Privacy policy.

Whatfired records what your Meta Pixel sends so you can inspect it — and everything it records stays inside your browser. Last updated: September 14, 2026.

Summary

Everything Whatfired records is stored on your device only. Values that look personal are masked the moment they are read, recordings are kept for 15, 30 or 60 minutes and then discarded, and nothing is sold or shared with anyone — including Meta, ad networks, and data brokers. There are no accounts, no analytics, no telemetry and no advertising.

What Whatfired observes

On the pages you visit, the extension watches: calls the page makes to its own pixel function (fbq), requests the page sends to Meta's collection endpoint and the parameters attached to them, which pixel IDs are present and which frame each event came from, and the address and title of the tab being inspected so recordings can be grouped by page. It observes requests to Meta's endpoint only — traffic to any other destination passes through untouched. It does not read page text, form fields, images, cookies, local storage or the DOM beyond the pixel's own calls.

Personal data and masking

One kind of problem Whatfired exists to catch is a site sending personal data — an email, a phone number, a name — to Meta without hashing it first. To make that safe to inspect, values that look personal are masked at the moment they are read: an email becomes j***@e***.com, a phone number becomes +4*******58. The original text is never written to storage and never shown in the panel, so a screenshot of a debugging session is not itself a data breach. Exports contain masked values only, because no unmasked copy exists anywhere.

Where the data lives

Event recordings are held in the browser's session storage, keyed by tab, and are discarded when the retention window elapses or the tab closes. Your settings — language, theme, retention window, whether recording is paused — are held in the browser's local storage and kept until you change them or uninstall. There is no account, no sign-in, and no copy of your recordings outside this browser.

Retention and deletion

Recordings are kept for the window you choose — 15, 30 or 60 minutes (30 by default) — then deleted automatically. Closing a tab erases that tab's recording immediately. Uninstalling the extension removes all stored data with it.

Network activity

Your recorded event data never leaves your browser. The network traffic you see while using Whatfired is the traffic the pages you visit already produce on their own — the extension watches it happen and does not generate, forward or modify it. The extension contacts exactly one website of its own: the Whatfired product site, which hosts the release notes it opens after updates. That site keeps a record of the installed version so the notes match what you are running, and nothing else.

Sharing

Data recorded by the extension is never sold, rented or traded, and never shared with third parties — including Meta / Facebook, advertising networks, analytics providers and data brokers.

Exports

When you export a recording, the file is written by the popup from its own data on your device and contains masked values only.

Permissions and why they are needed

storage — holds recorded events (session) and your settings (local) on your device; nothing recorded is ever written to a server. alarms — once a minute, wakes the extension to enforce the retention window: it deletes events older than your limit and discards recordings of tabs you have closed. Host access to one site — the extension's own product website only, which serves its release notes; no other site is accessed. Content scripts — two small scripts run on the pages you inspect, one in the page's own context to watch the pixel's fbq function and network calls, one in an isolated context to relay what it saw; they also run inside embedded frames, including frames with no URL of their own, because checkout and booking widgets frequently carry their own pixel. Every wrapped call is passed through to the original untouched — the page's tracking behaves exactly as it would without the extension.

Children

Whatfired is a developer tool and is not directed at children. It collects no personal information from anyone.

Changes to this policy

If this policy changes, the updated version is published on this page with a new date at the top. Continuing to use the extension after a change means you accept the revised policy.