Privacy Policy
Last updated: August 16, 2026
Knockoff is a browser extension that filters pseudo-brand listings out of Amazon search results. It is built to need as little of your data as possible: no accounts, no cookies, no profiles, and nothing collected that identifies you. Two settings control everything the extension sends on its own: facts about products, sellers, and listings, never anything that identifies you. Both are on unless you turn them off, everything they send is listed below, and both can be switched off in the extension's options.
That covers the extension, which is the whole product. There are three exceptions, and we would rather name them than bury them: all are addresses typed in by their owners. If you sign up for the monthly finds email on the shop pages, we keep that address and use it to send that one email a month (details under The monthly finds email below). If you leave an email with a piece of feedback so we can reply, we hold it with your message and use it to answer you, nothing more (details under Network requests the extension makes below). And addresses given to the site's old "email me the install link" form are still held, under the same promises that form made (details under The retired install-link form below).
What runs locally
All brand detection happens on your device, inside the extension: nothing about a page is sent anywhere in order to filter it. Your searches and the URLs you visit are never sent on their own. The one exception is feedback you write yourself, which attaches the address of the page you sent it from and says so on the form before you press send. Two features do send something, both listed below and both switchable: the seller origin map sends the IDs of the sellers shown on a page, and Help pick US alternatives sends the product itself when you open an Amazon product page. Your settings, allowlist, and blocklist are stored using your browser's extension storage and stay in your browser (your browser may sync them between your own devices via its built-in extension sync).
Network requests the extension makes
- Brand list and config refresh. Roughly once a day the extension downloads an updated list of brand names and display settings from
api.knockoff.co. This is a plain download; no information about you or your browsing is included in the request beyond what any HTTP request carries. - Misclassification reports (user-initiated). If you click "report" on a badge, the extension sends the brand name, the verdict it assigned, the product's ASIN, the Amazon marketplace domain, and the extension version. That's the entire payload. It contains no account information, no browsing history, and nothing that identifies you.
- Feedback (user-initiated). The extension's panel has a "Send feedback" form. If you use it, the extension sends what you typed, the address of the page you were on (for context; the form says so before you send), the marketplace (Amazon or Etsy), the extension version, and, only if you choose to leave one, an email address so we can reply. The message is stored on our servers and forwarded to us by email. The server also stores a coarse browser and operating-system label derived from the request's standard User-Agent header so we can triage browser-specific bugs; Safari on macOS and iPadOS may be grouped because they can report the same value. The email address is used to answer you and for nothing else. As with reports, a salted hash of your IP rate-limits abuse; the raw IP is not stored.
- Seller origin map (optional, on by default). To flag which country a marketplace seller ships from, the extension looks up the seller IDs shown on listings you view and counts how often each is seen. When you open a seller's own profile page, it reads the business-identity block Amazon already displays there to every shopper (published under marketplace-transparency laws: the INFORM Consumers Act in the US, the Digital Services Act in the EU). It then sends the seller's ID, country, registered business name, address, phone, email, trade-register or VAT number, whether that address is marked home-based, and the brand names listed on that seller's own storefront. It also reports anonymous counts of how many listings on a results page are sold by Amazon itself versus third parties. That's the entire payload, and every field of it describes the seller: no account information, no browsing history, and nothing that identifies you. As with reports, the server keeps a salted hash of your IP address to rate-limit abuse and to check that two different people saw the same seller; the raw IP is not stored.
- Help pick US alternatives (on by default, switchable). This is the one feature that sends a product rather than a seller. When you open an Amazon product page, the extension sends that product (its ASIN, title, brand, and the seller of the featured offer) so we know which products people actually want US alternatives for, and build those pages first. Those same rows do one more job: on marketplaces whose listings the filter can't read yet (Japan and the Middle East), they show us which unknown brands shoppers keep meeting, so a human can review them for the junk list. The report button can't work on those stores, so this is the only signal we get from them. It is aggregated into a per-product view count: a stored row says "this product was viewed N times" and nothing else. No account, no profile, no session, and no IP address is stored beside it, so a product is never linked back to a person. Switch it off and nothing about the products you view is sent.
- Etsy authenticity signals (needs the shopping-sites switch on, plus the switch above). On an Etsy listing page, the extension reads what the page itself shows every shopper — the listing ID and shop, the "Made by / Designed by" label, the shop's age and sales count, the ships-from country, the price and review count, and whether the description pitches duties-paid shipping or an enormous catalog — and sends that fingerprint so repeated, independent sightings can corroborate or clear a listing. The same request path is read in reverse: the extension asks whether corroborated sightings plus our own catalog-image check flagged the listing you're on (that lookup carries the listing ID alone) and, if so, adds the result to the card. On results pages — search, categories, a shop's items — it runs the same check for the listing IDs shown on the page so flagged tiles can carry a small badge; that lookup too sends listing IDs alone. When a lookup asks about a listing we've never checked, our own servers may then fetch and evaluate that listing's public page — the fetching happens from our infrastructure, never from your browser, and the only thing your browser sent was the listing ID. Every field describes the listing: no account, no browsing history, and nothing that identifies you. As with the seller map, the server keeps a salted hash of your IP to rate-limit abuse and to check that two different people saw the same listing; the raw IP is not stored. The same "Help pick US alternatives" switch controls this — turn it off and nothing about the listings you view is sent.
What your browser's permission prompt means
Browsers describe extension permissions in their own words, and the words are broad. Here is what each one actually covers in Knockoff's case.
- "Website content" (Firefox's data-collection prompt). What the extension reads to do its job: product titles, brand names, and seller IDs on the Amazon pages you shop, and, with Etsy checks on, a listing's own public shop facts. The brand appraisal itself runs locally in your browser; the parts that leave it are the seller origin map and Etsy authenticity signals described above, and both ride the switches described there.
- "Browsing activity" (Firefox's data-collection prompt). This is one feature: Help pick US alternatives, described above, which sends the Amazon product pages you open. A stored row records that a product was viewed N times, never who viewed it. Switch it off and nothing about the products you view is sent. Your searches, your orders, and the rest of your browsing are never sent either way.
- "Read and change your data on all websites" (turning on other shopping sites). Amazon access is granted at install. Checking marketplaces beyond Amazon (Etsy today; more shopping sites next) uses one broad optional grant so your browser doesn't re-prompt for every site we add. The extension uses it only to run on the shopping sites it supports: the site list is fixed in the extension's own code, no script ever runs on any other site, and nothing from any other site is read, stored, or sent. Decline it and everything on Amazon still works; the same switch revokes it.
Report handling
Reports are stored on our own servers and reviewed by hand to improve the bundled brand lists. To rate-limit abuse, the server stores a salted hash of the reporter's IP address; the raw IP is not stored, and the hash is never stored alongside a product. Reports are kept only as long as needed for list curation.
The monthly finds email
The shop pages on this site offer a monthly email: the newest US brands and US-based sellers we've confirmed from Amazon's own published seller info, once a month, and nothing else. This signup is the only thing on this site that asks for anything personal, and nothing happens unless you type an address in and send it.
We keep the address. It is stored with the date you gave it and which list you joined, and nothing else: no IP, no session, no referrer. Nothing about your browsing sits beside it, so it is never linked to any of the product or seller data above. It is never sold, never shared, and never used to market anything that isn't Knockoff. Every mail carries an unsubscribe link. The mail itself is sent by Resend, which keeps its own delivery log. To stop the form being used to mail someone who never asked, signups are capped per hour using the same salted hash of the IP address described above; the raw IP is not stored. If you would rather your address were deleted outright, email [email protected] and we will remove it.
The retired install-link form
This site used to offer visitors on a phone an "email me the install link" form, which also joined a list for news about Knockoff. The form is gone, but the addresses given to it are still held, under the same promises: stored with the date they were given and nothing else, used for nothing but Knockoff news, never sold or shared. The two lists are separate: a newsletter signup does not put you on that news list, or the other way around. Every mail carries an unsubscribe link, and unsubscribing is final: we keep the row so nothing can quietly put you back on the list, and we never mail that address again. The one thing that re-subscribes an address is its owner typing it into a signup form again; nothing we do revives it. Deletion requests work the same way as above: email [email protected].
What we never do
- No sale of data, to anyone, ever.
- No mail to anyone who didn't ask for it. The only addresses we hold are ones typed in by their owners: the monthly finds signup gets nothing but that monthly email, the retired install-link form's list gets nothing but Knockoff news, one unsubscribe ends either, and an address left with feedback gets a reply to that feedback and nothing else.
- No transfer of data for creditworthiness or any purpose unrelated to the extension's single function. Some shop-us pages on this site may carry a single clearly labeled sponsored listing, matched to the product category on the page, never to you. When one runs, impressions and clicks on it are counted in aggregate on our server, without cookies or identifiers, and sponsors receive those totals and nothing else: no user data, ever.
- No tracking pixels, cross-site tracking, or fingerprinting in the extension.
- No linking any of the above to a person. The counts we keep are per product and per seller: there is no account, profile, or identifier to attach them to.
Changes
If this policy changes, the update will be posted at this URL with a new date above. The extension ships as plain, unbuilt JavaScript, so every claim here can be checked against the code running in your own browser.
Contact
Questions: [email protected].