Security
Last updated: September 29, 2026
At FlowClip, we believe in a security-by-design approach. Our extension is built to minimize risk by keeping data processing local to your device.
Core Security Principles
- No Backend: We do not operate a backend server for data processing. All extraction logic happens directly within your browser.
- No Remote Code: FlowClip does not download or execute any remote JavaScript. All executable code is packaged and reviewed within the Chrome extension itself.
- Minimal Permissions: We strictly adhere to the principle of least privilege. We use the
activeTabpermission instead of broad host permissions wherever possible, meaning the extension only accesses the webpage you are currently viewing after you explicitly interact with it. - User-Initiated Extraction: Data is only extracted when you click or select elements to extract. We do not automatically scrape pages in the background.
- Local Storage & Exports: Extracted data is stored in your browser's local storage and exported directly to your local file system. It is never transmitted to us.
- No Credential Collection: We do not intentionally collect, extract, or store passwords, authentication tokens, or sensitive financial information.
Security Reporting
If you discover a security vulnerability or have a security concern regarding FlowClip, we appreciate responsible disclosure.
Please report security issues to: h.nazir@gridcore.co
Note: While we highly value and appreciate responsible disclosure to help keep our users safe, we do not currently offer a bug bounty payment program.