FlowScope Diagnostics privacy policy

Publisher: ML Dev
Last updated: September 13, 2026

What FlowScope does

FlowScope Diagnostics helps you investigate network requests and authentication flows in Microsoft Edge. It begins capture only when you choose Start Capture and grant optional HTTP(S) website access. Capture is limited to the selected tab, including its frames and redirects across websites. FlowScope does not monitor other tabs as part of that capture.

Information accessed and stored

While capture is active, FlowScope may record request URLs, request and response headers, browser request identifiers, resource types, status and timing information, errors, and selected SAML/OAuth form fields. URLs, cookies or other headers, SAML assertions, OAuth codes or tokens, and related fields may contain credentials, personal information, or internal system names. FlowScope does not retain raw request bodies or form fields outside its authentication-field allowlist.

FlowScope uses this information only to show the session timeline, map, request details, and diagnostic observations you request. These observations are troubleshooting aids; FlowScope does not verify SAML or JWT signatures or prove that authentication succeeded.

Where information goes

Captured session records are analyzed and stored locally in Microsoft Edge browser-session storage. The extension does not transmit captured records to a FlowScope server or third-party analytics service. It does not require a FlowScope account. If you choose to export a session, the downloaded file is controlled by you and is no longer subject to the extension's retention limits. FlowScope does not automatically share exports with the publisher or other parties.

Visibility and exports

Normal analysis views hide many URL and header details by default. You can deliberately reveal URL paths in the map or Inspector, and reveal a selected request's full URL or headers. Revealed paths, hostnames, and other diagnostic text can themselves be sensitive; hide details before sharing your screen.

Safe exports remove captured values and pseudonymize hosts. Diagnostic exports retain hostnames, paths, query-parameter names, and header names while redacting captured values; these retained names and paths may still identify people or systems. Original exports retain captured information, require an additional confirmation, and are marked UNREDACTED. Review every export before sharing it.

Retention and your controls

Capture stops when you choose Stop Capture, close the selected tab, or reach the 60-minute capture limit. FlowScope retains at most approximately 6 MiB or 10,000 requests in browser-session storage, removing the oldest records when a limit is reached. Saved requests are scheduled for deletion 30 minutes after capture stops; a sleeping browser may complete that deletion when it wakes. Edge restart, extension reload, update, or disable clears browser-session storage. Clear Session removes saved requests immediately. Local preferences such as filters are stored separately in Edge local storage.

Stop Capture does not revoke the separately granted website-access permission. The popup's Remove website access control stops capture and removes that optional permission without deleting saved requests; you can also manage it in Edge's extension settings. A later Start may restore access without another Edge prompt. If session storage fails during capture, FlowScope stops and attempts to remove website access.

Questions

For privacy questions, email support@meetingscribes.com.