浏览器增强隐私政策
飞花浏览器增强只与同一台 Windows 电脑上的飞花桌面应用通信,不运营云端账号,也不把浏览数据或凭据上传到飞花服务器。
最后更新:2026 年 8 月 11 日
适用范围
本政策适用于 Firefox、Chrome 与 Edge 上的“飞花 - PetalDesk 浏览器增强”。各版本使用相同的本地数据处理和安全边界,为飞花桌面应用提供长截图、由用户点选账户触发的密码填充、用户提交登录时的保存或更新提示,以及与本地 TOTP 的受控联动。
处理的信息
- 长截图所需的网站活动数据,例如滚动位置、视口尺寸和页面稳定状态。
- 用于把密码请求绑定到正确页面的精确网址 origin、标签页、文档和 frame 标识。
- 用户主动选择账户填充或提交登录时所需的用户名和密码,以及已关联账户在受信任登录流程中短暂使用的当前 TOTP(所需数据权限已在扩展安装时作为必要权限确认)。
扩展不会为广告、分析或画像收集页面正文、完整浏览历史、付款信息、健康信息、位置或广告标识符。
使用方式
- 长截图数据通过浏览器 Native Messaging 发送给本机飞花进程,用于完成用户主动发起的截图。
- 用户在飞花或工具栏弹窗中选择账户后,扩展先向目标页面发送不含密码的填充请求;目标 frame 的身份和字段可用性校验通过后,桌面应用才提供一次性凭据。扩展只填写字段,绝不自动提交表单。
- 连接的密码保险库可用时,登录检测默认开启,用户也可在扩展弹窗中单独关闭。用户提交登录后,扩展把候选交给本机加密保险库判断是否完全相同、需要新增或需要更新。
- 飞花填入已关联账户的密码,或手动登录与唯一已保存账户完全一致时,会为该标签页建立最长 5 分钟的二次验证 journey。唯一可信的 TOTP 字段可自动填入;模糊字段先询问用户,跨 origin 页面首次确认精确 HTTPS origin。飞花不点击按钮、不发送 Enter,也不主动提交表单。
- 工具栏弹窗只知道账户是否关联 MFA。用户点击复制 MFA 后,由桌面应用重新校验当前标签页和账户关联并直接写入系统剪贴板;验证码失效本身不会清空该值,只有被其他内容替换,或用户主动锁定 MFA、退出飞花时才会清理未被替换的值。弹窗只收到剩余有效秒数,MFA ID、密钥和验证码不会返回弹窗。
扩展不会绕过多因素认证,只会在上述受信任流程中填入明确关联的本地 TOTP。恢复码、CAPTCHA、Passkey、短信或邮件验证码、安全密钥、CVV、邮编和优惠码完全排除。
存储与保留
扩展不会把密码、MFA ID、TOTP 或登录候选写入 Firefox/Chrome/Edge storage、磁盘、日志、诊断或旧的截图文件通信目录。尚未进入保存提示的含密码候选最多在扩展内存中保留 30 秒;提交给本机飞花后,扩展立即清空密码,只保留恢复提示所需的非秘密元数据。桌面端把待确认候选仅保留在当前进程内存中,直到用户保存、更新、忽略或关闭,或标签页关闭、用户关闭登录检测、锁库、断连。两步登录中的纯用户名阶段最多保留 2 分钟;二次验证 journey 最长 5 分钟,每个字段 challenge 最长 30 秒且只能消费一次。
用户选择保存的凭据由飞花桌面应用写入本地 XChaCha20-Poly1305 加密保险库,保留与删除由用户在飞花中控制。
传输、共享与安全控制
扩展不出售、出租或向远程第三方传输个人信息。Native Messaging 只连接当前 Windows 用户下注册的飞花本机程序。
- 密码操作绑定单次会话、标签页、文档、顶层 origin 和经过校验的目标 frame。跨源委派默认拒绝;当前唯一明确允许的是
mail.163.com到其dl.reg.163.com登录 frame 的单向委派。 - 每次填充都需要用户先明确选择账户,且扩展不会自动提交。
- TOTP challenge 绑定连接、flow、标签页、顶层 HTTPS origin、frame 和文档;跨 origin 首次需确认精确站点,跨 origin OTP iframe 一律拒绝。
- HTTP 与 HTTPS 登录提交都会触发保存或更新判断;HTTP 在接受保存时显示明文风险,并只为该精确 origin 允许后续填充。TOTP 仍要求 HTTPS。
用户选择与联系
身份验证信息权限为安装时的必要权限:用户可以在安装时拒绝(扩展将无法启用)、手动锁定密码保险库、删除已保存账户,或卸载扩展。
隐私与支持问题请通过 PetalDesk GitHub Issues 联系项目维护者。
PetalDesk Browser Companion Privacy Notice
Last updated: August 11, 2026
PetalDesk Browser Companion communicates only with the PetalDesk desktop application on the same Windows computer. It has no PetalDesk cloud account and does not upload browsing data or credentials to a PetalDesk server.
Information handled and purpose
The extension handles website activity needed for user-initiated long screenshots; exact origins and tab, document, and frame identifiers needed to bind a password request; and usernames, passwords, and a short-lived current TOTP when the user has linked local MFA. The authentication-information permission is required and granted once at install time.
A fill offer contains no password. After the user chooses an account in PetalDesk or the toolbar popup, the target frame confirms its identity and field availability before the desktop application provides one-time credentials. The extension fills fields but never submits a form. A linked password fill, or a manual login that exactly matches one unique saved account, can start a five-minute second-factor journey. One high-confidence TOTP field can be filled automatically; ambiguous candidates require a user click, and a different exact HTTPS origin requires first-use confirmation. The popup receives only a hasMfa flag. PetalDesk writes an MFA copy directly to the system clipboard and returns only its remaining validity; TOTP expiry alone does not clear the value, while an explicit MFA lock or PetalDesk shutdown may clear the unchanged copy.
Storage, sharing, and retention
Credentials, MFA identifiers, TOTP codes, and login candidates are not written to Firefox, Chrome, or Edge storage, disk, logs, diagnostics, or the legacy screenshot file bridge. A pre-prompt candidate containing a password remains in extension memory for no more than 30 seconds. After it is handed to the local PetalDesk process, the extension clears the password and keeps only non-secret metadata needed to restore the prompt after navigation. The desktop keeps the pending candidate only in process memory until the user saves, updates, ignores, or closes it, or until the tab closes, login detection is disabled, the vault is locked, or the local connection ends. A username-only stage may remain for up to two minutes. A second-factor journey lasts at most five minutes and each bound field challenge lasts at most 30 seconds and is single-use.
The extension does not sell, rent, or remotely transmit personal information. Native Messaging transfers data only to the registered PetalDesk executable under the same Windows user account.
Controls and contact
Password operations are bound to one session, tab, document, top-level origin, and validated target frame. Cross-origin password delegation is denied by default; the only current explicit mapping is from mail.163.com to its dl.reg.163.com login frame. HTTP and HTTPS submissions both produce save or update decisions; accepting an HTTP save shows a plaintext warning and enables later filling only for that exact origin. TOTP is bound to a separate single-use challenge and exact HTTPS origin; cross-origin OTP frames are rejected. The extension never submits a form or bypasses MFA. Recovery codes, CAPTCHA, passkeys, SMS or email codes, security keys, CVV, postal codes, and coupons are excluded.
The authentication-information permission is required at install time. Users may decline it during installation (the extension cannot run without it), lock the password vault, delete accounts, or uninstall the extension. Questions can be filed through PetalDesk GitHub Issues.