Last updated: July 2, 2026
Kitbox is a browser extension that provides developer utilities — formatters, converters, generators, image tools, file converters, and page inspection tools — directly inside your browser.
Kitbox does not collect, store, transmit, or share any of your personal data. All 59 tools run entirely within your browser. Nothing you type, paste, generate, or inspect inside Kitbox is ever sent to any server, including ours.
Kitbox does not collect:
Personally identifiable information (name, address, email, age, ID numbers)
Health information
Financial or payment information
Authentication credentials or passwords
Personal communications (emails, texts, chat messages)
Location data
Web browsing history or activity
Keystrokes, mouse movement, or scroll behavior
Any data typed or pasted into Kitbox tools
Any page content read by Kitbox's Page Inspect tools
When Page Inspect tools read data from your active tab (see section below), that data is displayed in the extension popup only. It is never stored, logged, or transmitted anywhere.
Kitbox uses your browser's local storage (chrome.storage.local) only to remember:
Your pinned tools
Your recently used tools
Your theme preference (dark or light mode)
Per-tool settings you have configured
This information is stored only on your own device, is never transmitted to any server, and is never accessible to us or to any third party. Uninstalling the extension permanently deletes all of this data.
Kitbox requests the following browser permissions. Each one is used exclusively for the tools described — nothing else.
Used to save your preferences locally: pinned tools, recently used tools, theme selection, and per-tool settings. Nothing is synced to a server.
Used by Page Inspect tools to temporarily access the tab you are currently viewing, but only at the moment you click a tool's action button. Kitbox never accesses tabs in the background or without your explicit action.
Used by Page Inspect tools to inject a read-only script into your active tab in order to collect on-page data. The tools that use this are:
Font Inspector — reads computed font properties of elements you hover over
Web Technology Detector — scans script URLs and global variables to identify frameworks and libraries
Meta Tag Inspector — reads <meta> tags, structured data, and the page title
Page Color Palette Extractor — reads computed background and text colors across elements
CSS Variable Inspector — reads CSS custom properties defined on the page
Local & Session Storage Viewer — reads localStorage and sessionStorage contents for the current tab
Page Link Extractor — collects all hyperlinks on the page
Website Image Extractor — collects image URLs from the page DOM
In every case, the collected data is displayed in the extension popup only and is never stored or transmitted.
Used exclusively by the Cookie Inspector tool. This tool reads cookie names, values, domains, paths, expiry times, and security flags for the domain of your currently active tab. Cookies are never modified, deleted, or transmitted outside the extension popup.
Used by tools that generate downloadable output files. These tools create files entirely within your browser and write them to your local Downloads folder:
QR Code Generator (PNG)
Image Compressor, Image Resizer, Image Crop (image files)
PNG/JPG → WebP Converter, SVG → PNG Converter (image files)
Markdown → PDF, DOCX → PDF (PDF documents)
Website Image Extractor (images and ZIP archive)
No data is transmitted to any external server before, during, or after the download.
Required by three tools that need to make or intercept network requests:
HTTP Request Tester — sends HTTP requests (GET, POST, PUT, DELETE, PATCH) to any URL you specify. This is a developer tool equivalent to Postman; the extension context bypasses CORS restrictions so you can test any API endpoint. All requests are initiated manually by you — nothing is sent automatically.
Response Header Viewer — fetches the HTTP response headers for your current tab's URL to display security header information.
Website Image Extractor — fetches cross-origin images from CDN URLs to enable downloading them.
No requests are ever made automatically or in the background. All network activity is triggered only by your explicit action inside a tool.
Nine tools in Kitbox's "Page Inspect" category read data from your currently active browser tab. Here is how they work and what they access:
You open Kitbox and navigate to a Page Inspect tool.
You click the tool's action button (e.g. "Scan", "Activate", "Extract").
Only at that moment does Kitbox inject a temporary script into your tab.
The script collects the relevant on-page data (fonts, links, colors, storage, etc.) and sends it back to the popup.
The data is displayed to you in the popup.
When you close the popup or navigate away, the data is discarded. Nothing is saved.
Kitbox never monitors your tabs passively, never runs scripts in the background, and never stores or transmits any data read from a page.
Kitbox does not use any third-party analytics, advertising, crash reporting, or tracking services. No data is shared with, sold to, or accessible by any third party — because no data leaves your browser in the first place.
Kitbox is a developer tool intended for general use and not directed at children. We do not knowingly collect any information from anyone, including children under the age of 13.
When this policy is updated, the "Last updated" date at the top of this page will change. If a future update introduces any feature that involves sending data off your device, that will be:
Clearly disclosed in this policy
Opt-in only — never enabled by default
Reflected in the extension's Chrome Web Store listing
If you have questions about this privacy policy, you can reach us at: harsharora.digital@gmail.com