Is Prospecta safe?
Prospecta fingerprints the browser and combines it with the Chrome-signed-in email and IP location on every side-panel open.
On install and startup, Prospecta reads the Chrome-signed-in email and looks up the user's city and region from their IP address, storing both locally. A fingerprinting script injected into web.whatsapp.com hashes canvas, WebGL, audio, and font rendering into a persistent device ID. Every time the side panel is opened, the extension sends this email, location, and device ID together to its own backend at api.eminer.app, with no mention of this collection in its store listing or privacy policy.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes iteMiner - 2 other listings from the same operator, 1 of them carrying a finding
eMiner - 2 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 6k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed prospecta-%F0%9F%87%A7%F0%9F%87%B7 contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.eminer.app
prospecta-%F0%9F%87%A7%F0%9F%87%B7 sends data to api.eminer.app. No other extension we have analysed sends data here.