Extension: HeaderMod
Last updated: 2026-07-21
HeaderMod does not collect, transmit, or share any personal data or browsing data with the developer or any third party. All configuration stays inside your own browser.
Your header profiles and settings (profile names, header rules, URL and resource filters, paused/locked state, and timestamped backup snapshots) are stored using the browser's extension storage:
storage.local and storage.sync on your own device.storage.sync data is synced across your own browser profiles by the browser vendor (Google / Mozilla) — it is never sent to the extension developer.HeaderMod modifies HTTP request and response headers only according to the rules you configure, using the browser's declarativeNetRequest API. The rules are enforced by the browser itself. The extension does not read, log, capture, or transmit the content of the pages you visit or the requests you make.
HeaderMod requests broad host access (<all_urls>) so that the header rules you create can be applied to whichever sites you target. This access is used solely to register your header rules with the browser's request engine. No data from any site is read or sent anywhere.
None. HeaderMod makes no network requests of its own and uses no analytics, tracking, or advertising services.
Because header profiles can contain values you enter (such as authorization tokens or cookies), treat exported profile JSON files as sensitive and do not share them.
Questions about this policy or a problem to report? Open an issue on GitHub.