Skip to content
v1.0.0

Privacy and security

Effective date: 6 October 2026

Wireglass is built to keep your data on your machine. It has no servers or accounts, and Melliforge never receives any of your data. This page is the privacy policy for the Wireglass extension.

Only the requests you send: a query when you press Run, an introspection query when you press Refresh schema (or Run on a tab with no schema), and gql.fetch calls from scripts you enabled. There is no analytics, telemetry or other outbound traffic.

  • Settings, history, collections, environments and cached schemas live in chrome.storage.local, in your browser profile.
  • Captured traffic is kept in memory only and is gone when DevTools closes (apart from the Preserve log setting itself).
  • History keeps {{placeholders}}, never the resolved value of an environment variable. A header you type literally, such as Authorization: Bearer …, is saved as typed. Put tokens in a secret environment variable instead.
  • Environment secrets are exported as empty strings unless you tick Include secrets.
  • Collection exports leave header values empty unless they are only a {{placeholder}}.
  • Traffic Copy as… and Export HAR keep only format headers and redact token-like URL parameters unless Include secrets is ticked.

Scripts are off until you enable them per tab, and imported files never enable them. They run in a Worker in a sandboxed extension page with no network access of its own, so gql.fetch (with timeouts and size limits) is the only way out. A script can still send out what it can read, so only run scripts you have read.

To capture WebSocket subscriptions and apply mocks, Wireglass injects a small hook into pages. It wraps WebSocket, fetch and XMLHttpRequest; non-GraphQL traffic is passed through untouched and never reported. Events go only to this extension’s own panel, and only while it is open for that tab. While mocks are active, the rules reach the page’s hook through a window message, so scripts on that page could read them.

By default an image from a response loads only when you hover or select its row, and is requested without a referrer. See the response viewer.

Wireglass does not sell, share or transfer your data to anyone. It does not use your data for advertising, creditworthiness or any purpose other than inspecting and running GraphQL requests. Chrome sync is not used, so nothing is copied to your Google account, and uninstalling the extension deletes everything it stored.

  • Storage: saves your settings, history, collections, environments, mock rules and cached schemas in your browser.
  • Access to all sites: lets the client send requests to any GraphQL endpoint you choose, and lets the page hook capture GraphQL traffic and apply mocks on the pages you inspect.

If this policy changes, the new version is published on this page with a new effective date. For questions, bug reports or feedback, use the Support tab of Wireglass’s page in the Chrome Web Store.