so
subsequent pushes update the same Gist.
- pullFromGist(token): fetches the Gist, compares lastModified, applies
if newer (raw_url used to avoid API truncation).
- No desktop client needed; works across any browser/OS with a GitHub PAT.
- Options page shows a token field + Push/Pull buttons; Gist ID shown
once linked.
Custom URL sync:
- pushToUrl({ url, method, headers }): HTTP PUT to any endpoint.
- pullFromUrl({ url, headers }): HTTP GET, applies if newer.
- Works with Nextcloud/ownCloud WebDAV, self-hosted servers, cloud
functions, or any static-file host that allows PUT.
- Options page shows URL + optional JSON headers field + Push/Pull.
Both methods write ss_sync_notification on apply, triggering the purple
'SYN' badge and desktop notification added in the previous commit.
https://claude.ai/code/session_01TKpSR9M8JgHLXCp5CeDsQP
Notification system:
- When sync applies data (file folder, browser account, or sync code),
ss_sync_notification is written to local storage with the source.
- Service worker catches it via storage.onChanged, shows a purple 'SYN'
badge on the extension icon that persists until Options is opened, and
fires a desktop notification ('Settings updated via sync folder — open
Options to review').
- Clicking the desktop notification opens the Options page directly.
- On service worker wake, SYN badge is restored if the notification was
not yet dismissed.
- Opening Options clears ss_sync_notification, resets the badge, and
sends a sync:notification-seen message to the service worker.
- Added 'notifications' permission to both manifests.
Cloud storage clarity:
- Options page now explicitly lists that the folder sync works with any
cloud storage that has a desktop sync client: Dropbox, OneDrive, Google
Drive, iCloud Drive, Box, pCloud, Nextcloud, Synology Drive, etc.
https://claude.ai/code/session_01TKpSR9M8JgHLXCp5CeDsQP
PPI + button fix:
- After adding a mapping, the real PPI value is now immediately replaced
with the fake value in the input/contenteditable element via the new
replaceInInput() helper (handles both <textarea>/<input> and
contenteditable divs by walking text nodes).
- Triggers a re-scan 150ms later so the pre-send warning updates or
dismisses itself if no more PPI remains.
Auto-sync folder (File System Access API):
- User picks a folder once per browser via "Choose Sync Folder".
Any settings/mappings/identity change writes silent-send-sync.json
to that folder automatically (via api.storage.onChanged listener).
- On options page open and every time the page regains focus, the file
is read back; if its lastModified is newer than local data, settings
are imported immediately and the UI refreshes.
- File handle is stored in IndexedDB (ss_sync_handles) so it persists
across browser sessions without repeated permission prompts.
- Pick the SAME folder in each browser (or a synced cloud folder for
cross-computer sync) — fully automatic after that, no copy-paste.
- sync.js gains saveSyncDirHandle / loadSyncDirHandle / clearSyncDirHandle
helpers backed by IndexedDB.
https://claude.ai/code/session_01TKpSR9M8JgHLXCp5CeDsQP
Bug fixes:
- Date (possible DOB) pattern now requires context words (born, birthday,
dob, etc.) before firing — prevents spurious warnings on page-load API
calls that happen to contain ISO dates in conversation history.
- Highlight regex now uses word boundaries (\b) so short substitute values
(e.g. "aud") no longer match inside unrelated words like "Claude".
- Both TreeWalkers in content.js now skip the extension's own UI elements
(.ss-autodetect-warning, .ss-presend-warning, .ss-reveal-badge) to
prevent the highlight API from marking text in the extension's banners.
Settings sync:
- New src/lib/sync.js: exportSyncCode / importSyncCode (base64 JSON) for
manual copy-paste across any browser combination. Newest lastModified
timestamp wins; force flag available to override.
- browser.storage.sync support: when "Browser account sync" is enabled the
extension automatically pushes/pulls via Firefox Sync or Chrome account,
chunked to stay within per-item quota limits.
- storage.js now writes ss_lastModified on every save so conflict resolution
has an accurate timestamp.
- service-worker.js listens for both local and sync storage changes to keep
all copies in sync.
- New "Sync Between Browsers" section in options.html with Generate/Copy/
Import Sync Code UI and the browser sync toggle.
https://claude.ai/code/session_01TKpSR9M8JgHLXCp5CeDsQP
Detected PPI is now auto-redacted in the fetch hook using
RFC/standard reserved values — not just warned about:
- IPs → 192.0.2.1 (RFC 5737 TEST-NET-1, never routed)
- MACs → 00:00:00:00:00:00
- Addresses → 123 Example Street, Anytown, ST 00000
- GPS → 0.000000,0.000000 (Gulf of Guinea)
- Dates → 01/01/1970 (Unix epoch)
- EINs → 00-0000000 (impossible prefix)
- Paths → /home/user
- Git → example org
These are obviously fake and guaranteed not to be real data,
unlike random values which could be confused with actual PPI.
New Options toggle: "Auto-redact detected PPI on send" (on by
default). When on, PPI is caught in the fetch hook even if the
user hits Enter immediately after pasting. Warning banner now
says "Auto-redacted with standard placeholders" instead of
"These were sent as-is."
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Like spellcheck for privacy. Scans text as you type and paste
into chat inputs (debounced 800ms). Shows a dark floating warning
panel listing detected PPI BEFORE you hit Enter.
Each detected item has a green [+] button that instantly:
1. Generates a plausible fake value (random IP, fake address, etc.)
2. Adds it as a mapping to storage
3. Shows a checkmark to confirm
The warning disappears when you clear the text or when all
detected items have been addressed.
Three new Options toggles:
- Auto-detect unconfigured PPI (on by default)
- Offer to auto-add detected PPI (on by default)
Also adds a storage bridge (postMessage) so the page-world
content script can read/write chrome.storage through the
injector.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Scans outbound messages AFTER all substitutions for personal data
the user forgot to configure:
- Private/public IP addresses (skips 127.0.0.1, 8.8.8.8, etc.)
- MAC addresses
- Street addresses ("123 Main St")
- GPS coordinates
- Dates (possible DOBs)
- EIN/tax IDs
- Home directory paths not caught by smart patterns
- Shell prompts (user@host)
- Git remotes (reveals username/org)
- Environment variable assignments (HOME=, USER=, etc.)
Shows a floating dark warning banner (top-right, auto-dismisses
after 15s) listing each detected item with its type, value, and
hint. Skips values already in the user's identity config.
Also shows PPI warnings in the popup Test tab and adds toggle
in Options to disable auto-detect.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
License: Changed from MIT to BSL 1.1. Free for personal use,
commercial use requires a paid license. Auto-converts to MIT
on March 26, 2030.
Export/Import: Options page now has "Transfer Data" section:
- Export All (plain) — JSON file with all identities, mappings, settings
- Export Encrypted — AES-256-GCM with PBKDF2 password derivation,
saved as .ssbackup file
- Import — handles both plain and encrypted backups, prompts for
password if encrypted
Crypto uses Web Crypto API (browser-native, no dependencies):
100k PBKDF2 iterations, random salt + IV per export.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
No timestamp metadata in versions. Uses simple incrementing patch
numbers (0.3.3, 0.3.4, etc.). If Mozilla rejects the version as
already existing, auto-increments and retries up to 10 times.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Old approach: increment patch by 1 each time. Failed when the
same patch number was already signed with Mozilla from a
previous session.
New approach: version is 1.MMDD.HHMM (e.g., 1.326.1542).
Guaranteed unique per minute, all parts under 65535.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Two visual modes using the Highlight API (zero DOM modification):
- Yellow highlight: fake/substituted values the AI received.
Shows automatically in all AI responses, even without reveal mode.
"The AI sees these yellow values, not your real data."
- Terminal style (black bg, green text): your real data shown
in reveal mode. "This is YOUR data — the AI never saw this."
Uses CSS.highlights with ::highlight() pseudo-elements — no
spans, no DOM changes, no copy/paste artifacts. Falls back to
CSS class-based styling if Highlight API is unavailable.
Highlights are debounced (500ms) to handle streaming responses
without excessive reflows.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Revealed values are now wrapped in <span class="ss-revealed">
with a blue underline and subtle blue background, making it
obvious which parts are your real data vs what the AI said.
Hover shows tooltip "Substituted value: [fake]" so you can see
what the AI actually received. Un-reveal properly removes the
spans and normalizes text nodes.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
After the multi-profile migration, ss_identity changed from a flat
object { names, emails, ... } to { profiles: [...] }. The injector
was passing the raw profiles wrapper to the content script, which
expected the flat format.
Now the injector merges active profiles into a flat identity object
before injecting into the page world, and also merges on storage
change events. Also handles legacy format (pre-profile data) for
backward compatibility.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
~85-90% correctness for configured data. Lists specific things
that leak: images, file uploads, base64, short names, names
inside other words, unconfigured data, non-standard secrets.
"Think of it like a spell checker for privacy — it catches most
things, but you wouldn't send a legal document without proofreading."
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
No more manual version bumps or "version already exists" errors.
sign-firefox.sh now:
1. Reads current version from manifest.firefox.json
2. Increments the patch number (0.3.1 → 0.3.2)
3. Updates all three files (manifest.json, manifest.firefox.json, package.json)
4. Auto-commits the bump
5. Builds and signs
Just run `npm run sign:firefox` after any code change.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Add LICENSE file (MIT). Explain in README that reveal mode is a
local display change only — the AI never received the real data.
Reveal exists so users can copy paths/commands from AI responses
and paste them directly into their terminal without manually
translating fake values back to real ones.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
- Pressing Enter in any identity field saves immediately
- Save button shows "Save Identity *" (orange) when there are
unsaved changes, flashes "Saved!" (green) on save
- New profiles start with empty First and Last name rows
pre-populated so users know what to fill in
- Input changes in the identity tab are tracked to show
saved/unsaved state
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Storage issue: Chromium/Brave keeps storage.local data even when
an unpacked extension is removed and reloaded. Added "Reset
Everything" button in Options → Danger Zone that clears all data
(double-confirm to prevent accidents).
Reveal mode: Now re-runs revealAllResponses() every 2 seconds
while active to catch streamed content and dynamically loaded
responses. Adds console logging for reveal toggle state changes
to aid debugging. Cleans up interval when reveal mode is turned off.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Identity fields now support multiple entries per type:
- Add unlimited names (first, last, middle, nickname), emails,
usernames, hostnames, and phone numbers per profile
- "+ Add" button on each section, "x" to remove rows
- Names have a type selector (1st/Last/Mid/Nick)
README now includes:
- First-time setup walkthrough (step by step)
- Icon color legend (gray/black/blue/red)
- Keyboard shortcuts table
- Note that extension does nothing until configured
Also bumps version to 0.3.0 for Firefox re-signing.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Identity tab now supports multiple named profiles:
- Dropdown selector to switch between profiles
- "+" button to add a new profile (prompts for name)
- Pencil button to rename
- X button to delete (can't delete the last one)
- Toggle to enable/disable each profile independently
Default profile is "Personal". All active profiles are merged
and substituted simultaneously — so "Personal" (your name) and
"Work" (your work email, company domain) both get caught.
Storage model: profiles are stored as an array under ss_identity.
getIdentity() merges all active profiles into a single identity
object for the substitution engine.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Users can now label mappings as 'domain' (e.g. mycompany.com →
example.com). This is a category label for organization — the
substitution works the same as any other mapping.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Interception is now completely inactive until the user configures
at least one identity field or explicit mapping. Before that:
- Icon shows gray (unconfigured)
- No fetch/XHR hooks fire
- First-run banner tells user to set up
Custom domains: clicking "Add Domain" in Options now triggers
the browser's native permission prompt via permissions.request().
No more manual chrome://extensions site access step.
Icon states are now:
- Gray = unconfigured (nothing will happen)
- Black = active and protecting
- Blue = reveal mode on
- Red = manually disabled
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Activity log fix:
- Injector now writes directly to storage.local in addition to
sending runtime messages to the background worker. This fixes
the issue where MV3 service worker sleep caused messages to be
silently dropped.
Dynamic icon colors:
- Black "SS" = active, normal
- Blue "SS" = reveal mode on
- Red "SS" = Silent Send disabled
- Icons generated via OffscreenCanvas in the service worker
- Updates on every settings change and keyboard shortcut toggle
Also adds keyboard shortcuts section to Options page showing
current bindings and how to customize them per browser.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Shows a red warning banner at the top of the popup when no identity,
email, username, or explicit mappings are configured. The status dot
turns orange (instead of green) to indicate the extension is active
but not protecting anything yet. Banner disappears as soon as the
user saves their identity.
Prevents users from thinking they're protected when nothing has
been configured.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Previous sign script failed because web-ext's config file discovery
was conflicting with CLI args. Now:
- Parses .env line by line with explicit key matching
- Prints truncated key/secret so you can verify they loaded
- Uses --no-config-discovery to prevent web-ext-config.cjs from
overriding the CLI args
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
The previous approach (source .env && npm run sign:firefox) failed
because npm subshells don't inherit env vars consistently, and
quoted values in .env weren't being stripped.
New approach: sign-firefox.sh reads .env itself, strips quotes,
and passes --api-key/--api-secret directly to web-ext sign.
Also renames web-ext-config.js → web-ext-config.cjs to fix the
deprecation warning, and bumps package.json version to 0.2.0.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Adds a secret scanning layer that runs after identity/explicit
substitutions. Catches secrets the user didn't configure:
- API keys: OpenAI (sk-), Anthropic (sk-ant-), Google (AIza),
AWS (AKIA), GitHub (ghp_), GitLab (glpat-), Slack (xox),
Stripe (sk_live/test), SendGrid (SG.)
- Auth: Bearer tokens, key=value assignments (password=, secret=,
api_key=, token=), private key blocks (-----BEGIN PRIVATE KEY-----)
- Connection strings: mongodb://, postgres://, mysql:// with creds
- PII: SSN (xxx-xx-xxxx), credit card numbers (Visa/MC/Amex/Discover)
Redacted values shown in red in the Test tab. Secrets are truncated
in the activity log (first 8 chars + "...") to avoid logging the
full secret. Enabled by default, toggle in Options.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Users will stop checking once they trust the tool. Be upfront that
it can miss PPI in images, file uploads, unusual name variations,
or unconfigured data. Yellow warning box in the popup footer.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Replace URL-pattern and body-shape matching with universal approach:
Outbound (substitution):
- Hooks ALL POST/PUT/PATCH fetch and XHR requests, not just known
API endpoints. Skips static assets and analytics.
- Deep-walks any JSON structure recursively to find and substitute
all string values. Skips metadata keys (model, id, token, etc.).
- Falls back to raw string substitution for non-JSON bodies.
Inbound (reveal):
- Walks ALL text nodes in document.body, not just specific CSS
selectors. Skips SCRIPT, STYLE, INPUT, TEXTAREA tags.
- Handles streaming by observing characterData mutations globally.
This makes Silent Send survive any API restructuring — the only
thing that could break it is a site encrypting request bodies in
JS before fetch, which would also break their own dev tools.
Performance: reveal pairs are cached and only rebuilt on config
change. Deep walk skips known non-content keys to avoid touching
auth tokens or request metadata.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Reveal mode (eye icon) now works as intended:
- Toggle ON: all existing responses on the page get fake→real
substitution applied immediately (paths, names, emails, etc.)
- Streaming responses are revealed in real-time as they arrive
- Toggle OFF: original text is restored from saved state
- Covers code blocks, artifacts, pre tags, and all response
containers across all supported services
- Blue floating badge shows "Reveal Mode — showing real data"
when active so user knows what they're seeing
The workflow is now: type /home/jsmith/... → Claude sees
/home/ademo/... → Claude responds with /home/ademo/... →
reveal mode shows /home/jsmith/... → user copies real path.
Also adds privacy note in popup footer: data stays in local
browser storage, no servers, no tracking, no analytics.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Test tab now has two modes:
- Strip (real → fake): paste text with real data, see what gets sent
- Reveal (fake → real): paste AI output with fake data, get back
real data with a "Copy to Clipboard" button
Also fixes:
- content.js smartSubstitute bailing when identity.enabled was
undefined (defaulted enabled to all-true instead of returning)
- Test tab now reloads identity from storage on tab switch so
changes saved in the Identity tab take effect immediately
- Shows yellow warning when identity fields are missing
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
- Add custom domain support in Options page so users can add
self-hosted AI services (e.g. https://ai.myserver.com)
- Background worker dynamically injects content scripts on
custom domains using scripting.executeScript
- Add optional_host_permissions so Chrome can grant per-domain access
- Rewrite README: add clone step to Firefox instructions, clarify
what "credentials" means in step 3, add Windows commands alongside
Mac/Linux for every terminal step
- Bump version to 0.2.0
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Add clone instructions, prerequisites, and detailed step-by-step
Firefox signing walkthrough. Mark Claude as tested, all other
services (ChatGPT, Grok, Gemini, OpenWebUI) as untested.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Extend Silent Send to intercept API requests on all major AI chat
services. Each service has different API shapes:
- ChatGPT: /backend-api/conversation with content.parts arrays
- Grok: GraphQL + /2/grok/add_response with message field
- Gemini: form-encoded f.req with nested arrays (+ generateContent)
- OpenWebUI: /api/chat and /ollama/api/chat (self-hosted)
All services share the same substitution pipeline. Manifests updated
for both Chrome and Firefox with host_permissions for all domains.
OpenWebUI supported via localhost/127.0.0.1 for self-hosted instances.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
jsmith@macbook-pro now becomes ademo@mycomputer when both username
and hostname are configured in the Identity tab. Hostnames are also
caught standalone (e.g. just "macbook-pro" in text).
Also rewrites README with detailed step-by-step Mozilla API key
setup instructions for Firefox signing.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Instead of requiring explicit mappings for every variation, users
now configure their identity once (Identity tab) and Silent Send
auto-catches:
- Emails: any address @gmail, @yahoo, @outlook, etc.
- Names: first/last, full name, reversed, possessives, case variants
- Usernames: user@host, ~user, /home/user, C:\Users\user
- Phones: all common formats ((555) 123-4567, 555.123.4567, etc.)
Smart patterns run before explicit mappings, so explicit rules
can override smart catches when needed.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Add package.json with web-ext dev dependency and npm scripts for
building, linting, signing, and running the Firefox extension.
Signing produces a self-hosted .xpi that persists across restarts
without needing the Mozilla store.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw