Privacy
OctoSpy keeps everything it collects in your own browser. It has no server, no account and no analytics.
Applies to OctoSpy by Bliink, version 3.9 and later. Last updated 3 October 2026.
What the extension reads
- The page you inspect. When you open the popup on a page, the extension reads that page inside the tab: theme name, installed apps and trackers, sections, prices, structured data and SEO fields. It does not run on pages where you do not open it.
- A store’s public catalog. When you add a store to the report or rescan it, the extension requests the same public files any visitor can open:
products.json,collections.json, the sitemap, blog feeds, policy pages and the “best selling” collection page. - Shopify admin (optional, on by default). If you open the popup while one of your own Shopify admin tabs is open, it reads the plan name, store opening date and theme author from that admin page. It never reads orders, customers or payouts. Switch it off under Settings → Privacy.
- Ad libraries (optional, on by default). If you open the popup on a Meta Ad Library or Google Ads Transparency Center page, it reads the ads shown on that page. Switch it off under Settings → Privacy.
- Redirect blocking (off by default). When you switch it on for a site, a small script runs on that site to stop it from sending you to another country’s version by itself. You choose the sites.
Where the data goes
Into the browser’s extension storage on your device, and nowhere else. The extension makes requests only to the store you are looking at and to the ad-library page you opened. It does not contact Bliink or any third party, and it has no way to identify you. Country flags on the report are loaded as images from flagcdn.com.
Backups are files you download yourself. Exports (CSV, Markdown, JSON) are files you download yourself. If you share a brief or an insights file with an AI assistant, that is your choice and happens outside the extension.
Deleting data
Delete a store from its report menu, or remove the extension: the browser deletes the extension’s storage on uninstall.
Permissions, in plain words
- Access to all sites — a Shopify store can be on any domain, so the extension cannot list them in advance. It acts on a site only when you open the popup there, add it to the report, or list it for redirect blocking.
- Scripting, active tab — to read the page you inspect.
- Storage, unlimited storage — to keep store reports and history in the browser.
- Alarms, notifications — scheduled rescans of the stores you watch, and a notification when one changes.
- Downloads — the weekly backup file.
- Declarative net request (with host access) — strips one response header (
Link: rel=preload) from requests the extension itself makes, so the report page does not load store scripts.
Contact
Ravi Rahul, Bliink — ravirahul@bliink.in