1. Summary
o-flag has a single purpose: it shows the likely country or region of the current website in the browser toolbar icon and popup.
The extension does not sell personal data, does not use data for advertising or profiling, does not use data for creditworthiness decisions, and does not execute remote code.
o-flag does not require account creation or sign-in. Most processing happens locally in the browser, with limited third-party network requests used only when needed to support region detection.
2. Data the Extension Processes
To provide its region-detection feature, the extension may process the following categories of data:
- Top-level page URL and hostname. The extension reads the URL and hostname of HTTP or HTTPS pages visited in browser tabs so it can determine and display a region indicator for that page.
- Top-level network metadata. The extension observes main-frame request and response metadata, such as response headers, request URL, and the resolved server IP address made available by the browser.
- User public IP address. The extension retrieves the user's current public IP address so it can choose the most relevant DNS lookup path and improve region detection accuracy.
- Locally cached lookup results. The extension stores local cache records such as hostname-to-IP mappings, IP-to-country mappings, and Cloudflare-derived country codes.
The extension does not read page content, form entries, passwords, emails, messages, or payment information.
3. How the Data Is Used
- To determine the likely country or region associated with the currently visited website.
- To display the corresponding flag and region label in the browser action icon and popup.
- To reduce repeated network requests and improve performance through local caching.
- To reapply the correct indicator after top-level page navigation.
Data processed by the extension is used only for the extension's core feature and not for analytics, advertising, or any unrelated purpose.
4. Permissions Used
-
host_permissions: Allows the extension to work on HTTP and HTTPS pages the user visits so the region icon can be shown consistently. -
tabs: Used to identify the active tab, read the current page URL, and set the correct per-tab icon and title. -
storage: Used to store a short-lived local cache and avoid repeated network lookups. -
webNavigation: Used to detect top-level navigation completion so cached region information can be reapplied. -
webRequest: Used to observe top-level request and response metadata needed for region detection. The extension does not block, redirect, or modify requests.
5. Third-Party Services
The extension makes HTTPS requests to third-party services to retrieve lookup data required for its core functionality:
-
https://td5s.co/ipto retrieve the user's current public IP address. -
https://doh.pub/dns-queryto resolve DNS records for the current hostname. -
https://www.ip112.com/api/geoipto map an IP address to a country code.
When the extension contacts these services, those providers may receive normal request metadata such as the user's IP address, user agent, request time, and the queried hostname or IP address, according to their own server operations and privacy practices.
Because these services are operated by third parties, related request data may be processed on infrastructure and in jurisdictions outside the user's country or region.
External responses are treated as data only. The extension does not download or execute remote JavaScript, remote modules, or other remote executable code.
6. Storage and Retention
-
The user's public IP address is cached in
chrome.storage.localfor up to approximately one hour. - Lookup caches are stored locally in the browser using extension storage and IndexedDB.
- The extension does not sync this cache through a cloud account.
- Domain and Cloudflare-derived cache entries are retained for up to approximately seven days unless they are refreshed or the extension data is cleared sooner.
- Stored cache data remains on the user's device until it expires, becomes stale, or the extension is removed.
8. Security
The extension is designed to minimize data use and keeps caches on the user's device. Network lookups are sent over HTTPS to the endpoints listed in this policy. No security measure is perfect, but the extension aims to limit data access to what is reasonably necessary for the region-detection feature.
9. Your Choices
- You can stop all data processing by disabling or uninstalling the extension.
- Removing the extension will remove extension-managed local data from the browser as part of Chrome's extension removal flow.
- You may also clear extension-related data through browser tools if supported by your browser environment.
10. Children's Privacy
This extension is not directed to children and is not designed to knowingly collect personal information from children.
11. Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes to the extension, review requirements, or applicable policies. The updated version will be posted on the same page with a revised "Last updated" date.
12. Contact
For privacy questions or support requests related to o-flag, contact the developer through the project's support channel: https://github.com/xnny/o-flag/issues