Last updated 20 September 2026
In plain English
ClickShield reads the destination URL of a link on a page you're viewing: when you hover it, and separately if you click a link it has already flagged unsafe during that page's session. That URL is the only piece of information it acts on. It does not read page content, form fields, cookies, or anything else on the page.
When a check runs, the URL travels through the following path:
| Step | What's sent | To whom |
|---|---|---|
| 1 | The hovered/clicked URL, plus a random install identifier | ClickShield's backend proxy (Google Cloud Run, with a Cloudflare Workers fallback), operated by us. It holds the three providers' API keys so this extension never does |
| 2 | The same URL only | Google Safe Browsing, URLhaus (abuse.ch), and PhishTank, whichever are configured |
| 3 | The shortened URL itself | The shortener's own domain (e.g. bit.ly), only for links on ClickShield's known-shortener list, to follow its redirect |
The install identifier (a randomly generated value stored on your device) exists only so our proxy can apply a fair-use rate limit. It is not a user account, is not linked to your name or email, and is never sent anywhere except that proxy.
Everything below is stored locally in your browser (chrome.storage.local), never on our servers:
A daily cleanup removes anything past its cache lifetime. Uninstalling the extension removes all of it immediately.
Available from the toolbar popup, all on by default:
Turning the four toggles off stops ClickShield from displaying anything, though hover checks still run in the background so the click-confirm feature stays reliable. Pausing goes further and stops those background checks too. Uninstalling the extension stops everything entirely.
ClickShield's results come entirely from three independent, third-party threat databases (Google Safe Browsing, URLhaus, and PhishTank). Those lists are maintained by others, aren't exhaustive, and can be wrong in either direction: a link marked "no known threats" is not a guarantee it's safe, only that it wasn't on those lists at the moment it was checked, and a link that's actually safe can occasionally be flagged incorrectly.
ClickShield only displays what these providers report, it doesn't independently verify a link's safety. When "Ask before opening unsafe links" is on, it shows a warning and asks you to confirm before a known-unsafe link opens, it never silently blocks, filters, or removes anything.
ClickShield is provided as-is, without warranty of any kind. We aren't responsible for any loss or harm arising from a missed threat, an incorrect flag, or any decision made based on a result it shows.
Each has its own privacy practices, outside ClickShield's control:
ClickShield does not knowingly collect personal information from anyone, including children, and isn't directed at children specifically. Its only input is a hovered or clicked link's URL.
If ClickShield's data practices change, this page will be updated and the date at the top revised accordingly. Material changes will also be noted in the extension's release notes.
Email: clickshield.support@gmail.com
Facebook: facebook.com/clickshield