MxInspector reads the Mendix page you open it on, in your browser only: its structure, data, styling and network timings. It does not transmit, sell or share any of it, and the only things it stores are two of your settings.
What the extension does
MxInspector is a developer tool. When you click its toolbar icon on a Mendix application, it adds a panel to that page showing the page structure, the data the page has already loaded, performance timings, accessibility findings, styling information and a client-side security scan. All of that is read from what the browser has already received. The extension makes no calls to any server of ours, because we do not run one.
Why the extension asks for access to all sites
Mendix applications are served from domains their owners choose. One may run on
localhost, another on a company domain, another on Mendix Cloud. There is no
address pattern that identifies a Mendix application in advance, so the extension cannot
request a narrower list of sites and still be useful.
Two things limit what that access is used for. Two small scripts are registered to run automatically. One only defines the functions the panel later uses to read Mendix data, and does nothing on its own. The other exists to capture page load and network timings, which cannot be measured after the fact. It only starts timing network requests once the page shows the markers of a Mendix application; on any other site it never touches them. Everything else, including the inspector panel itself, runs only after you click the toolbar icon, and only on that tab.
Network activity
For completeness, these are the only three ways the extension touches the network. All stay within the application you are inspecting.
- Observing requests the page makes. To time them for the performance panel, the extension observes the application's own network calls. It reads their timing and addresses to display them to you. It does not alter, redirect, record or forward any of them.
- The documentation endpoint check. The security panel can test whether common documentation endpoints are publicly exposed on the application you are inspecting. This sends up to four requests, to that application's own address only, and only when you press that button. Nothing is sent automatically.
- Reading the page's security policy. When you open the panel, the extension requests the headers of the page you opened it on, once, to read its Content Security Policy. That tells the panel whether to mention that the application restricts styles. It is one request to that page's own address; only the policy header is read, and nothing is stored or sent anywhere else.
Local storage
The extension stores two settings: the appearance you pick in the panel (light or dark, solid or glass, full or simple view), and whether you switched the AI assistant interface on. They are kept in the browser's own extension storage on your device, are never synced or sent anywhere, and are removed when you uninstall the extension. Everything else, such as which sections are open, exists only while the tab is open and disappears when you close or reload it.
Assistance from AI coding tools
From version 0.3.0, MxInspector can expose a read-only interface that lets an AI coding assistant you are already using read the inspected page's structure and styling, so it can help you with layout and CSS questions. The extension does not contact any AI service itself and sends nothing anywhere. It only makes information available to a tool already running on your own machine, and only on a tab where you have opened MxInspector. It stays off until you switch it on with the badge in the panel header, which also shows what has been read and switches it off again. That choice is remembered.
Changes to this policy
If the extension's behaviour ever changes in a way that affects this policy, the policy will be updated here and the date above will change. Any change that introduces data collection would also require a new permission, which the browser would ask you to accept.
Contact
Questions about this policy can go to hello@timothymaurer.nl.