Single purpose
Flash Route is designed only to select and apply routes to supported online services in Chrome.
Which Chrome API data is required for Flash Route's single purpose and how Limited Use applies.
Flash Route is designed only to select and apply routes to supported online services in Chrome.
Use and transfer of information received from Google Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Through Chrome APIs the extension processes selected services and their domains, proxy and permission state, random install/device identifiers, platform and version, local account state and short-lived access data. The signed installation attestation is stored locally and in Chrome Sync when synchronisation is enabled. For the first successful route, only the service ID, UTC timestamp and fixed route class authorized_selected_service are stored locally once. Active correlation records use Chrome's request ID only to bind the current route generation and owned proxy endpoint until the terminal request event or browser session ends; this is not a separate store with an independent count or time limit. Only rejected terminal tombstones are bounded to at most 128 records with a 60-second TTL. Visited URLs, page content, cookies and credentials are not stored in this correlation. During bounded recovery, the extension checks a fixed selected-service endpoint with a HEAD request and random nonce, without credentials or a body; it does not repeat the failed user's URL, is valid for at most 30 seconds and is bounded by the recovery deadline, and remains a local observation rather than proof of server-side acceptance or independent egress.
Chrome API data is used only for selective routing, account, trial, licence, purchase, security, recovery and support of this feature. It is not sold, transferred to data brokers, used for unrelated advertising or credit decisions, or used to build a browsing profile.
There are no content scripts. Flash Route does not read page or chat content, password fields or other form data, user files, or browsing history.
Before starting a trial, sign-in, purchase, or any proxy/edge processing, the extension presents this disclosure and direct Privacy and Limited Use links. The package already contains 26 required host origins: 25 for the five supported services and one fixed Route Proof diagnostic endpoint, route-proof.flashroute.app. The diagnostic runs only from an explicit user action, is not a selectable service, and does not change the selected route; selecting a service controls routing and credential authorisation, not a new host-permission grant. The Flash Route API host is optional and is requested only from an explicit sign-in or access action. Processing starts only after separate affirmative consent stored with a version in chrome.storage. When a disclosure is new or changed, selected services are blocked locally without falling back to DIRECT; the saved session stays local and routing resumes only after consent.
Recipients and retention match the published Privacy Policy: infrastructure/hosting, email and payment providers only for the corresponding action, and Chrome Sync only by user setting; short-lived data expires, local logs are capped, and other records are retained only as necessary for the stated purposes and applicable requirements.
Human access is allowed only with explicit support consent, in anonymised form for internal operations, for security, or when required by law.
The manifest declares 26 required host origins: 25 for five supported services — YouTube, ChatGPT, Gemini, Grok, and WhatsApp Web — and one fixed Route Proof diagnostic endpoint, route-proof.flashroute.app. The diagnostic runs only from an explicit user action, is not a selectable service, does not change the selected route, and is not used to read content. onCompleted/onErrorOccurred processing is limited to the supported-service domains and considers only the selected service. The Flash Route API host is the only optional host and is requested only from an explicit sign-in or access action. The manifest does not declare <all_urls>. Optional privacy is requested separately for WebRTC protection.