Candidate policy · September 24, 2026
Privacy policy
Hack Engine processes inspected-tab data locally to provide user-requested WebAssembly and JavaScript value tools.
Information handled
Hack Engine handles the inspected tab and frame URLs, public Ruffle metadata, numeric WebAssembly memory values and addresses, reachable JavaScript numeric properties and their paths, scan settings, watches, labels, groups, and values entered for writes or freezes.
JavaScript discovery runs on request and can encounter numeric application data unrelated to a game. Use the Advanced object picker to narrow discovery. Ordinary getters and DOM/browser internals are skipped; JavaScript Proxy inspection traps can still run.
Local use and storage
The information is used only for capture, scans, live candidates and watches, writes, and freezes. Live scans and one undo checkpoint belong to the current game document. Small watch metadata uses extension session storage to recover after background restarts. Saved workspaces and file import/export are no longer supported. Records saved by older versions may remain unused in extension local storage until the extension is uninstalled. These contain addresses, JavaScript path hints, labels, groups, and scan settings, but no live JavaScript references, memory snapshots, or freeze commands. UI preferences use extension-page session storage. Write diagnostics are transient background state shared with connected controls, discarded on background restart or game navigation. Batch selections remain local to each open interface. Unknown-value scans temporarily place compressed snapshot chunks in the inspected origin's IndexedDB; reset, replacement, cancellation, and page exit clean up owned data. When Web Locks is available, later initialization can reclaim orphaned data without deleting another live document's snapshots. Otherwise leftover snapshots may require clearing the site's stored data.
No external transmission
Hack Engine does not send browsing activity, page content, memory values, scan results, or analytics to the developer or any third party. It has no accounts, advertising, telemetry, or remote configuration and does not sell or share user information.
Permissions
storage preserves session metadata. tabs binds controls to the inspected tab. <all_urls> permits the document-start capture hook to run before browser games instantiate WebAssembly, including in permitted child frames. Chrome's sidePanel permission keeps the user-requested controls visible beside the page.
Retention and control
Resetting or replacing a scan clears its active candidates and undo snapshot. Private/incognito windows are not supported. Reloading closes active page memory state. Browser site-data controls remove origin snapshots, and normal extension-data removal applies when Hack Engine is uninstalled. Files exported by older versions remain where the user saved them.
Contact
Email a.abduljawad@outlook.com or use the public issue tracker for privacy questions. Use the private security advisory form for vulnerabilities.
Use Hack Engine only with software and content you own or are authorized to inspect. Raw writes are experimental and can reset or crash the player.