GOpenCDR privacy notice for the extension and apps
What the GOpenCDR browser extension and the desktop and mobile apps send, to whom, and what they keep on your device.
The short version
The GOpenCDR browser extension and the desktop and mobile apps send one thing that concerns you: DNS queries for GOpenCDR names, to the resolver you configure. They carry no analytics, no telemetry, no advertising identifiers and no fingerprinting, and none of them needs an account.
The controller is Gelhaus Solutions, as in the GOpenCDR privacy notice, which this notice adds to.
What each client does
- The browser extension, for Chromium-based browsers and Firefox, recognises GOpenCDR names in the address bar, resolves them through the desktop app or through the resolver you choose, and shows whether the site you are on validates with DNSSEC and DANE.
- The desktop app, for Windows, macOS and Linux, runs a local validating resolver for GOpenCDR TLDs only, and keeps the trust anchors and the list of TLDs up to date.
- The mobile app, for iOS and Android, sets up encrypted DNS for GOpenCDR TLDs only: on iOS through the system's DNS settings for those domains, and on Android through a local VPN that carries the DNS queries for those TLDs and no other traffic.
What leaves your device
- DNS queries for GOpenCDR names, to the resolver the client is set to use. By default that is
dns.cdr.gplatform.org, which keeps no log linking a query to your address, as the privacy notice describes. Queries for every other name are not touched by the clients and go wherever your system sends them. - TLSA queries for a GOpenCDR site you open, which the extension makes to show its DANE status.
- Trust anchors and the TLD list, downloaded over HTTPS from
cdr.gplatform.org, with their signatures checked before use. - Update checks for the desktop app, against
cdr.gplatform.org, carrying the app's version and platform. Every update is signed and checked before it is installed. The extension and the mobile apps are updated by their stores.
The downloads and update checks carry your IP address, as any request does. Our web server keeps it in its request log for 14 days, as for every other request.
Nothing else leaves your device. If you want to report a crash, you send it yourself, by email.
What stays on your device
Your settings, the trust anchors, the TLD list and a DNS cache. The extension keeps the status of the sites you open in memory only.
Permissions
- The extension reads the address of the page you navigate to, only to decide on your device whether it is a GOpenCDR name. Nothing about your browsing is sent anywhere except the queries described above.
- The Android VPN permission is used only to carry DNS queries for GOpenCDR TLDs. No other traffic passes through it.
App stores
Downloading a client from a store, such as the App Store, Google Play, Chrome Web Store or Firefox Add-ons, is governed by that store's own privacy terms. We receive only the aggregate figures the store provides.
Why, and your rights
We process these queries and requests to provide the client you installed and keep it secure (Art. 6(1)(b) and (f) GDPR). Your rights, and the supervisory authority you may complain to, are as described in the GOpenCDR privacy notice.