Frequently asked questions
Questions, answered
Grouped by theme. For the canonical privacy disclosure see the Privacy Policy. For anything not covered, email [email protected].
Version 1.0.12
Min Chrome 116
General
What does this extension do?
Its single purpose is to convert and normalize web links into affiliate links per your configured rules, and optionally broadcast them to destinations you configure (Telegram bots and HTTP webhooks). In one click it resolves redirects, unwraps embedded URLs, cleans tracking params, adds your tag, optionally wraps with a network, optionally shortens, and optionally broadcasts. Every other feature supports that one workflow.
Do I need an account, sign-up, or login?
No. There is no account, no sign-up, and no login. All of your configuration, credentials, and history are stored locally in your browser. You can start using the extension immediately after installing it.
What does it cost?
The extension is free to install and use. The bundled default shortener (ViaDeals Free,
via.deals/api/links) requires no signup. Any third-party services you connect — affiliate networks, Telegram, webhooks, or a custom shortener — are governed by their own terms and any fees they charge.Which Chrome version do I need?
Chrome 116 or newer. The extension is Manifest V3 and declares
minimum_chrome_version: 116. It also runs on other Chromium-based browsers (Edge, Brave, Vivaldi, Arc) that meet that baseline.Which stores and networks are supported out of the box?
Eleven store presets: Amazon India, Amazon (US/Global), Flipkart, Meesho, Myntra, AJIO, Nykaa, JioMart, Tata CLiQ, AliExpress, and eBay. You can add custom stores too. For networks, starter templates are provided for Cuelinks, EarnKaro, INRDeals, and Admitad, and INRDeals plus Cuelink are seeded as defaults (Cuelink as the catch-all fallback).
Privacy & data
Is my data sent anywhere?
The extension is local-first. All config, credentials, and conversion history are stored only in
chrome.storage.local on your machine. There is no account, and your config/credentials/browsing are never uploaded to any DealsGroup server. It does make network calls — but only for features you use, and only to: the link's own servers (redirect resolution), your shortener API, your webhook, api.telegram.org, the opt-in Deal Feed (tg-forwarded-deals.deals.group), api.qrserver.com (only on QR click), and google-analytics.com/g/collect (only while analytics is enabled). Every user-supplied endpoint passes an SSRF guard.Where exactly is my data stored, and how much?
In
chrome.storage.local only. There is no chrome.storage.sync and no remote database. A small amount of transient state (analytics session id, mobile-preview UA rule, remind-me payload) lives in chrome.storage.session and is cleared automatically. The local quota is about 10 MB. History is capped at 500 entries by default (configurable 100–5000), and the redirect cache is capped at 1000 with per-entry TTL (default 24h).Are my affiliate tags, bot tokens, or webhook secrets ever uploaded?
No. They are stored locally and sent only where you direct them — into the affiliate links you generate, or to the Telegram/webhook destinations you configure. They are never sent to analytics. When you export, all secrets are redacted by default unless you explicitly choose "Include credentials," and single-item community shares always strip secrets.
Analytics
Do you collect analytics?
Yes. The extension uses anonymous Google Analytics 4 (Measurement Protocol) usage analytics, and it is effectively on by default: the first-run wizard shows the consent toggle pre-enabled, and completing onboarding without changing it resolves to enabled. Every payload is marked
non_personalized_ads: true.What does analytics actually send?
Only an allowlist of non-personal event parameters:
tab, tool, via, reason, kind, success, count, engagement_time_msec, app_version. Strings are capped at 40 characters and a denylist drops any value that looks like a URL, email, or 20+ character token. Identifiers are a random client id and a per-session id — not tied to you. It never sends URLs, domains, affiliate tags, bot tokens, webhook secrets, message bodies, page content, your config, user_id, or user_properties — by construction.How do I turn analytics off?
Open the dashboard and go to Settings → Behavior, then toggle off anonymous usage analytics. Turning it off takes effect within milliseconds across all extension contexts.
The Deal Feed
What is the Deal Feed and what does it connect to?
An optional dashboard panel that shows incoming Telegram deal messages in real time. When you open it and click Connect, it opens a Socket.io WebSocket (wss) connection to the DealsGroup-operated server at
https://tg-forwarded-deals.deals.group and streams deal messages to you; feed images are fetched from /media/*. This is the extension's one first-party network feature.Is the Deal Feed opt-in, and does it send my data?
Yes, opt-in. It never connects on its own — you must open the panel and click Connect (a confirmation prompt). If you never open it, the extension never contacts that server. The connection is receive-only: the client never sends your data beyond a standard WebSocket connection (plus the server reporting an anonymous online-client count). Feed images are fetched with
credentials:'omit', and incoming HTML/Markdown is re-sanitized client-side, so it is XSS-safe.Will it stay connected forever? What can I do with a message?
No — it auto-disconnects after 5 minutes of inactivity to free the socket. Reconnect or disconnect manually at any time. It is live-only — there is no history or backlog. Per message you can Convert (open the composer), Convert & Send (broadcast to all configured destinations), or Copy as WhatsApp, Markdown, Telegram, or Plain text.
Telegram & webhooks
How do I send converted links to Telegram?
Add a channel with its bot token, chat id, and parse mode (Markdown or HTML). When you broadcast, the message text (and an optional image, sent as a photo with the message as caption) is posted to
api.telegram.org using your bot token. No browser cookies are involved.How do webhooks work?
Configure Discord, Slack, n8n, or custom webhooks with a method, headers, and a body template using placeholders like
{{message}}, {{message_json}}, {{message_url}}, {{timestamp}}, and {{token}}. You choose the trigger type (message, all, or reminder). Webhook requests use credentials:'omit' and pass the SSRF guard.What are inline reply buttons? Are my credentials safe?
You can attach static inline reply-button sets to Telegram messages; button values are sent verbatim (smart
[DG-*] tokens are no longer applied to button values). Fill-in-the-blank empty slots are prompted before sending. Your Telegram/webhook credentials are stored only in chrome.storage.local, never uploaded to any DealsGroup server, and redacted by default in exports.Permissions
Why does it need so many permissions? Which ones?
Each permission backs a specific feature. Exactly:
storage, tabs, scripting, contextMenus, clipboardWrite, notifications, alarms, webNavigation, webRequest, sidePanel, offscreen, declarativeNetRequest, plus the <all_urls> host permission. It does not request activeTab. The full list with code citations is in Permissions.Why does it need <all_urls>? Does DNR modify my browsing?
Because you can right-click any link or page to "Process with dealsgroup," and Mobile Preview can navigate to any URL, the host permission must cover all sites. The content script does not read or exfiltrate page content; its optional auto-detect is off by default. The DNR rule (strips X-Frame-Options/CSP, injects a mobile UA) applies only to sub-frame requests initiated by the extension's own pages and only while Mobile Preview is open. It never affects normal browsing.
Does the extension run remote code?
No. There is no
eval, no new Function, and no remotely loaded scripts. The CSP for extension pages is script-src 'self'; object-src 'self'. The socket.io-client used by the Deal Feed is bundled locally, not loaded remotely.Troubleshooting
My converted link looks wrong or is missing a tag.
Check the store's affiliate tag and network assignment in the dashboard. If the host is a suspicious IDN lookalike (punycode
xn-- homograph), the extension intentionally refuses to tag it as a phishing safeguard.Why does a hidden tab briefly appear when I trace or convert?
When JS-redirect resolution is enabled, the tracer/resolver loads the link in a hidden background tab so JavaScript-driven redirects can settle, then reads the final URL. A watchdog alarm closes any orphaned trace tab after a service-worker restart. This is expected behavior. Redirect fetch hops use
credentials:'omit'; JS-redirect detection uses your normal session.A reminder or scheduled message didn't fire.
Make sure Chrome notifications are allowed at the OS level; the dashboard surfaces a warning when they are blocked. Reminders are backed by
chrome.alarms, and missed reminders fire on startup within a 24-hour grace window.An import was rejected, or the Deal Feed won't show messages.
An import is rejected if the file contained unknown keys, wrong-shape values, or a webhook/shortener URL that failed the SSRF check. Imports are validated per key, written atomically, and rolled back on failure. The Deal Feed is opt-in and receive-only — you must click Connect; it is live-only (no backlog) and auto-disconnects after 5 minutes of inactivity.
Still stuck?
For anything not covered here, see Support or email us.
Add DealsGroup Affiliate Engine to Chrome
Free on the Chrome Web Store — works on Chrome, Edge, Brave, Vivaldi and Arc.