浏览器增强隐私政策

飞花浏览器增强只与同一台 Windows 电脑上的飞花桌面应用通信,不运营云端账号,也不把浏览数据或凭据上传到飞花服务器。

最后更新:2026 年 8 月 11 日

适用范围

本政策适用于 Firefox、Chrome 与 Edge 上的“飞花 - PetalDesk 浏览器增强”。各版本使用相同的本地数据处理和安全边界,为飞花桌面应用提供长截图、由用户点选账户触发的密码填充、用户提交登录时的保存或更新提示,以及与本地 TOTP 的受控联动。

处理的信息

扩展不会为广告、分析或画像收集页面正文、完整浏览历史、付款信息、健康信息、位置或广告标识符。

使用方式

扩展不会绕过多因素认证,只会在上述受信任流程中填入明确关联的本地 TOTP。恢复码、CAPTCHA、Passkey、短信或邮件验证码、安全密钥、CVV、邮编和优惠码完全排除。

存储与保留

扩展不会把密码、MFA ID、TOTP 或登录候选写入 Firefox/Chrome/Edge storage、磁盘、日志、诊断或旧的截图文件通信目录。尚未进入保存提示的含密码候选最多在扩展内存中保留 30 秒;提交给本机飞花后,扩展立即清空密码,只保留恢复提示所需的非秘密元数据。桌面端把待确认候选仅保留在当前进程内存中,直到用户保存、更新、忽略或关闭,或标签页关闭、用户关闭登录检测、锁库、断连。两步登录中的纯用户名阶段最多保留 2 分钟;二次验证 journey 最长 5 分钟,每个字段 challenge 最长 30 秒且只能消费一次。

用户选择保存的凭据由飞花桌面应用写入本地 XChaCha20-Poly1305 加密保险库,保留与删除由用户在飞花中控制。

传输、共享与安全控制

扩展不出售、出租或向远程第三方传输个人信息。Native Messaging 只连接当前 Windows 用户下注册的飞花本机程序。

用户选择与联系

身份验证信息权限为安装时的必要权限:用户可以在安装时拒绝(扩展将无法启用)、手动锁定密码保险库、删除已保存账户,或卸载扩展。

隐私与支持问题请通过 PetalDesk GitHub Issues 联系项目维护者。

PetalDesk Browser Companion Privacy Notice

Last updated: August 11, 2026

PetalDesk Browser Companion communicates only with the PetalDesk desktop application on the same Windows computer. It has no PetalDesk cloud account and does not upload browsing data or credentials to a PetalDesk server.

Information handled and purpose

The extension handles website activity needed for user-initiated long screenshots; exact origins and tab, document, and frame identifiers needed to bind a password request; and usernames, passwords, and a short-lived current TOTP when the user has linked local MFA. The authentication-information permission is required and granted once at install time.

A fill offer contains no password. After the user chooses an account in PetalDesk or the toolbar popup, the target frame confirms its identity and field availability before the desktop application provides one-time credentials. The extension fills fields but never submits a form. A linked password fill, or a manual login that exactly matches one unique saved account, can start a five-minute second-factor journey. One high-confidence TOTP field can be filled automatically; ambiguous candidates require a user click, and a different exact HTTPS origin requires first-use confirmation. The popup receives only a hasMfa flag. PetalDesk writes an MFA copy directly to the system clipboard and returns only its remaining validity; TOTP expiry alone does not clear the value, while an explicit MFA lock or PetalDesk shutdown may clear the unchanged copy.

Storage, sharing, and retention

Credentials, MFA identifiers, TOTP codes, and login candidates are not written to Firefox, Chrome, or Edge storage, disk, logs, diagnostics, or the legacy screenshot file bridge. A pre-prompt candidate containing a password remains in extension memory for no more than 30 seconds. After it is handed to the local PetalDesk process, the extension clears the password and keeps only non-secret metadata needed to restore the prompt after navigation. The desktop keeps the pending candidate only in process memory until the user saves, updates, ignores, or closes it, or until the tab closes, login detection is disabled, the vault is locked, or the local connection ends. A username-only stage may remain for up to two minutes. A second-factor journey lasts at most five minutes and each bound field challenge lasts at most 30 seconds and is single-use.

The extension does not sell, rent, or remotely transmit personal information. Native Messaging transfers data only to the registered PetalDesk executable under the same Windows user account.

Controls and contact

Password operations are bound to one session, tab, document, top-level origin, and validated target frame. Cross-origin password delegation is denied by default; the only current explicit mapping is from mail.163.com to its dl.reg.163.com login frame. HTTP and HTTPS submissions both produce save or update decisions; accepting an HTTP save shows a plaintext warning and enables later filling only for that exact origin. TOTP is bound to a separate single-use challenge and exact HTTPS origin; cross-origin OTP frames are rejected. The extension never submits a form or bypasses MFA. Recovery codes, CAPTCHA, passkeys, SMS or email codes, security keys, CVV, postal codes, and coupons are excluded.

The authentication-information permission is required at install time. Users may decline it during installation (the extension cannot run without it), lock the password vault, delete accounts, or uninstall the extension. Questions can be filed through PetalDesk GitHub Issues.