WoltFlow Token Reviewer Privacy Policy

Last updated: August 2025

Overview

WoltFlow Token Reviewer is a simple Chrome extension that reads and displays Wolt.com access and refresh tokens from your browser cookies with copy functionality.


Data Collection and Usage

What We Collect

  • Cookies Only: The extension reads two specific cookies (`__wtoken` and `__wrtoken`) from Wolt.com domains to extract authentication tokens
  • No Personal Data: We do not collect, store, or transmit any personal information
  • No Configuration Data: No user settings or preferences are stored

How We Use Data

  • Display Only: Tokens are only displayed in the extension popup for viewing and copying
  • Local Processing Only: All token extraction happens locally on your device
  • No Remote Transmission: Tokens and cookie data are never sent to external servers
  • No Storage: No data is stored by the extension - everything is temporary

Data Storage

  • No Storage: The extension does not store any data locally or remotely
  • No Cache: Tokens are fetched fresh each time you open the popup
  • Memory Only: Token data exists only in memory while the popup is open

Permissions

Required Permissions

  • Cookies: To read the two specific authentication tokens (`__wtoken` and `__wrtoken`) from Wolt.com cookies
  • Host Permission (*.wolt.com): To access cookies specifically from Wolt domains only

Permission Usage

  • Permissions are used only to read the two hardcoded cookie names
  • No access to any other cookies or data
  • Minimal permission scope limited to Wolt.com domains only
  • No storage permissions required as nothing is saved

Security

Token Handling

  • Display Only: Tokens are displayed only in the extension popup
  • No Transmission: Tokens are never sent over the network
  • No Storage: Tokens are not saved anywhere
  • Temporary Access: Tokens are only accessible while the popup is open
  • User Responsibility: Users must ensure they have authorization to access displayed tokens

Data Protection

  • All processing happens locally on your device
  • No analytics, tracking, or telemetry
  • No external dependencies or remote resources
  • No data persistence between sessions

User Rights and Control

Your Controls

  • Disable Extension: You can disable or remove the extension at any time
  • No Data to Clear: Since no data is stored, removing the extension has no data implications
  • Permission Management: You can revoke permissions through Chrome settings

Your Responsibilities

  • Ensure you have proper authorization to access tokens
  • Protect any tokens you view or copy
  • Use the extension only for legitimate development/debugging purposes

Third Party Services

This extension does not integrate with any third-party services and does not share data with external parties.


Changes to This Policy

We may update this privacy policy from time to time. Any changes will be reflected in the extension's metadata and documentation.


Contact

For questions about this privacy policy or the extension, please contact WoltFlow support.


Compliance

This extension is designed to comply with:

  • Chrome Web Store policies
  • General data protection regulations
  • Browser security best practices

Note: Handle tokens responsibly and ensure appropriate usage.