Privacy
Privacy Policy
Last updated: September 14, 2026.
This policy explains how Internet Health Check handles information in the browser extension and web portal. It is written to match the current system behavior as implemented today.
1. Who operates the service
Internet Health Check is operated by Anh Bui, an independent sole trader based in the United Kingdom, trading as anhbui dev. For privacy requests or questions, contact support@anhbui.dev.
2. What the extension stores locally
The extension stores its monitoring data in chrome.storage.local inside your browser profile. That local data can include settings, license state, samples, events, health summaries, and related metadata used to power the popup and dashboard.
- Connection status and latency samples
- Event history such as outages, recovery, unstable periods, and IP change events
- Configuration such as check interval, endpoint choice, notifications, theme, badge mode, and retention settings
- Local Pro activation details such as license key, plan, expiry, and device activation identifier
- Optional JSON backup and restore data if you export or import it yourself
- Pro trial status (whether a trial is active and its expiry time), stored in
chrome.storage.syncso it persists across your signed-in browser profiles when Chrome sync is enabled - First-use checklist progress, preview usage counters, and trial checklist state — stored locally on your device only and never uploaded except as the consented aggregate events listed in Section 4
The local monitoring history — connection samples, events, and related charts — is not uploaded to this web portal. Optional product analytics is off by default; see Section 4 below for the exact opt-in event fields.
3. Network requests made by the extension
The extension performs network checks against the configured test endpoint. By default, that may include Google connectivity or Cloudflare. You may configure one custom HTTPS endpoint in Free; Pro adds additional targets.
The extension may also request your public IP address from https://api.ipify.org when the network is available. That value is used for display and diagnostics such as IP change detection.
If you run the speed test, the extension sends download and upload test traffic to Cloudflare speed test endpoints.
If you explicitly enable anonymous product analytics in Settings, the extension may post conversion events to POST /api/conversion-event for trial and purchase milestones. These posts contain only the fields described in Section 4; they do not contain monitoring content, browsing history, page URLs, or email addresses.
4. What the web portal stores
The web portal stores information required for pricing, license management, checkout fulfillment, support, and administration. Depending on your use, that may include:
- Email address entered during checkout (name is no longer collected; display name is derived from the email)
- Selected plan and license status
- License key, activation timestamps, and device activation identifiers submitted during license verification
- Stripe-related identifiers such as checkout session, customer, subscription, and order references
- Failed-renewal state (invoice identifier, attempt count, grace deadline) and operator billing actions with audit records — see Section 6
- SHA-256 hashes of single-use license-management links (the raw link is emailed once and never stored), plus link expiry and session timestamps
- Support request details, including email, optional license key, subject, and message
- Administrative changes to license records
- Conversion and trial analytics events — see Section 4 for the exact field list
5. Conversion and trial analytics
Product funnel analytics requires an explicit choice: the extension toggle is off by default, and the pricing page asks before it records a page-view event. When enabled, the extension and pricing page post funnel events. A checkout still creates the billing record required to process the purchase, whether or not analytics is enabled. Each stored analytics event contains only these fields:
- type — one of:
landing.viewed,pricing.viewed,plan.selected,checkout.started,trial.started,trial.ending_soon,trial.expired,trial.checklist_completed,upsell.shown,pro.gate_reached,upsell.cta_clicked,value.core_completed,value.pro_completed,retention.observed,checkout.auto_activated,evidence-report.exported,session.completed,activation.popup_opened,activation.first_test,activation.dashboard_opened,activation.checklist_step,preview.eligible,preview.shown,preview.dismissed,preview.cta_clicked,review.prompt_shown,review.prompt_opened, orreview.prompt_dismissed - source — a coarse label such as "edge-outage-upsell" or "website", identifying where the event originated
- feature — the key of the feature that triggered the paywall, if applicable
- plan — the plan identifier selected, if applicable
- edition — Free, trial, or Pro at the time of an extension event
- browser and extension version — a coarse browser family (Chrome, Edge, other, or website) and the extension version when an extension event is recorded
- coarse OS — one of Windows, macOS, ChromeOS, Linux, or blank; used only to compare activation across platforms. It cannot identify a device
- timestamp — when the event occurred
- client — a salted, non-reversible SHA-256 hash derived from your IP address and coarse browser type (user-agent string), used only to estimate repeat trials and limit abuse (see below)
- installId — a random anonymous install identifier created on your device (extension) or browser (website) only after you opt in. It lets funnel rates count distinct installs instead of raw event volume. It contains no identity and cannot be reversed into one
- eventId — a random per-event identifier used only to drop retried offline sends so they are never double-counted
- env — the runtime environment stamped by the server (
local,preview, orproduction). Client claims about environment are never trusted; decision metrics cover one environment at a time and report excluded events as counts - origin — whether the record came from a consented client event or is server-verified billing truth (checkout and subscription records)
These events contain no captured network or monitoring content, no browsing history, no page URLs, no email address, and no raw IP address.
Client hash: The raw IP address is hashed together with a coarse browser type using a server-side salt before storage; the raw IP is never stored. The hash is used only to estimate whether a trial has been claimed before and to limit trial abuse. Because many users may share the same IP address (NAT) and because IP addresses change over time (dynamic IPs), the estimate is imprecise — it can produce both false positives and false negatives. It identifies a network and browser combination, not an individual.
Trial events: If you opt in, the extension records trial.started when you begin a Pro trial and may record the trial-ending milestones in the background. The Pro trial status itself is stored in chrome.storage.sync (see Section 1).
Consent counts: When you answer the website analytics question (yes or no), we increment an anonymous daily total for that answer via POST /api/analytics-consent. Declining sends only that aggregate increment — no page-view event follows. These totals contain no IP address, no browser data, and no identity — they exist only so we can measure what share of visitors consent (the denominator for website funnel rates, not extension coverage).
6. Optional uninstall feedback
After uninstalling, the extension may open an optional feedback page. No response is required. If you submit the form, we store only the reason you selected, any text you choose to enter, the coarse browser family, extension version, and submission time. The form does not request an email address, license key, monitoring data, or browsing data. Please do not include sensitive information in free-text feedback.
7. Payments
Payments are processed by Stripe Checkout when Stripe is configured. The portal receives the checkout result and related identifiers needed to create or update a license after a successful webhook event. The current system does not store full payment card details.
If Stripe is not configured in a development environment, the checkout flow can create a local test license without real payment processing.
Failed renewals: if a subscription renewal cannot be charged, Pro stays active for a bounded grace period (7 days for monthly, 14 days for yearly plans), then pauses until payment succeeds. We store only the Stripe invoice identifier, the attempt count, and the grace deadline — never card details. Recovery happens on Stripe's own hosted invoice page, linked from the reminder email and your license page. The reminder also delivers a single-use license-management link that expires in 7 days; only a hash of that link is stored. If you explicitly ask support to stop after a failed payment, the subscription is cancelled immediately, the open invoice is voided so no retry can charge it, and a confirmation email states the immediate effect and the no-further-charge outcome.
8. How information is used
Information is used to operate the service, verify licenses, provide paid features, process checkout events, respond to support requests, and administer the system. Conversion and trial events are used to understand the purchase funnel and to limit repeat trial abuse.
9. Sharing and processors
The current system may involve third-party services that process data as part of normal operation, including:
- Stripe for payment checkout and subscription events
- Microsoft Graph for transactional license and support email when configured
- Hosting and infrastructure providers used to run the web portal
- Google connectivity, Cloudflare connectivity, Cloudflare speed test, ipify, and any custom endpoint you configure in the extension
10. Retention
Local browser monitoring data remains under the user's control and follows the retention settings enforced by the extension. Free mode is limited to shorter retention, while Pro may allow longer retention.
Portal-side conversion analytics expire automatically after 180 days by default, submitted uninstall feedback after 180 days, and closed support tickets after 180 days (all configurable up to two years). Pending checkout records expire after 24 hours; paid checkout records are removed after fulfillment. License records are retained while needed to provide Pro access, subscription management, recovery, and legal/accounting obligations. If the portal is deployed using ephemeral storage, records may also be lost between deployments or cold starts.
11. Security
The system uses bearer-style admin token protection for admin APIs and stores extension data locally in the browser. The conversion event endpoint is rate-limited and isolated from billing records. No system can guarantee absolute security, and you should avoid submitting secrets in support messages unless necessary.
12. Your choices
- You can uninstall the extension or clear browser extension storage to remove local data from your browser profile.
- You can choose whether to start a Pro trial, purchase Pro, or submit support requests.
- You can request deletion or correction of portal-side support or license records by contacting support through the support page.
13. Contact
For privacy or support questions, email support@anhbui.dev or use the support page available in this portal.