Privacy Policy

Last updated: March 13, 2026

Scope

This policy covers the Mocklet website and the Mocklet DevTools browser extension used to record or import HAR traffic, validate endpoints, and create or manage hosted HTTP mocks.

What Mocklet processes

Mocklet processes only the data needed to run your account and provide API mocking features.

  • Account data, including your email address and optional display name.
  • Authentication data, including password hashes or Google OAuth provider identifiers.
  • Extension local storage, including the selected API base URL, session token, and a short-lived OAuth callback result used to complete sign-in.
  • Traffic you explicitly record or import, including URLs, methods, headers, bodies, status codes, timing data, and other HAR metadata.
  • Mock configuration, matching rules, validation results, and generated mock URLs.
  • Request statistics and runtime diagnostics, including hit or miss counters, latency, and unmatched reasons.

How Mocklet uses this data

  • To authenticate you and maintain your session.
  • To validate HAR files, create mocks, list mocks, delete mocks, and show diagnostics and statistics.
  • To remember your selected backend and complete Google OAuth sign-in.
  • To operate, secure, and troubleshoot the Mocklet service.

Data minimization and privacy controls

  • Recording in the extension is off by default and starts only when you explicitly begin a capture in DevTools.
  • During live DevTools recording, the extension removes Authorization, Cookie, and Set-Cookie headers and clears request and response cookies before processing captured entries.
  • Imported HAR files are processed as provided by you. If an imported HAR file contains secrets or personal data, Mocklet may process that data as part of validation or mock creation.
  • Mocklet does not sell user data and does not use extension data for advertising.
  • No ad tracking cookies are used on the product itself.

Your responsibility for recorded or uploaded data

You must record or upload only development or testing HAR data. Do not record or upload production traffic that contains real credentials, tokens, personal data, or sensitive customer information.

Retention and deletion

  • Mocks are temporary and expire automatically based on TTL settings.
  • You can delete mocks at any time from your account.
  • HAR-derived mock data is retained while the corresponding mock exists.
  • Account data is retained while your account remains active.
  • Data stored locally by the extension remains until you sign out, change settings, clear extension storage, or remove the extension.

Third-party services

  • Google OAuth: used only for authentication when you choose Google sign-in.
  • Umami analytics: optional landing-page analytics, privacy-focused and configured without cookies.

What Mocklet does not do

  • Mocklet does not sell your uploaded data.
  • Mocklet does not use extension data for advertising or credit-related decisions.
  • Mocklet does not download and execute remote code inside the extension.

Documentation and governance

For product usage guidance, read the documentation. For legal obligations around service usage, see the terms of service.

Contact

For privacy or data handling questions, contact [email protected].