HiveFury Browser Extension: Privacy Policy
Effective date: October 7, 2026
Applies to: the HiveFury extension for Chrome (Chrome Web Store ID mgcmocglffknmbhhfjihifeldhghihpj), version 3.0.1 and later.
Published by: Interlock Network (Interlock Association, Mühlegasse 1, 6340 Baar, Switzerland), referred to here as "Interlock", "we" or "us".
Contact: rick@interlock.network
This policy explains, in plain terms, what the HiveFury extension does with data. It describes how the extension actually behaves. Where behaviour differs between versions, we say so.
1. Summary
- HiveFury warns you before you open a website, or connect a crypto wallet to a website, that is known to be dangerous.
- To do that, it checks the address of the website (for example
https://example.com) with our threat service. It doesn't send the rest of the link (the path, search terms or anything after?or#), what is on the page, or what you type. - HiveFury has no accounts. It doesn't ask for your name, email or wallet address.
- We don't sell your data. We don't use it for advertising, and we don't share it with data brokers.
- The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
2. What the extension does with data
2.1 Website safety checks
When: each time the address in a browser tab changes to an http or https page, and when a page asks your crypto wallet to connect (for example, when a site's "Connect wallet" button asks the wallet for your accounts). Recent results are remembered for a short time so the same site isn't checked over and over.
What is sent: the website's origin, meaning the scheme, host name and port (for example https://www.example.com), to our threat service at api-galactus.apps.interlock.network.
What is not sent: the full link (path, query string, fragment), page titles, page content, form fields, passwords, cookies, keystrokes, wallet addresses, private keys, transaction details, or any account or identifier for you or your device.
What comes back: a verdict (for example "known malicious", "not secure", "known wallet drainer" or "verified legitimate brand"). If a site is flagged, HiveFury replaces the tab with a warning page. You can choose to continue anyway.
What our service keeps: like every web server, the threat service sees your IP address and the time of each request. Request logs, including IP addresses, are kept for no longer than 30 days for security and abuse prevention and are then deleted. The service also keeps a list of website origins and their verdicts so future checks are faster and more accurate. That list is about websites, not people: we don't use it to identify or follow individual users.
How the wallet check works: a small script on each page notices only when the page asks a crypto wallet for access to your accounts. It then tells the extension to check that page's origin. It doesn't read page content, form fields, keystrokes, wallet addresses or transactions.
2.2 Data kept only in your browser
The following stays on your device. It isn't sent to us:
- Sites you chose to continue to after a warning (stored as the site's origin), so you aren't warned about them again.
- Recent verdicts, kept in the extension's memory for a short time to avoid repeat checks.
- A random installation ID and the date of the last usage report (see 2.3, versions 3.0.x only).
Uninstalling the extension deletes all of this.
2.3 Usage statistics (versions 3.0.x)
Once a day, versions 3.0.x send one anonymous usage event to Google Analytics, a service run by Google LLC that processes it for us. The event contains:
- a random installation ID created by the extension (not linked to your identity or Google account),
- the extension version,
- your browser's brand names as the browser reports them (for example "Google Chrome, Chromium"), and whether the browser is Mises.
Google receives your IP address as part of the request. We use these statistics only to count active installations and browser types.
2.4 Error reports from the warning page
The warning page is built into the extension. If it hits a software error, it sends an error report to Sentry, an error-monitoring service run by Functional Software, Inc. that processes it for us. A report can include the technical error details, the warning page's own address (which contains the address of the flagged site that triggered the warning), the browser and operating system version, and a short log of recent actions on the warning page. Sentry receives your IP address as part of the request. We use error reports only to find and fix bugs. No report is sent unless an error happens.
2.5 The toolbar button
Clicking the HiveFury button in the browser toolbar opens the HiveFury web app at app.hivefury.com in a new tab. The extension doesn't send that website any data. The website isn't part of the extension, and this policy doesn't cover it.
2.6 Former ThreatSlayer and HiveFury accounts
Earlier versions (ThreatSlayer and HiveFury up to 3.0.0) let people register an account. Registered users' visited links were linked to their account to calculate token rewards.
- From version 3.0.1 the extension doesn't use accounts. On install or update it deletes any stored account key from your browser, and it never sends account information or account-linked browsing data.
- The extension no longer offers token rewards, referrals, staking or wallet linking, and HiveFury doesn't pay or reward anyone for browsing data or reviews.
- Data from those former accounts held on our servers (username, email, password hash, wallet address and link history) is being deleted, and it isn't used for any purpose in the meantime. You can ask us to confirm that your data has been deleted, or ask for a copy before it is, at rick@interlock.network.
3. Planned changes in version 3.1.0
We plan to change how safety checks work in version 3.1.0, so that ordinary browsing never leaves your device:
- On-device checks. The extension would download a list of hashed prefixes of known-dangerous site addresses from our service and check each site against it locally. A hashed prefix is a short fragment of a one-way fingerprint of an address. Nothing would be sent for sites that don't match the list.
- Confirmation only on a possible match. If a site matches a prefix, the extension would send that site's origin to our service to confirm the result. Our service may confirm with Google's Web Risk service (Google LLC acting as our processor).
- Wallet-connect checks would follow the same rule.
- No usage statistics (see 2.3).
We'll update this policy, including its effective date, before version 3.1.0 is released. Everything else in this policy, including what we don't collect and our commitment never to sell data, will continue to apply.
4. How we use data
We use the data in section 2 only to:
- warn you about dangerous websites and wallet-draining sites (the extension's single purpose);
- keep the threat service and the extension working, secure and accurate, including fixing errors, and protect the service against abuse;
- count active installations (versions 3.0.x).
We don't use it for anything else. In particular, we don't use it to build profiles, personalise ads, or decide creditworthiness or lending.
5. Sharing and the "no sale" commitment
We don't sell, rent or trade data from the extension, whether raw, aggregated, anonymised or derived. We don't transfer it to advertising platforms, data brokers or other information resellers.
We transfer data only:
- to service providers who run infrastructure for us and may use it only on our instructions: Cloudflare, Inc. (network and security services; requests to our threat service pass through Cloudflare), the cloud provider that hosts our threat service's servers, Google LLC (Google Analytics in versions 3.0.x; Google Web Risk if version 3.1.0 ships as planned), and Functional Software, Inc. (Sentry error reports);
- to protect people against malware, phishing, fraud or abuse, for example reporting a dangerous website address to a browser safety list or domain registrar. Such reports contain the dangerous site's address, never information about who visited it;
- when required by law; or
- as part of a merger, acquisition or sale of assets, and only after asking for your explicit consent.
People at Interlock don't look at extension data except when it is aggregated and anonymised for running the service, when it is needed to investigate security issues, errors or abuse, or when the law requires it.
6. Limited Use statement
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In practice: the extension collects only what its single purpose (protecting you from dangerous websites) needs. Data is used only for that purpose and for keeping it secure and reliable. It is transferred only as described in section 5. It is never sold, used for advertising, or used to assess creditworthiness.
7. Retention
- Data in your browser: until you clear it or uninstall the extension.
- Threat service request logs, including IP addresses: no longer than 30 days.
- Website origin and verdict records (about websites, not people): kept while they help with detection.
- Google Analytics events (versions 3.0.x): we set Google Analytics to keep event data for the shortest period it offers (currently 2 months).
- Sentry error reports: deleted automatically by Sentry after its retention period, which is at most 90 days on Sentry's plans.
- Former account data: being deleted (see section 2.6).
8. Where data is processed
Interlock is based in Switzerland. Our service providers process data in the United States and other countries where they operate. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's standard contractual clauses.
9. Your choices and rights
- You can uninstall the extension at any time from
chrome://extensions. This stops all checks and reports and deletes local data. - Depending on where you live (including under the EU/UK GDPR and the Swiss Federal Act on Data Protection), you may have the right to ask for access to, correction of, deletion of, or a copy of personal data we hold about you, to object to or restrict its processing, and to complain to your data protection authority. Interlock Association is the controller. To exercise these rights, contact rick@interlock.network.
- Legal basis (EU/UK/Switzerland): safety checks are based on our legitimate interest, and yours, in protecting you from dangerous websites. Usage statistics in versions 3.0.x are based on our legitimate interest in counting installations, and error reports on our legitimate interest in keeping the extension working.
- California and other US states: we don't sell or "share" personal information for cross-context behavioural advertising.
10. Children
The extension isn't directed at children under 13 (or under 16 in the EU), and we don't knowingly collect their personal information.
11. Security
Requests to our service use HTTPS. Access to our servers is limited to authorised staff. No method of transmission or storage is completely secure, but we work to protect the data we handle.
12. Changes to this policy
If we change what the extension collects or how we use it, we'll update this policy before the change ships, change the effective date above, and describe the change in the extension's release notes. We won't use data in ways that are materially different from this policy without asking for your consent.
13. Contact
Interlock Association (Interlock Network), Mühlegasse 1, 6340 Baar, Switzerland
rick@interlock.network