HAR Fixture Studio

Privacy policy

Last updated 4 October 2026.

This policy covers HAR Fixture Studio, the web app at whitehatharbor.com/har-fixtures/app/ ("the app") and the HAR Fixture Studio extension for Chrome ("the extension"), built and supported by Michael Costa, trading as White Hat Harbor ("we"). In short: the HAR file you open is read and turned into fixtures inside your browser and is never uploaded. We never see your HAR, its contents or the files you export. The only network service the app talks to is Polar, and only to check a license key you enter.

Your HAR file

HAR files hold the URLs, headers, cookies and bodies of the requests in them, which can include passwords, tokens and personal data. When you open one, the app reads it inside the browser tab (or the extension's own tab) with code that ships with the page. Everything it works out (the request list, your edits, the rules' results, the warnings, the zip you download) stays in that tab's memory and is gone when you close or reload it. The zip is made in the browser and saved by it, like any other download.

The app sends nothing from the HAR anywhere: not to us, not to Polar, not to any analytics, error-reporting or advertising service. The app page's Content-Security-Policy enforces this: it lets the page connect only to its own site (for the bundled sample HAR) and to Polar's license check.

What is stored, and where

DataWhere
A license key you activate, and whether it was valid when last checkedYour browser's local storage for whitehatharbor.com, or the extension's local storage
Rule sets you save (full version): a name and the rules (header names, query parameter names, JSON paths, text to find and what to replace it with)The same local storage

Nothing from a HAR is stored, unless you type it into a rule yourself. Clear this data by clearing the site's data in your browser, or by removing the extension.

The license key and Polar

The full version is sold by Polar, the merchant of record. If you buy it, you give your email address and payment details to Polar on its own pages, under its own terms (Polar privacy policy). We receive your email address, what you bought and the payment status from Polar, to support you and handle refunds. We never see your card details.

When you activate a key, and each time the app opens with a key saved, the app sends the key to Polar's license-key check (api.polar.sh) together with our organization id and the product's benefit id, and Polar answers whether it is active. Polar receives your IP address and browser details with that request, as with any web request. Nothing from your HAR is part of it.

The website

whitehatharbor.com is hosted by Cloudflare, which receives your IP address and browser details when you load a page. This docs page and this policy count visits with Cloudflare Web Analytics, which sets no cookies, like the rest of the site. The app page's security policy doesn't let that script load, so the app itself isn't counted.

The extension

The extension asks for one permission, storage, for the license key and rule sets above. It has no access to the websites you visit, reads no web pages and runs no remote code: its toolbar button opens the app in a tab of its own, where it works exactly as described here. The extension isn't in the Chrome Web Store yet.

Your exports

The files you download are yours. The rules and the scanner help you remove secrets, but they can't promise that a file holds none; check the files before you share or commit them.

What we don't do

Contact

Questions about this policy: see Support. Changes to it are posted on this page with a new date.