Informativa sulla privacy per OpenAsGuest – Shared Link Access Checker
OpenAsGuest – Shared Link Access Checker di backstop-dev
Informativa sulla privacy per OpenAsGuest – Shared Link Access Checker
OpenAsGuest privacy notice
Last updated: July 28, 2026
OpenAsGuest checks supported Google Drive and Dropbox file links directly from Firefox. It has no developer-operated server, account, analytics, advertising, telemetry, or persistent link history.
A provider check occurs only when the user:
- pastes or prefills a recognized file link and chooses Check as guest or Check this page as guest;
- right-clicks a recognized file link and chooses Check link with its provider as guest; or
- chooses Recheck after fixing for a previous restricted or broken result.
Opening the toolbar popup grants temporary
activeTab access and can read the active tab URL to recognize and prefill a supported sharing page. That recognition happens locally. Merely opening the popup does not contact Google, Dropbox, OpenAsGuest, or Buy Me a Coffee.For a requested check, OpenAsGuest sends a normalized version of the selected link directly to its original Google or Dropbox sharing flow using:
credentials: "omit";cache: "no-store"; andreferrerPolicy: "no-referrer".
The request does not include the user’s existing provider cookies, HTTP authentication credentials, or TLS client credentials. The provider still receives the requester’s IP address and ordinary network/device information. OpenAsGuest is not an anonymity or anti-tracking service.
Firefox may follow provider-controlled redirects. A result is accepted only when the final HTTPS response remains on an allowlisted Google or Dropbox access/content host. An unexpected final host produces Couldn’t verify guest access.
Some links contain a
resourcekey, rlkey, or similar capability value needed for guest access. OpenAsGuest preserves only the recognized provider token needed for the check and removes unrelated query parameters. Treat sharing links as potentially sensitive.HTML or text provider responses are inspected locally as inert text, never rendered or executed, and read only up to 512 KiB. Dropbox shared-file checks request
Range: bytes=0-0. When Dropbox returns a binary file response, OpenAsGuest verifies the status, content type, and final host, then cancels the response body.The background process can retain a sanitized result in memory under a SHA-256 hash of the prepared link. Confirmed results expire within ten minutes; ambiguous results expire within 30 seconds. Toolbar checks and repair rechecks bypass that cache and request a fresh result.
For a right-click check, a random opaque job identifier, the selected link, and a sanitized result can remain in background memory for up to ten minutes so the internal result page can display and recheck it. The tested link is never placed in that page’s address. All temporary data disappears when it expires or the extension background is restarted.
OpenAsGuest does not write sharing links, query parameters, provider responses, file titles, check results, or usage counts to persistent extension storage.
OpenAsGuest does not send the developer:
- sharing links or capability parameters;
- provider responses or file titles;
- browsing history;
- check results or usage counts;
- identifiers, diagnostics, or crash reports.
There is no remote database, cloud synchronization, or link-history screen.
OpenAsGuest requests:
activeTab, to read the current tab URL only after the user opens the toolbar popup and prefill it when supported;contextMenus, to provide the deliberate right-click check; and- access to named Google Drive, Google sign-in, Dropbox, and Dropbox content hosts needed for the requested signed-out check and provider-controlled redirects.
It does not request
<all_urls>, clipboard, cookies, storage, notifications, webRequest, private-window, or content-script access.The manifest declares Mozilla’s required
websiteContent category because the selected provider link is transmitted to Google or Dropbox and the returned provider response is inspected locally. Nothing is transmitted to the developer.The extension-owned interface shows its Buy Me a Coffee prompt only after a fresh recheck verifies that a link previously reported as restricted or broken now opens without sign-in. Every feature remains free.
Opening Buy Me a Coffee is a separate, user-initiated visit to a third-party website. No checked link or result is appended to that URL. Buy Me a Coffee’s own privacy terms apply to that visit.
Questions can be directed through the creator page above until a dedicated monitored support address is published.