If you discover a security vulnerability in True Cost, please report it via GitHub Issues. Do not disclose vulnerabilities publicly.
True Cost uses the minimum permissions necessary:
storage– to save your wage and display settings locallyactiveTab– to inject the price picker on the current tab onlyscripting– to run the picker script on demand
No broad host permissions (<all_urls>) are requested. Content scripts are only injected on the specific sites listed in the manifest.
- All data stays in your browser (
chrome.storage.sync/chrome.storage.local) - The only outbound traffic is plain GET downloads of public data files from the project's own GitHub repository (wage dataset + site selector database); see PRIVACY.md for the exact list and schedule
- No user browsing data is collected or transmitted