Is Custom profile picture for Netflix™ [QVI] safe?
Custom Profile Picture for Netflix is medium risk. On install, the extension marks data collection enabled unasked. Before consent, it sends a tracking ID plus your viewing history, profile data, device lists, and watch-lists to metricsplus.online. No opt-out at install; only in settings.
Who publishes itHideApp - 67 other listings from the same operator, 15 of them carrying a finding
HideApp - 67 other listings from the same operator, 15 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 67 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Viewing Data Sent Without Consent Prompt
On install, the extension marks data collection enabled unasked.
Before consent, it sends a tracking ID plus your viewing history, profile data, device lists, and watch-lists to metricsplus.online.
No opt-out at install; only in settings.
You install the extension from the Chrome Web Store.
No consent prompt for data sharing is displayed during or immediately after installation.
The service worker writes shareInsights=true to chrome.storage.sync, enabling data collection.
Dynamic analysis confirmed this flag is set before any onboarding flow completes and before you visit Netflix for the first time.
Controls whether viewing data goes to metricsplus.online. Set true on every fresh install unasked, so collection runs until manual opt-out.
chrome.storage.sync key 'shareInsights'{
"shareInsights": true
}{
"dist": "chrome",
"revision": "4e389220",
"platform": "netflix",
"namespace": "flow",
"extVer": "1.2.9.71",
"extensionUserId": "795cda2d-a3f1-4e22-b918-c7d04e2b1f93",
"dhVer": "3.1.0",
"message": "init"
}| Field | Value | Why it matters | |
|---|---|---|---|
Extension user ID | 795cda2d-a3f1-4e22-b918-c7d04e2b1f93 | A random ID from first install, stored in your browser, letting metricsplus.online link uploads across sessions. | |
Netflix account ID and profile GUID | accountId: 2001298374, profileId: a1b2c3d4-e5f6-7890-abcd-ef1234567890 | Your Netflix account ID and profile GUID are pulled from the page and sent in the session-init request. | |
Netflix viewing history | Squid Game, Bridgerton, Cobra Kai, Money Heist, The Witcher | Titles from up to five pages (500 items) of viewing history are uploaded when shareInsights is enabled. | |
Country and browser language | country: US, browserLanguage: en-US | Your device locale and inferred country code are included in every session-init request sent to metricsplus.online. | |
Extension version and build revision | extVer: 1.2.9.71, revision: 4e389220 | Version and build revision are sent with every request, letting the server segment data by release. |
sw.js: consent flag set to true on install (no prompt)
// Runs once when the extension is first installed.
// At this point the user has NOT been asked about data sharing.
chrome.runtime.onInstalled.addListener(async (event) => {
const { reason } = event;
if (reason === chrome.runtime.OnInstalledReason.INSTALL) {
initConfig(); // creates a local profile-picture config in chrome.storage.local
openSuccessPage(); // opens greatbrowserextensions.com/thank-you-survey/ in a new tab
} else if (reason === chrome.runtime.OnInstalledReason.UPDATE) {
applyLegacyMigration();
}
reloadNetflix(); // reloads any open Netflix tabs so content scripts activate
// Set data collection to ON by default — no consent prompt is shown.
// If shareInsights is not already set (i.e., fresh install), write true.
chrome.storage.sync.get(['shareInsights'], (result) => {
if (result.shareInsights === undefined) {
chrome.storage.sync.set({ shareInsights: true }); // DATA COLLECTION ACTIVE
}
});
});- metricsplus.online
Primary endpoint. Receives telemetry (/n/js/dlog), session-init data at /n/netflix/start, and viewing/profile data at /n/netflix/upload. Hardcoded across all eleven bundles.
- metricsmint.quest
Secondary upload endpoint, config key 'd1', across eight bundles. Role undocumented in the listing or privacy policy.