Privacy Policy · WhereToSubmit - Blog Backlink Helper

Last updated: 2026-09-04

By default this extension does not go online. Everything stays in your own browser on your own computer. Only after you deliberately connect it to a wheretosubmit.org account — a paid feature — does it talk to that site, and only for two things: fetching the list of target URLs, and reporting back that a given one was submitted. No third-party analytics, telemetry, or advertising SDKs.

1. What the extension stores

The following is created by you and saved in local browser storage (chrome.storage.local), on this device only:

Comment libraryThe comment text and labels you write
Identity profilesThe name, email and website you type or generate
SettingsEmail domain list, name style, rotation mode, and the count and delays for auto-submit
Field bindingsThe hostname of sites where you manually bound a field, plus the element selector
Usage logWhich hostnames (e.g. example.com) each comment has been used on, so the extension can warn you about reusing the same text on one site. No full URLs, page titles or page content.
Device tokenOnly once you connect an account. A random string issued by the site, used to prove to the API that this device belongs to that account. Your password is never stored.
Target list cacheOnly once you connect and have a plan. Public directory data pulled from wheretosubmit.org — hostname, URL, category, authority score — plus your own submitted marks.

None of this is uploaded, and none of it is included in any request the extension makes — with the single exception described in section 3.

2. What page content the extension reads

The extension reads a page in two situations: when you click the toolbar icon, or when you turn on and start auto-submit, where the extension opens the target page itself. What it reads is:

All of this happens in memory. Nothing is written to storage and nothing is transmitted anywhere. It is gone when the tab closes.

The extension does not read: password fields (input[type=password] is never a candidate), cookies, localStorage, browsing history, bookmarks, downloads, or any page text outside those form fields.

3. What goes over the network once you connect an account

Only after you connect the extension to an account does it make requests to https://wheretosubmit.org. There are exactly four:

WhenWhat is sent
You type a pairing code and press Connectthat 8-character code, plus a rough device name (e.g. macOS · Chrome) so you can tell your devices apart on the account page
Confirming who you are after connectingthe device token
Syncing the target listthe device token, the project id you picked, paging parameters
End of an auto-submit runthe device token, the project id you picked, and the ids of the targets that were submitted in that run

What is never sent: your comment text, your name or email, the URL you are promoting, which pages you visit, which sites failed, or any page content or screenshots.

Requests carry only the device token for authentication — never your site login cookie. You can revoke a token from the account page at any time, which kills it immediately; “Disconnect” in the extension clears the local copy.

4. What the extension does not do

5. Why each permission is needed

storageto save the local data listed in section 1
sidePanelto show the control panel
activeTabgrants temporary access to the current tab when you click the toolbar icon, and only then
scriptingto inject the detection and filling script into the page
alarmsfor auto-submit only: the browser evicts idle background scripts, and a timed wake-up lets an interrupted run finish
https://wheretosubmit.org/* (optional)the extension’s own backend, for the four calls in section 3. Declared as an optional permission and never requested at install or update time — only when you press Connect in the panel. Revocable at any time.
Site access (optional)not requested at install time. The manual tab can be granted access to one site at a time. The auto tab needs all-sites access, because it fills forms on whichever blogs your plan covers; it asks for that in its own prompt before the first run, and it is revocable at any time in your browser’s extension settings.

Installing this extension does not show a “read your data on all websites” warning. That permission is only requested when you enable auto-submit.

6. Deleting your data

7. Third parties

No third-party services, SDKs or analytics are integrated. wheretosubmit.org is the extension’s own backend, not a third party.

Note that once a comment is submitted to a blog, that content is handled by that website under its own privacy policy, which is unrelated to this extension.

8. Children

This extension is not directed at children under 13 and does not knowingly collect information from them.

9. Changes

If this policy changes, the date at the top is updated. Should any future version add another feature involving data transmission, it will be disclosed and consented to before it ships.

10. Contact

hi@wheretosubmit.org

隐私政策 · wheretosubmit-博客反向链接提交助手

最后更新:2026-09-04

默认情况下这个插件不联网,所有内容只保存在你自己电脑的浏览器里。 只有当你主动把插件连接到 wheretosubmit.org 账号(付费功能)之后,插件才会与该站通信, 通信内容仅限于「取回目标网址列表」和「回传某条已提交」两件事。插件不接任何第三方统计、埋点或广告 SDK。

一、插件会保存什么

以下内容由你自己创建,保存在浏览器本地存储(chrome.storage.local)中,只存在于这台设备上:

正文库你写的评论正文和条目名称
身份档案你填写或随机生成的昵称、邮箱、网址
设置项邮箱域名列表、昵称风格、轮换方式,以及自动提交的数量与各段延迟
字段绑定你手动指定过字段的站点域名,及对应的元素选择器
使用记录每条正文用过哪些域名(例如 example.com),用于提醒你别在同一站点重复用同一条内容。不记录具体网址、页面标题或页面内容
设备令牌只在你连接账号后出现。是一枚由网站签发的随机字符串,用于向接口证明「这台设备属于这个账号」。不保存你的密码
目标列表缓存只在你连接账号且已订阅后出现。是从 wheretosubmit.org 取回的公开目录数据(域名、网址、分类、权重)加上你自己的提交标记

这些数据不会被上传,也不包含在插件发出的任何请求里 —— 唯一例外见第三节。

二、插件会读取什么网页内容

插件在两种情况下读取页面:你主动点击插件图标,或你主动开启并启动自动提交(由插件自己在后台标签页里打开目标页面)。读取的内容是:

这些读取全部在内存中完成,不写入存储,不发送到任何地方,标签页关闭即消失。

插件不读取:密码框(input[type=password] 从不进入候选范围)、Cookie、localStorage、浏览历史、书签、下载记录,也不读取正文以外的页面文本。

三、连接账号后会发生什么网络通信

只有在你把插件连接到账号之后,插件才会向 https://wheretosubmit.org 发起请求。全部通信只有这四个接口:

时机发出去的内容
你输入配对码点「连接」那 8 位配对码,以及一个粗略的设备名(如 macOS · Chrome),用于你日后在账号页分辨设备
连接后确认身份设备令牌
同步目标列表设备令牌、你选择的项目 id、分页参数
一轮自动提交结束设备令牌、你选择的项目 id、以及这一轮提交成功的目标条目编号

不会发出去的内容:评论正文、你的昵称与邮箱、你要推广的网址、你访问过哪些网页、你在哪些站点提交失败、任何页面内容或截图。

请求只带设备令牌做鉴权,不携带你在网站上的登录 Cookie。令牌可以随时在网站账号页吊销,吊销后插件立刻失效;插件里的「断开连接」则是清掉本机这一份。

四、插件不做什么

五、权限为什么需要

storage保存上面第一节列出的本地数据
sidePanel显示操作面板
activeTab你点击插件图标时,临时获得当前标签页的访问权。不点就没有
scripting把识别和填充脚本注入到页面
alarms仅自动提交用:浏览器会回收空闲的后台脚本,靠定时唤醒把中断的那一轮接着跑完
https://wheretosubmit.org/*(可选)插件自己的后端,用于第三节列出的那四个接口。声明为可选权限,安装和更新时都不申请,只在你点面板里的「连接」时才现场征求同意,随时可撤销
站点访问权(可选)安装时不申请。手动栏可以对单个站点一次性授权;自动栏需要「所有网站」权限,因为它要在你订阅内的各个博客上填表 —— 这一项在你启动自动提交前会单独弹窗征求同意,可随时在浏览器扩展设置中撤销

安装这个插件时,浏览器不会提示「读取你在所有网站上的数据」。那项权限只在你启用自动提交时才申请。

六、你怎么删除数据

七、第三方

本插件不集成任何第三方服务、SDK 或分析工具。wheretosubmit.org 是本插件自己的后端,不是第三方。

需要说明的是:当评论被提交到某个博客之后,那些内容就归该网站处理了,适用的是那个网站自己的隐私政策,与本插件无关。

八、儿童

本插件不面向 13 岁以下儿童,也不会有意收集儿童信息。

九、政策变更

若本政策有变动,会更新本页顶部的日期。若未来版本新增其他涉及数据传输的功能,会在更新前明确告知并征得同意。

十、联系方式

有疑问请联系:hi@wheretosubmit.org

WhereToSubmit · wheretosubmit-博客反向链接提交助手
插件介绍 · Extension page · wheretosubmit.org